Security Awareness
Security awareness helps you recognize common cybersecurity and privacy risks, choose safer actions, and report suspicious activity. It also helps organizations build learning programs that turn policies into repeatable behavior.
itCybersecurity fundamentals and governance | OpenSkills.info
Course pathWalk it in order
Look it upDip in anytime
Go furtherLeaves this page
Don't Panic
Don't Panic: Security Awareness
Security awareness is the habit of noticing when ordinary work has wandered into a cybersecurity or privacy decision. The inconvenient part is that ordinary work does this constantly. Messages arrive. Accounts ask to be signed into. Files need sharing. Requests announce that they are urgent, which is not a proof of urgency any more than a loud alarm is a fire drill.
The useful mental model has four moves: pause, verify, protect, and report. Pause interrupts the bit where pressure makes the decision for you. Verify means using a trusted route you already know, such as a saved contact, a directory, an official service opened separately, or the normal approval process. If the suspicious request supplied the only contact method, it has helpfully demonstrated why that method cannot verify it.
Protecting an account means more than having a password, because a reused password spreads one exposure across several accounts. Multifactor authentication adds another kind of identity evidence, but an unexpected prompt is not a little button asking for encouragement. Do not approve it. Do not share the code. Deny it and use the reporting path.
The surprising part is that a polished message proves almost nothing. A strange message might be legitimate, and a convincing one can be malicious. The message is not the court of appeal. The separate verification route is. That is why the safer action depends on clear processes, approved tools, and responsive help as much as it depends on a careful recipient.
Reporting is not a confession booth. It gives responders time, context, and evidence. If you clicked, replied, downloaded something, or approved a prompt, stop further interaction and report the facts. Do not delete evidence or start an improvised investigation. There are professionals for that, and they prefer facts to archaeology.
For the compact version, open the Cheatsheet and keep the signals and reporting checklist nearby. The Slides show how the decision loop, account protection, reporting, and the learning-program life cycle fit together. Use the Practice Reference for a fictional request before a real one arrives at an inconvenient moment. The Quiz checks the judgment calls that look obvious only after the incident.
Where this skill leads
Relevant careers
See how this topic contributes to broader role-level skill maps.
Sources
- https://csrc.nist.gov/pubs/sp/800/50/r1/final
Supports
- Definitions of awareness, awareness content, and awareness training
- Foundational and role-based learning for personnel
- Cybersecurity and privacy learning program scope and life cycle
- Behavior goals, security culture, measurement, evaluation, and improvement
- Limits of completion counts and the use of multiple assessment methods
- Quiz answers about program purpose, learning layers, and measurement
- https://csrc.nist.gov/projects/cybersecurity-framework/filters
Supports
- Awareness and Training category and general-task outcome PR.AT-01
- Recognition and reporting of social engineering and suspicious activity
- Basic cyber hygiene, assessment, and refresher examples
- Role-based awareness and training outcome PR.AT-02
- https://csrc.nist.gov/glossary/term/awareness_training
Supports
- Awareness training as foundational learning for all personnel
- Protection of information, cybersecurity, and privacy-related assets
- Acceptable use and organizational system risk orientation
- https://www.cisa.gov/secure-our-world
Supports
- Recognizing and reporting phishing
- Strong unique passwords and password-manager use
- Enabling multifactor authentication
- Installing software updates
- https://www.cisa.gov/more-password
Supports
- Multifactor authentication concepts and factor categories
- Account protection beyond passwords
- Differences in MFA strength
- FIDO and WebAuthn as widely available phishing-resistant authentication
- Quiz answers about unexpected authentication prompts and MFA limits
- https://github.com/sindresorhus/awesome
Supports
- Discovery of the Awesome Security and Awesome Security Card Games lists
- https://github.com/sbilly/awesome-security
Supports
- Discovery of Gophish as an open-source phishing framework
- https://github.com/Karneades/awesome-security-card-games
Supports
- Discovery of Security Cards and Backdoors and Breaches
- Security card games as training and discussion resources
- https://getgophish.com/
Supports
- Authorized phishing campaign templates, scheduling, result tracking, and REST API
- Gophish Awesome Links rationale
- https://securitycards.cs.washington.edu/
Supports
- Threat brainstorming across human impact, motivations, resources, and methods
- Educational and industry activities
- Security Cards Awesome Links rationale
- https://www.blackhillsinfosec.com/tools/backdoorsandbreaches/
Supports
- Cooperative incident-response tabletop exercises
- Attack paths, detections, procedures, and debrief-driven improvements
- Backdoors and Breaches Awesome Links rationale
