EU Regulating InfoSec: How Detectify helps achieving NIS 2 and DORA compliance
**Disclaimer: The content of this blog post is for general information purposes only and is not legal advice. We are very passionate about cybersecurity rules and …
Detectify
Security is not compliance. This is something that the security champions at Detectify can agree on and each employee practices security everyday to help keep our customers and business secure.
You’ve probably never met a more engaged group about security training than us at Detectify! We are passionate about our industry and maybe even gain a few new security nerds every few months as we go.
To achieve ISO 27001 certification, the team at Detectify decided to create a group of Security Champions with members from every department to help spread security awareness across the organization. We asked some security champs to share their best practices for raising security awareness and culture.
As a Security Champion, how do you keep your teammates updated about security updates and training?
Hmm … I would probably say “there’s a slack channel for that!” Jokes aside, as part of the Support team, I get to see a lot of common and sometimes even creative attempts at trying to phish us. My best practice is to take screenshots when I see more sophisticated attempts and share examples within my team and company to drive awareness for the different attempts. We then discuss best practices, new processes and guidelines in the Support team and also Security Champions committee to keep things relevant.
Of course, it’s important to keep the basics in mind and give reminders to the team. Sometimes it only takes a 5 minute update in a week team meeting. It could be as simple as a post that explains:
Have you noticed any impact on your team’s information security practices or awareness since becoming a Security Champion?
Working in an already quite security savvy team we have a lot of awareness already, but I do my best to be clear about the purpose of why something needs to be done. I combine this together with gamification through quizzes and contests with small prizes. These are definitely more efficient than a simple Slack reminder. The only trick is figuring out what motivates your team members.
Since starting the ISO project and the security champions committee, I have definitely seen a change of mindset. My team members are more involved and we are all more quick to notice security risks like accidental screen shares rather than window shares here and there – it’s really cool to see! Even a thing such as labelling documentation with the right information classification label has been a very smooth process for people to adopt, which is awesome.
Since working at Detectify, have you picked up any pro tips for increasing security awareness and positive security culture in the day-to-day?
Let Detectify scan your web applications for the latest vulnerabilities, while you build the next big thing. Our passionate security defenders bring vulnerability research from hacker-to-scanner in as fast as 25 minutes.
Stay on top of threats and continue building safer web apps with Detectify. Discover how our security champions can bring clarity and scale to your application security with a free 2-week trial today.
**Disclaimer: The content of this blog post is for general information purposes only and is not legal advice. We are very passionate about cybersecurity rules and …
TLDR: This article details methods and tools (from DNS records and IP addresses to HTTP analysis and HTML content) that practitioners can use to classify …