Towards a Model for Building Public Awareness for Successful Cybersecurity Skilling

TOWARDS A MODEL FOR BUILDING PUBLIC AWARENESS
Aim/Purpose The aim of this study was to create a Cybersecurity awareness model that can guide the design of an effective cybersecurity awareness programme.

INTRODUCTION

The introduction of new information and communication technologies (ICT) positioned modern societies in a constant state of flux. The consequence is that the evolution of technology increases risk and its safe and secure use. Hence, safety and security awareness is no longer simply a luxury, but a necessity as cybersecurity threats come in various forms (e.g. intrusion, denial of services, viruses) and are increasingly threatening individuals, companies and national critical digital infrastructure. In this regard, the literature suggests that a large portion of the South African population that has not had regular and sustained exposure to technology and broadband Internet access, expose local communities to cyber threats (Grobler, Van Vuren & Zaaiman, 2013).

An ‘emergent skill need’ is defined as the change in skills that are needed to adequately fulfil a certain job function in the future (Dijkgraaf, 2009) and, for starting learning these skills public awareness is crucial (ECORYS, 2010). The cybersecurity skills are such kinds of skills. Furthermore, being a part of a learning continuum (awareness-training-education), awareness is an essential first step but can also include cybersecurity basics literacy (NIST, 2016).

Despite certain authors’ suggestion that there are some clear indications of attempts to raise cybersecurity awareness and to establish an effective cybersecurity culture in South Africa (e.g. Kritzinger, Bada & Nurse, 2017), the literature review revealed that there are no readily available works specifically dedicated to the models for building the cybersecurity awareness programmes - as a precursor for skilling South African workforce and population and developing an appropriate cybersecurity culture.

However, there are some academic works from other fields that confirm needs for building public awareness in order to enhance interest in certain skills (Gould, 2002). This is also supported by supplementary voices for the South African industry that point out the importance of awareness campaigns for cybersecurity skilling (Mybroadband, 2018). This importance is also recognised internationally. For example, in May 2108, the Computer Education in India organised an awareness programme regarding skill development programs launched by Prime Minister, Narendra Modi, for the awareness of the students and public at large (Daily Excelsior, 2018).

The cybersecurity campaigns in South Africa are officially led by the Cybersecurity Hub (Department of Telecommunications and Postal Services) but this entity is currently under-resourced and is not being able to effectively plan and deliver such campaigns (Mitrovic, 2018). While some organisations are launching cybersecurity awareness programs, citizens are rarely offered such a programme or campaign. In this regard, government responsibility cannot be ignored but governments cannot do the job alone. It seems that a lot remains to be done, especially in terms of changing societal attitude through targeted cybersecurity awareness campaigns.

All the above suggests that there is a need for a model that will guide cybersecurity awareness campaigns for building appropriate consciousness for the need of cybersecurity skilling. This conceptual paper, therefore, proposes a model that can be used for building an effective cybersecurity awareness programmes in the South African companies and society or, possibly, elsewhere. The further structure of this paper is as follows: a brief description of the approach to this study is given, followed by the presentation of the reviewed literature. The subsequent section presents the proposed cybersecurity awareness model, which is followed by the concluding remarks.

Continued in the full PDF...
DOWNLOAD THE FULL PDF

 

🌩️ Secure Your Future with StormWarning!🌩️

 

Is your digital infrastructure prepared for the storm of cyber threats?
At StormWarning!, we've got you covered. We specialize in cutting-edge Cyber Security and NIST CSF Auditing solutions that safeguard your business from today's relentless security challenges.

🔒 Why Choose StormWarning!? 🔒

Proven Expertise: Our team of cybersecurity professionals is equipped with years of experience and up-to-the-minute knowledge to protect your assets.

Comprehensive Services: We offer a full suite of services, including Cybersecurity Awareness, Risk Mitigation, and NIST CSF Auditing to ensure you're fortified against every threat.

Tailored Solutions: We understand that every business is unique. Our solutions are customized to fit your specific needs, ensuring your peace of mind.

Government Compliance: Worried about regulatory requirements?
Our NIST CSF Auditing services guarantee your compliance with government standards.

🚀 Empower Your Business with StormWarning! 🚀

Don't let cyber threats disrupt your operations or compromise your data.
Partner with StormWarning! today and take control of your digital security.
It's time to weather the storm with confidence.

Shield your business with StormWarning!, the cybersecurity and NIST CSF Auditing experts you can trust.
🌐 Learn more at https://StormWarning.co.za.

 

CONTACT US NOW!
 
 

Related Articles

What is StormWarning! ?

 StormWarning! is a Cybersecurity consultancy. Our experienced team of cybersecurity experts provide cybersecurity assessments, cybersecurity training and cybersecurity solutions to organisations that have a high risk public profile. StormWarning! is your organisation's best defense against the ever growing cascade of innovative security threats raining down on all organisations with a public digital footprint.

What is Cybersecurity?

Cybersecurity is the practice of protecting critical systems and sensitive information from digital attacks. Also known as information technology (IT) security, cybersecurity measures are designed to combat threats against networked systems and applications, whether those threats originate from inside or outside of an organization. StormWarning! is constantly researching the latest cybersecurity threats and building innovative measures to prevent them.

 

NIST Audit & Targeted Cyber-Risk Training

StormWarning! offers comprehensive Cybersecurity Consulting, with a focus on its Automated Online Auditing Solutions, primarily the NIST CSF Readiness Audit. This audit is prioritized as its results directly inform the organization's needs for targeted cybersecurity training. By identifying specific gaps in risk management knowledge, they deliver precise education via Short Courses—like Cybersecurity Risk Management or Understanding Cybersecurity GRC—to ensure staff and leadership close deficiencies and maintain compliance.

Their full suite of services also includes robust Risk Management planning, development of essential Policies, impactful Cybersecurity Awareness Campaigns, and a security monitoring/incident response platform, StormFront. Additionally, we offer a resource library of Cybersecurity Books authored by our esteemed associate Dr. Zoran Mitrovic.