TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Ask HN: Security Awareness Training

8 点作者 phunel超过 3 年前
I&#x27;m at a bit of a loss. Just wanted to ask the community if there were any recommendations for decent security awareness training. This requirement is coming up more and more with regulators and underwriters.<p>In essence, this is of course more &#x27;box ticking&#x27; and has little to do with actual security, but the requirement remains.<p>Would love to hear from actual experience. I&#x27;ve gotten quotes from about a half dozen suppliers and I&#x27;ve yet to find a supplier that the staff wouldn&#x27;t hate me for subjecting them to. The materials are almost universally pretty childish and melodramatic.<p>Saw the Stacksi launch earlier last year and they seem to have the right idea for this domain. Would love to find a comparable company but offering security awareness training - or if the Stacksi guys are reading this, please consider adding this to your product line up! :)

7 条评论

andersonmvd超过 3 年前
If it&#x27;s a general course, you can even pay a udemy course to each employee for 15 bucks each (or even less for companies?) like <a href="https:&#x2F;&#x2F;www.udemy.com&#x2F;course&#x2F;security-awareness-training&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.udemy.com&#x2F;course&#x2F;security-awareness-training&#x2F;</a>? Haven&#x27;t tested it, but for box ticking it may be enough.<p>If it&#x27;s for developers or engineers, I&#x27;ve been working on the approach that you get security awareness when working with security engineers. The idea to have a security person close to your team that will teach in practice what it&#x27;s hard to absorb with some courses out there. Not a replacement for a course, but another way to learn. For more details on this, the info is on my profile.
评论 #30294060 未加载
kespindler超过 3 年前
Depending on the size of your team, and whether you just need to &quot;check a box&quot; and say you do it, versus you&#x27;re actually worried about employee mistakes re: cybersecurity (e.g. you have a big and varied enough team where training is geniunely important), it&#x27;s pretty easy to design this yourself.<p>Write up or copy a few page doc outlining security best practices, then require every employee to read &amp; sign an acknowledgement that they&#x27;ve read it. Now every employee has gone through security training.
chair6超过 3 年前
Check out SafeStack, <a href="https:&#x2F;&#x2F;academy.safestack.io&#x2F;safestack-courses&#x2F;security-awareness&#x2F;" rel="nofollow">https:&#x2F;&#x2F;academy.safestack.io&#x2F;safestack-courses&#x2F;security-awar...</a> .. they&#x27;re one of the less-cringey, more-modern awareness options I&#x27;ve seen recently.
评论 #30294189 未加载
binarybyes超过 3 年前
If you want a company that is trying to change the paradigm around security awareness training, I&#x27;d highly recommend looking at Ninjio: <a href="https:&#x2F;&#x2F;ninjio.com&#x2F;" rel="nofollow">https:&#x2F;&#x2F;ninjio.com&#x2F;</a><p>They take a drip-feed approach, with one 5ish minute video monthly rather than an hour yearly. People don&#x27;t mind 5 minutes once a month, and as a bonus, it has been shown that the drip feed method helps to keep security on peoples minds, as well as increase their overall retention
rdj超过 3 年前
If it’s security training for developers, architects, and technical teams take a look into the CTF style trainings (hands on keyboard, hacking exercises). We’ve turned it into an annual event (leaderboards, trophies, bragging rights, swag, pizza, the works) and the participants not only loved it, they have started to pregame, plan teams and held live debriefs where they talk through the experience and where it actually impacts their code.
plasma超过 3 年前
Haven’t used them myself, but I see <a href="https:&#x2F;&#x2F;www.securecodewarrior.com" rel="nofollow">https:&#x2F;&#x2F;www.securecodewarrior.com</a> mentioned, aim is to teach developers and seems engaging.
jiveturkey超过 3 年前
Did you look at eset? They have a free one too. I&#x27;m at a loss as to how Stacksi is relevant. They do some AI form filling for you. How&#x27;s that going to apply to security awareness training.