{"id":32094,"date":"2019-07-24T09:00:27","date_gmt":"2019-07-24T08:00:27","guid":{"rendered":"https:\/\/www.intelligentcio.com\/eu\/2019\/07\/24\/research-shows-75-of-security-awareness-professionals-work-part-time\/"},"modified":"2019-07-24T09:01:17","modified_gmt":"2019-07-24T08:01:17","slug":"research-shows-75-of-security-awareness-professionals-work-part-time","status":"publish","type":"post","link":"https:\/\/www.intelligentcio.com\/eu\/2019\/07\/24\/research-shows-75-of-security-awareness-professionals-work-part-time\/","title":{"rendered":"Research shows 75% of security awareness professionals work part-time"},"content":{"rendered":"<p>The most common factors holding back security awareness programmes in companies are the lack of time and staff rather than budget, although nearly 60% of the professionals surveyed say they are not even aware of the budget allocated to security awareness in their companies.<\/p>\n<p>These are some of the key findings of the 2019 <em>Security Awareness Report<\/em>, the fifth edition of a report produced annually by SANS Security Awareness, a division of SANS Institute and a world leader in security training.<\/p>\n<p>The study compares current data with that of previous years and analyses the main problems faced by security awareness professionals in companies: lack of resources, managerial support and ambiguity in their positions and responsibilities.<\/p>\n<p>The intention of the SANS Security Awareness Report is to provide security awareness professionals with a road-map to make data-driven decisions on how to improve their security awareness programmes. It also provides professionals with the ability to benchmark their programmes against their industry peers.<\/p>\n<p>Essentially, it works to more definitively answer the question of what ingredients go into making a security awareness programme successful. This year, data was analysed from nearly 1,600 respondents providing even greater insight into how to benchmark and mature a security awareness programme.<\/p>\n<p>\u201cI\u2019m absolutely thrilled about the release of the 2019 <em>Security Awareness Report<\/em>,\u201d says SANS Security Awareness Director, Lance Spitzner. \u201cEvery year we are able to gain a better understanding of the most common challenges awareness professionals face and how to best address them and after five years, we are beginning to identify key trends.\u201d<\/p>\n<p>Working with researchers from\u00a0The Kogod Cybersecurity Governance Center (KCGC), an initiative of American University&#8217;s Kogod School of Business (KSB), the survey data was examined in detail to provide information on:<\/p>\n<ul>\n<li>Common challenges holding back programme maturity \u2013 lack of time and staffing were among the top reported roadblocks facing awareness professionals. More than 75% of these professionals work part-time, which means that companies are spending less than half of their time on security awareness.<\/li>\n<li>Getting the support of management and programme buy-in is key \u2013 industry peer pressure was found to have a distinctive role in determining whether leadership treats security awareness training as a top priority. In fact, 69% of organisations whose managers believe that the market is investing significantly in this area consider safety awareness training to be a top priority.<\/li>\n<li>The growing need to create more concrete job roles and expectations within the security awareness training realm \u2013 less than 10% of the respondents reported their job titles even included the words &#8216;awareness&#8217; or &#8216;training&#8217; in them and about 60% were not even aware of the budget allocated to security awareness in their companies.<\/li>\n<\/ul>\n<p>This report highlights these growing concerns and challenges for security awareness. It also utilises the SANS Security Awareness Maturity Model as a guide to identify an organisation&#8217;s level of a program&#8217;s impact and how to measure human risk and change end-user behaviour.<\/p>\n<p>This model, which has been revamped in this year\u2019s report, provides organisations with the ability to easily identify where their security awareness programme is currently at, where a qualified leader can take it and it even outlines the path to get them to where they want to be.<\/p>\n<p>For more detailed analysis and recommended action on improving an awareness strategy, the 2019 SANS Security Awareness Report is available for download <a href=\"https:\/\/www.sans.org\/security-awareness-training\/reports\/2019-security-awareness-report\">here<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The most common factors holding back security awareness programmes in companies are the lack of time and staff rather than budget, although nearly 60% of the professionals surveyed say they are not even aware of the budget allocated to security awareness in their companies. These are some of the key findings of the 2019 Security [&hellip;]<\/p>\n","protected":false},"author":28,"featured_media":32097,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[57,6617,93],"tags":[12927,11880,12928],"class_list":["post-32094","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-enterprise-security","category-research","category-top-stories","tag-2019-security-awareness-report","tag-lance-spitzner","tag-the-kogod-cybersecurity-governance-center-kcgc"],"acf":[],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts\/32094","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/users\/28"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/comments?post=32094"}],"version-history":[{"count":1,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts\/32094\/revisions"}],"predecessor-version":[{"id":32096,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts\/32094\/revisions\/32096"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/media\/32097"}],"wp:attachment":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/media?parent=32094"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/categories?post=32094"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/tags?post=32094"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}