Caputo Deanna D, Danley Lura, Ratcliff Nathaniel J
The MITRE Corporation, McLean, VA, United States.
Front Psychol. 2024 Jul 31;15:1410426. doi: 10.3389/fpsyg.2024.1410426. eCollection 2024.
Numerous security domains would benefit from improved employee risk recognition and reporting through effective security training. This study assesses the effectiveness of a new skills-based training approach to improve risk recognition and reporting of malicious elicitations. Malicious elicitations are techniques that strategically use conversation (i.e., online, in writing, in person, or over the phone) with the sole purpose of collecting sensitive, non-publicly available information about business operations, people, or technological assets without raising suspicion. To an untrained observer, a skilled elicitor can make conversations seem analogous to many professional networking situations such as those experienced over email and at conferences. A 12-month longitudinal experimental study was conducted to test training effectiveness on employees of a large corporation that focuses on serving national security needs and the public interest. Half of participants were randomly assigned to receive traditional awareness-based training (i.e., reviewing informational slides) while the other half of participants received a new skills-based training that allowed them-over the course of five weeks-to iteratively practice skills learned in the training and receive feedback on their performance in their day-to-day work environment. Following training for both experimental groups, malicious elicitations and benign professional networking test messages were sent (via email & text message) to unaware employee participants for 12 months. Findings revealed that skills-based training improved reporting of malicious elicitations and lasted for up to 12 months compared to traditional awareness-based training.
许多安全领域将受益于通过有效的安全培训来提高员工对风险的识别和报告能力。本研究评估了一种新的基于技能的培训方法在提高对恶意诱导的风险识别和报告方面的有效性。恶意诱导是指策略性地利用对话(即在线、书面、面对面或通过电话),其唯一目的是收集有关业务运营、人员或技术资产的敏感、非公开信息,且不引起怀疑。对于未经训练的观察者来说,熟练的诱导者可以使对话看起来类似于许多专业社交场合,比如通过电子邮件和在会议上经历的那些场合。进行了一项为期12个月的纵向实验研究,以测试针对一家专注于满足国家安全需求和公共利益的大公司员工的培训效果。一半的参与者被随机分配接受传统的基于意识的培训(即查看信息幻灯片),而另一半参与者接受一种新的基于技能的培训,这种培训使他们在五周的时间里能够反复练习在培训中学到的技能,并在日常工作环境中获得关于其表现的反馈。在两个实验组都完成培训后,为期12个月向不知情的员工参与者发送(通过电子邮件和短信)恶意诱导和良性专业社交测试信息。研究结果显示,与传统的基于意识的培训相比,基于技能的培训提高了对恶意诱导的报告率,并且持续了长达12个月。