Security awareness

Insider threats

Risks from employees, former employees, contractors, or partners, intentional or accidental.

Train staff to spot the behavior indicators: altered state or substance abuse (impaired judgment, coercion), emotional distress (non-compliance, exploitation), lifestyle incongruence (spending beyond income), and financial struggles (susceptibility to bribery).

Build an insider threat program: encourage reporting, train on warning signs, support mental health and finances, run fair and confidential investigations, and use user activity monitoring while respecting privacy.

Password managers

Reusing passwords is dangerous: one breach exposes every site sharing that password, and most usernames are email addresses.

Managers store and encrypt unique credentials behind one master password and auto-fill logins. Built-in browser managers exist, but third-party tools (Bitwarden, Dashlane, and the like) are generally preferred for stronger security.

Avoiding social engineering

Social engineering uses deception to exploit human psychology; awareness is the first defense.

Run simulated phishing exercises and train everyone regardless of rank.

Policies and handbooks

A policy is the rules guiding decisions; a handbook is the detailed reference guide (employee, training, compliance). They cover data protection, remote work, technology use, conflicts of interest.

Review at least annually to track new and changing threats, and make sure employees are aware of updates. Policies can’t cover every scenario, so employees should understand the why, to make good judgment calls and report gaps.

Remote and hybrid work

Working outside the office loses physical controls and exposes data over weaker home and public networks, plus a higher device loss and theft risk.

Address it with remote-work policies, VPNs, MFA, company-issued devices with current security software, BYOD rules, automated backups, end-to-end-encrypted collaboration tools, and regular audits.

Creating a culture of security

Technical controls fail if employees don’t value security. Embed it through organizational change management (starting with executive commitment, framed as shared responsibility), a development phase (actionable plans, policies, education), an execution phase (ongoing training, simulated attacks), and reporting and monitoring (compliance checks, feedback loops).

The payoff: resilience, inherent vigilance, and a trust-based reputation.

Exam quick facts

SY0-701 domains by weight: Security Operations (28%), Threats, Vulnerabilities, and Mitigations (22%), Security Program Management and Oversight (20%), Security Architecture (18%), General Security Concepts (12%).

No penalty for guessing, so mark hard questions for review, skip, and come back.