It all starts with a seemingly innocent email.
Joanne wants to connect with you on LinkedIn.
But lurking behind that email is an invisible threat that could cost your government agency millions of dollars and destroy your reputation.
IT does its best to protect against different kinds of cyberattacks. But phishing is a different beast. Employees all over your organization are targets. And with a single click any one of those emails could trigger a data breach costing upward of $7 million.
Government employees seem to be vulnerable to phishing attacks. A recent study found that phishing emails to government employees had one of the highest click through rates (CTR) out of 15 different industries, with an average CTR of over 17 percent. To put that in perspective, the CTR for an average email marketing campaign is about 3 percent.
This problem isn’t just going away. Attacks are increasing in frequency. Employee susceptibility is going to be a huge problem. Government agencies need to buckle down on phishing training to protect themselves against hackers who are getting bolder and smarter.
The problem with current phishing training
The majority of organizations run an annual security awareness coursedelivered via eLearning. But training your employees just once a year has some significant drawbacks.
For starters, yearly security awareness courses tend to cram multiple topics into a one or two-day course. Critical information gets lost because there is simply too much to learn all at once.
In fact, multiple studies have shown that this kind of compressed training doesn’t correspond with how we learn. Researchers found that retention rates drop significantlywhen learning is done all at once. Training needs to be done over time so employees can practice recalling and applying information.
Another major issue with annual training is the lack of responsiveness to problems as they emerge. When you only train once a year, you have no idea whether employees are applying what they learn. There’s no way to address risky behavior before it causes a serious security issue.
Solution: Game-based training
What if I told you that you could test and train employees on phishing attacks year-round, measure the efficacy of the program as well as track employees who are particularly vulnerable, and do it in a way that wasn’t mind numbing but fun?
You’d probably think I was dreaming, but I’m not.
Game-based training lets you test and train government employees simultaneously, instantly correcting any risky behavior and reinforcing learning concepts. Instead of a one-and-done approach, game-based training lets employees practice recalling and applying information, which helps improve retention over time.
Game-based training also lets you measure results. You can track individual employees and measure their improvements over time, making it easier to prove your ROI and assess whether employees are applying what they learn. This is imperative — especially in high-stake situations like phishing attacks.
The bottom line
Phishing is a huge problem for government organizations, and it requires special attention in training. You can’t just lump phishing attacks into your annual security awareness course and think you’re covered.
Game-based training can help ensure your phishing training is effective because it tests and reinforces key security policies year-round. However, it’s important to remember that not all game-based training programs are built equally.
Make sure to look for programs that offer the ability to test employees on an ongoing basis, train employees who fail those tests, and have a deep analytics suite to measure results.
John Findlay is co-founder of Launchfire, a digital engagement shop
that builds game-based eLearning programs that make training fun, addictive and effective.
You can learn more about John at http://www.launchfire.com/aboutor visit https://www.phishingderby.com.




