Security awareness
Insider threats
Risks from employees, former employees, contractors, or partners, intentional or accidental.
Train staff to spot the behavior indicators: altered state or substance abuse (impaired judgment, coercion), emotional distress (non-compliance, exploitation), lifestyle incongruence (spending beyond income), and financial struggles (susceptibility to bribery).
Build an insider threat program: encourage reporting, train on warning signs, support mental health and finances, run fair and confidential investigations, and use user activity monitoring while respecting privacy.
Password managers
Reusing passwords is dangerous: one breach exposes every site sharing that password, and most usernames are email addresses.
Managers store and encrypt unique credentials behind one master password and auto-fill logins. Built-in browser managers exist, but third-party tools (Bitwarden, Dashlane, and the like) are generally preferred for stronger security.
Avoiding social engineering
Social engineering uses deception to exploit human psychology; awareness is the first defense.
- Situational awareness counters shoulder surfing and eavesdropping (privacy screens, secure discussions).
- Piggybacking and tailgating (someone follows authorized staff through a door): use access control vestibules.
- Dumpster diving: dispose of sensitive data securely (shredding).
- OPSEC: protect critical info and routines, and don’t overshare on social media.
- Baiting uses dropped USB drives or cables. Don’t connect found devices; carry your own charger.
- Pressure tactics manufacture urgency to bypass procedure. Slow down when rushed.
Run simulated phishing exercises and train everyone regardless of rank.
Policies and handbooks
A policy is the rules guiding decisions; a handbook is the detailed reference guide (employee, training, compliance). They cover data protection, remote work, technology use, conflicts of interest.
Review at least annually to track new and changing threats, and make sure employees are aware of updates. Policies can’t cover every scenario, so employees should understand the why, to make good judgment calls and report gaps.
Remote and hybrid work
Working outside the office loses physical controls and exposes data over weaker home and public networks, plus a higher device loss and theft risk.
Address it with remote-work policies, VPNs, MFA, company-issued devices with current security software, BYOD rules, automated backups, end-to-end-encrypted collaboration tools, and regular audits.
Creating a culture of security
Technical controls fail if employees don’t value security. Embed it through organizational change management (starting with executive commitment, framed as shared responsibility), a development phase (actionable plans, policies, education), an execution phase (ongoing training, simulated attacks), and reporting and monitoring (compliance checks, feedback loops).
The payoff: resilience, inherent vigilance, and a trust-based reputation.
Exam quick facts
SY0-701 domains by weight: Security Operations (28%), Threats, Vulnerabilities, and Mitigations (22%), Security Program Management and Oversight (20%), Security Architecture (18%), General Security Concepts (12%).
No penalty for guessing, so mark hard questions for review, skip, and come back.