Creating a Culture of Security

November 16, 2021
A person in a suit holding a shield with a lock icon and a human figure, symbolizing security and protection.

Credit: iStock/LeoWolfert

Every manufacturer should hold cybersecurity awareness training for all their staff at least once a year. Many people are spooked by the mere mention of the words “cybersecurity” and “training,” so October seems like an appropriate time for it. Your training should, at a minimum, cover relevant company policies such as your IT security, information security, and physical security.

Over the years many of us have taken this type of training and learned to dread it. Training where someone gives the exact same cybersecurity speech they gave last year and then hands out a paper for you to sign saying you were there. A real snoozefest. This kind of training does its job as far as meeting the bare minimum but has little impact on actually molding employee behavior.

The real purpose of cybersecurity awareness and training efforts should be to create a culture of security, meaning that employees should view good cybersecurity practices as good business and as part of “how we do business here.” Employees should feel enabled to make good cybersecurity decisions and understand what makes a good decision. Awareness and training should focus on:

  • Stopping risky behavior: Help employees know what decisions can lead to a bad outcome. For example, opening email attachments from unknown sources.
  • Encouraging less risky behavior: Help employees understand and care about implementing processes that increase security. For example, how to make strong passwords.
  • Turning employees into sentinels: Help employees recognize and respond to a cybersecurity event. For example, what to do if a guest plugs an unauthorized USB drive into a machine.

Ideally, training should be a continuous effort. Some ideas on how to include cybersecurity training in the everyday workings of your business include:

  • Regularly emphasize cybersecurity as an important goal of your company.
  • Integrate one cybersecurity tip, trick or reminder into every meeting.
  • Post reminders around the workplace about appropriate security practices.
  • Have regular meetings to discuss possible process improvements which can make it easier for employees to make better security decisions.

There has been a lot of research into what good employee cybersecurity training looks like. In general, it can be summed up using the acronym “RAINSTORMS.” Yes, I just made that up right now.

  • Real: Using real-world case studies or realistic scenarios help bring home the lessons.
  • Actionable: Include something that employees can do immediately. This may include changing their passwords, making an inventory of their IT assets or making sure they have contact information for the person or organization they should report an incident to in their phones. Sometimes a long-term homework assignment is appropriate as well, but having an immediate goal is always helpful.
  • Interactive: Role-play, small group discussions or hands-on exercises are some great ways to make training more interactive. Ideally, the interactions should include bi-directional conversations involving all levels of management to ensure everyone knows that everyone has the same responsibilities, and everyone is on the same page.
  • New: Some repetition is appropriate in training, especially when talking about policies, but it shouldn’t get stale. Different training formats (e.g. lecture, role-play, videos) can help.
  • Small: Bite-size chunks of information are much easier to digest than an entire computer science degree worth of information forced upon employees. One topic at a time is generally preferable.
  • Testable: There should be a measurable, testable goal for the cybersecurity training. If it’s general awareness, perhaps a quiz can be developed. If a goal is to mitigate phishing attacks, perhaps a fake phishing email can be sent both a few weeks before and a few weeks after the event. This will help show how effective the training was.
  • Owned: Employees should leave the training feeling a sense of ownership and that cybersecurity is their responsibility; they should feel empowered to make good cybersecurity decisions.
  • Relevant: Most companies have different types of users. Tailoring training to each type of user makes it more real. This may mean having different training for shop floor employees versus office employees.
  • Memorable: Use acronyms, pithy mnemonics, or, my personal favorite, humor. Humans remember funny things – puns, bad music videos, ridiculous memes of cats – much better than a boring lecture. Don’t be afraid to make it unconventional and have fun.
  • Simple: Above all else, training should be simple. Overly technical lessons full of technobabble are only good for putting people to sleep.

The National Initiative for Cybersecurity Education (NICE) has a small list of free and low-cost resources to help with employee training. There are also many additional resources available online. Just do an internet search and you’ll be bombarded with options. Evaluate those options using the RAINSTORMS template above.

Not sure where to start? You can learn more about how to implement an effective cybersecurity training program by contacting CONNSTEP. You can also access cybersecurity resources for manufacturers on the NIST MEP website.

 

This article originally appeared on NIST’s Manufacturing Innovation blog and is reprinted with permission

Recent Posts

Penn Globe logo over a room with people, possibly a conference.
February 11, 2026
Learn how Penn Globe partnered with CONNSTEP to invest in employee training, strengthen skills, and support business growth and competitiveness.
Logo of Specialty Cable Corporation (SCC) in a warehouse setting.
February 10, 2026
See how Specialty Cable Manufacturers partnered with CONNSTEP to strengthen quality systems and successfully achieve AS9100 recertification.
People in a factory setting, with the Forum Contract Manufacturing logo in the foreground.
February 9, 2026
Learn how Forum Plastics partnered with CONNSTEP to invest in supervisory training, strengthen leadership skills, and support long-term growth.
Logo of the letter
February 8, 2026
See how a Connecticut printing company partnered with CONNSTEP to improve efficiency, reduce waste, and advance environmental sustainability.
Beekley Medical logo with text
February 7, 2026
Learn how a medical products manufacturer partnered with CONNSTEP to strengthen quality systems and achieve successful recertification.
Pursuit Aerospace logo over a blurred medical equipment background. The logo is white text on a black rectangular box.
February 6, 2026
See how an aerospace manufacturer partnered with CONNSTEP to conduct an internal quality audit and get back on track to compliance.
Woman in lab setting, logo overlay of Syn-Mar Products Inc., blue and white color scheme.
February 5, 2026
Learn how a home bathroom remodeling manufacturer partnered with CONNSTEP to use lean training to streamline operations and improve efficiency.
Logo for Wild CNC Machining Services on a blue background.
February 4, 2026
See how a manufacturer partnered with CONNSTEP to update HR policies, strengthen people practices, and support future business growth.
Modelcraft Co. logo over a blue background featuring a machine shop with machinery.
February 2, 2026
Learn how a manufacturer partnered with CONNSTEP to apply continuous improvement measures that reduced setup and inspection time.
Logo for Siftex,
February 2, 2026
See how a manufacturer partnered with CONNSTEP to elevate supervisory skills, improve performance, and boost overall productivity.
Show More