TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Ask HN: Security Awareness Training

8 pointsby phunelover 3 years ago
I&#x27;m at a bit of a loss. Just wanted to ask the community if there were any recommendations for decent security awareness training. This requirement is coming up more and more with regulators and underwriters.<p>In essence, this is of course more &#x27;box ticking&#x27; and has little to do with actual security, but the requirement remains.<p>Would love to hear from actual experience. I&#x27;ve gotten quotes from about a half dozen suppliers and I&#x27;ve yet to find a supplier that the staff wouldn&#x27;t hate me for subjecting them to. The materials are almost universally pretty childish and melodramatic.<p>Saw the Stacksi launch earlier last year and they seem to have the right idea for this domain. Would love to find a comparable company but offering security awareness training - or if the Stacksi guys are reading this, please consider adding this to your product line up! :)

7 comments

andersonmvdover 3 years ago
If it&#x27;s a general course, you can even pay a udemy course to each employee for 15 bucks each (or even less for companies?) like <a href="https:&#x2F;&#x2F;www.udemy.com&#x2F;course&#x2F;security-awareness-training&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.udemy.com&#x2F;course&#x2F;security-awareness-training&#x2F;</a>? Haven&#x27;t tested it, but for box ticking it may be enough.<p>If it&#x27;s for developers or engineers, I&#x27;ve been working on the approach that you get security awareness when working with security engineers. The idea to have a security person close to your team that will teach in practice what it&#x27;s hard to absorb with some courses out there. Not a replacement for a course, but another way to learn. For more details on this, the info is on my profile.
评论 #30294060 未加载
kespindlerover 3 years ago
Depending on the size of your team, and whether you just need to &quot;check a box&quot; and say you do it, versus you&#x27;re actually worried about employee mistakes re: cybersecurity (e.g. you have a big and varied enough team where training is geniunely important), it&#x27;s pretty easy to design this yourself.<p>Write up or copy a few page doc outlining security best practices, then require every employee to read &amp; sign an acknowledgement that they&#x27;ve read it. Now every employee has gone through security training.
chair6over 3 years ago
Check out SafeStack, <a href="https:&#x2F;&#x2F;academy.safestack.io&#x2F;safestack-courses&#x2F;security-awareness&#x2F;" rel="nofollow">https:&#x2F;&#x2F;academy.safestack.io&#x2F;safestack-courses&#x2F;security-awar...</a> .. they&#x27;re one of the less-cringey, more-modern awareness options I&#x27;ve seen recently.
评论 #30294189 未加载
binarybyesover 3 years ago
If you want a company that is trying to change the paradigm around security awareness training, I&#x27;d highly recommend looking at Ninjio: <a href="https:&#x2F;&#x2F;ninjio.com&#x2F;" rel="nofollow">https:&#x2F;&#x2F;ninjio.com&#x2F;</a><p>They take a drip-feed approach, with one 5ish minute video monthly rather than an hour yearly. People don&#x27;t mind 5 minutes once a month, and as a bonus, it has been shown that the drip feed method helps to keep security on peoples minds, as well as increase their overall retention
rdjover 3 years ago
If it’s security training for developers, architects, and technical teams take a look into the CTF style trainings (hands on keyboard, hacking exercises). We’ve turned it into an annual event (leaderboards, trophies, bragging rights, swag, pizza, the works) and the participants not only loved it, they have started to pregame, plan teams and held live debriefs where they talk through the experience and where it actually impacts their code.
plasmaover 3 years ago
Haven’t used them myself, but I see <a href="https:&#x2F;&#x2F;www.securecodewarrior.com" rel="nofollow">https:&#x2F;&#x2F;www.securecodewarrior.com</a> mentioned, aim is to teach developers and seems engaging.
jiveturkeyover 3 years ago
Did you look at eset? They have a free one too. I&#x27;m at a loss as to how Stacksi is relevant. They do some AI form filling for you. How&#x27;s that going to apply to security awareness training.