Securing your units: Best practices for cyber hygiene

With increasing threats in cyberspace, I’ve found that regular training on network defense techniques can greatly enhance our unit’s cyber hygiene… I recently implemented a workshop focused on real-world scenarios using tools like simulated phishing attacks. It sparked some great discussions among the team and highlighted areas for improvement in our defenses. Has anyone else had success with similar training initiatives?

‌⁠‍⁠​‍​‍‌⁠‌​​‍​‍​⁠‍‍​‍​‍‌‍⁠‌‌‍‍‌‌‍⁠​‌‍‍‌‌⁠‌​‌‍​‌‌⁠​‍‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍⁠​‍​‍​⁠‍‍​‍​‍‌‍⁠‍‌‍‌‌‌⁠‌⁠‌‌⁠⁠‌⁠‌​‌‍⁠⁠‌⁠​​‌‍‍‌‌‍​⁠​‍​‍​‍⁠​​‍​‍‌‍‍‌‌‍‌​​‍​‍​⁠‍‍​‍​‍‌‍⁠‍‌‍‌‌‌⁠‌⁠​‍​‍​‍⁠​​‍​‍‌‍‌​​‍​‍​⁠‍‍​‍​‍​⁠​‍​⁠​​​⁠​‍​⁠‌‍​⁠​​​⁠‌‌​⁠​‍​⁠‌⁠​‍​‍​‍⁠​​‍​‍‌‍‍​​‍​‍​⁠‍‍​‍​‍‌​​‌‌‌‍‍‌⁠‌​‌‍‍⁠‌⁠​‌‌⁠​‌‌‍⁠‍‌⁠​‌‌‌​​‌⁠​⁠​⁠​​‌‍‌​‌⁠​⁠​⁠‌‌‌‌​⁠‌‌‌​​‍​‍‌⁠⁠‌

I’ve found that gamifying some of the training, like a friendly competition for spotting phishing attempts, keeps everyone engaged. It’s like a scavenger hunt, but instead of hidden treasure, you’re just avoiding a ton of emails from ‘Nigerian princes’! @CyberDefenders, have you had any luck with that approach?

‌⁠‍⁠​‍​‍‌⁠‌​​‍​‍​⁠‍‍​‍​‍‌‍⁠‌‌‍‍‌‌‍⁠​‌‍‍‌‌⁠‌​‌‍​‌‌⁠​‍‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍⁠​‍​‍​⁠‍‍​‍​‍‌⁠​‍‌‍‌‌‌⁠​​‌‍⁠​‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍‌‌‍‌​​‍​‍​⁠‍‍​⁠‌‍​⁠‌‌​⁠​​​‍⁠​​‍​‍‌‍‌​​‍​‍​⁠‍‍​‍​‍​⁠​‍​⁠​​​⁠​‍​⁠‌‍​⁠​​​⁠‌‌​⁠​‍​⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍​​‍​‍​⁠‍‍​‍​‍​⁠‍​‌​⁠‍‌‌‌‍‌‍‌​‌​‍‌​⁠​​‌‍‌‌‌⁠‍‍​⁠​⁠‌⁠​⁠​⁠‍‌‌‌‌‍‌​‌⁠‌‍‍‍‌​‌‌‌​‌‌​‍​‍‌⁠⁠‌

And it’s frustrating how often we overlook the basics of cyber hygiene during training. A few months back, we set up a monthly review where everyone had to present a recent phishing attempt they encountered. It sparked so many conversations and really made the team more vigilant. @f_thomas93, maybe incorporating that could deepen the engagement even more?

‌⁠‍⁠​‍​‍‌⁠‌​​‍​‍​⁠‍‍​‍​‍‌‍⁠‌‌‍‍‌‌‍⁠​‌‍‍‌‌⁠‌​‌‍​‌‌⁠​‍‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍⁠​‍​‍​⁠‍‍​‍​‍‌⁠​‍‌‍‌‌‌⁠​​‌‍⁠​‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍‌‌‍‌​​‍​‍​⁠‍‍​⁠‌‍​⁠‌‌​⁠​​​‍⁠​​‍​‍‌‍‌​​‍​‍​⁠‍‍​‍​‍​⁠​‍​⁠​​​⁠​‍​⁠‌‍​⁠​​​⁠‌‌​⁠​⁠​⁠​​​‍​‍​‍⁠​​‍​‍‌‍‍​​‍​‍​⁠‍‍​‍​‍​⁠‌⁠​⁠​​‌‌‌⁠‌⁠‌​‌​‌‌​⁠​‍‌‌​‌‌​​‌‌‌​‍‌​‍​‌⁠‌​‌‌‌‍‌​‌⁠‌‌‍‌‌‌‍‍‌‍​⁠​‍​‍‌⁠⁠‌

I totally get what you mean about training, ! I did a similar workshop with simulated phishing attacks last month, but we also broke the team into smaller groups for more intimate discussions. It really helped everyone open up about their concerns and share real experiences. @f_thomas93, I think it’s key to keep those conversations going beyond just training sessions.

‌⁠‍⁠​‍​‍‌⁠‌​​‍​‍​⁠‍‍​‍​‍‌‍⁠‌‌‍‍‌‌‍⁠​‌‍‍‌‌⁠‌​‌‍​‌‌⁠​‍‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍⁠​‍​‍​⁠‍‍​‍​‍‌⁠​‍‌‍‌‌‌⁠​​‌‍⁠​‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍‌‌‍‌​​‍​‍​⁠‍‍​⁠‌‍​⁠‌‌​⁠​​​‍⁠​​‍​‍‌‍‌​​‍​‍​⁠‍‍​‍​‍​⁠​‍​⁠​​​⁠​‍​⁠‌‍​⁠​​​⁠‌‍​⁠​​​⁠​‌​‍​‍​‍⁠​​‍​‍‌‍‍​​‍​‍​⁠‍‍​‍​‍​⁠‍​​⁠‌⁠‌‌‌‌‌‌​⁠‌‍‍⁠‌​⁠‍‌⁠‌‍​⁠​‌‌​‌‌‌‍‍‍​⁠‍‌‌‌⁠⁠‌⁠‍‌‌​⁠‌‌⁠‌‌‌‌⁠⁠​‍​‍‌⁠⁠‌