Skip to main content

Working-from-home lessons: employees ‘confidently’ make 90% of all security awareness mistakes

September 7, 2020

Free security awareness training on remote working from Kaspersky and Area9 Lyceum has seen participants enact correct responses 66% of the time.

However, even when learners were wrong, they mostly remained confident in their competences. The most difficult learning objectives proved to be virtual machines, updates, and reasons why people should use corporate IT resources even while working outside the office.

This spring, due to the coronavirus pandemic, many companies switched to remote working. This change affected corporate security via a growing number of web-based attacks, coronavirus-related phishing, as well as the increased use of shadow IT. To help businesses improve their staff cybersecurity skills, in the beginning of April 2020 Kaspersky and Area9 Lyceum released an adaptive learning course for those transitioning to at-home working, covering the basics of secure remote operations.

Analysis of anonymized learning results revealed that remote staff tend to overestimate the level of their knowledge of cybersecurity basics. In 90% of cases when learners selected a wrong answer, they evaluated their feelings toward the given response as “I know it” or “I think I know it”. This was revealed through an adaptive learning methodology, which asked learners to assess their levels of confidence in responses, as well as answer the test questions.

The study also identified the most difficult learning objectives – the hardest being reasons why to use virtual machines. As many as 60% of the given answers were wrong on this matter, with 90% of respondents falling into the ‘unconscious incompetence’ category. This means that mistaken learners were still sure that they had selected the right answer or option.

More than half of responses (52%) to questions about reasons why employees should use corporate IT resources (such as mail and messaging services or cloud storage) when working from home was incorrect. In 88% of cases, remote employees thought that they could explain this correctly. Almost the same proportion of mistakes (50%) was made when answering a question about how to install software updates. In this case, a staggering majority of 92% of those who had provided wrong answers, believed they had that required skill.

the-most-difficult-learning-objectives.png

“If employees see no danger in risky actions, let’s say, in storing sensitive documents in personal storage, they are unlikely to seek advice from IT or IT Security departments. From this perspective, it’s hard to change such behavior, because a person has an established habit and may not recognize the associated risks. As a result, ‘unconscious incompetence’ is one of the most difficult issues to identify and solve with security awareness training,” comments Denis Barinov, Head of the Kaspersky Academy.

To learn more about how the adaptive learning approach can be applied to make employees behave more securely, please visit the official Kaspersky Adaptive Online Training web page.

About Kaspersky

Kaspersky is a global cybersecurity company founded in 1997. Kaspersky’s deep threat intelligence and security expertise is constantly transforming into innovative security solutions and services to protect businesses, critical infrastructure, governments and consumers around the globe. The company’s comprehensive security portfolio includes leading endpoint protection and a number of specialized security solutions and services to fight sophisticated and evolving digital threats. Over 400 million users are protected by Kaspersky technologies and we help 250,000 corporate clients protect what matters most to them. Learn more at www.kaspersky.com.

About Area9 Lyceum

Area9 Lyceum builds 21st century skills and competencies through the world’s first four-dimensional learning platform, Area9 Rhapsode™. Based on more than 20 years of research into human factors and cognition, our AI-based platform delivers truly personalized learning at scale -cutting training time in half, guaranteeing proficiency and making lasting impacts on careers and business outcomes. www.area9lyceum.com

Working-from-home lessons: employees ‘confidently’ make 90% of all security awareness mistakes

Free security awareness training on remote working from Kaspersky and Area9 Lyceum has seen participants enact correct responses 66% of the time.
Kaspersky logo

About Kaspersky

Kaspersky is a global cybersecurity and digital privacy company founded in 1997. Innovating the industry with a Cyber Immunity approach, Kaspersky safeguards consumers, businesses, critical infrastructure, and governments from cyberthreats, with over a billion devices protected to date.

Kaspersky ensures Cybersecurity True to Business, focusing on providing clear outcomes, protecting revenue, easing workloads and preventing downtime. Kaspersky’s deep threat intelligence and security expertise is constantly transforming into innovative solutions and services for organizations of every size, from small businesses to large enterprises, combining proven AI-driven protection technologies with simple management and expert support.

Recognized in independent tests and trusted by millions of individuals worldwide and nearly 200,000 organizations, Kaspersky helps detect threats earlier, respond faster and operate with greater confidence and freedom, protecting what matters most to our clients. Learn more at www.kaspersky.com.

Related Articles Press Releases