➡️ Emmanuel NICAISE’s Post

View profile for ➡️ Emmanuel NICAISE, graphic

Expert in Cybersecurity & (Human) Risk Management | Psychologist | Integrating IT, Governance, & Psychology for Enhanced Security

The #human aspects of #cybersecurity are really poorly adressed in most security #frameworks. Neither #ISO27002, #NIST CSF, #PCI-DSS, #DORA, nor our Belgian NIS2 framework #cyfun, go further than making #securityawareness and cybersecurity #trainings mandatory. Ok, it is not bad, it is just not enough. If you stick to this only, it won't change your risk posture as we need to change behaviours to reduce risks. The only standard that seems to really grasp the importance of human risk management and how to make a positive impact on it is the #ECB (European Central Bank) "Cyber resilience oversight expectations for financial market infrastructures" (#CROE). That is, up to my current knowledge (and I would be glad to discover other ones), the only regulatory requirement in Europe that address cybersecurity #culture and #behaviour: Just one example - Requirement 36 of the Role of the Board and senior management: "Senior management should validate the effectiveness of its cyber resilience training programme (e.g. social engineering or phishing tests) and assess whether training and awareness programmes positively influence behaviour. Based on the lessons learned from its training programme, the FMI should improve the employee awareness programmes." Centre for Cybersecurity Belgium, it would be great if you could include some of their wisdom in the next version of your fabulous CyFun. It would confirm again Belgium as leader in Cybersecurity.

  • No alternative text description for this image
Patrick Coomans

Global Product Owner Cybersecurity at Vinçotte KIWA | Industrial Automation and Control Systems (IACS) ICS OT IT IOT NIS2 ISO27001 CYFUN | Private Pilot | Security Cleared ✅

1mo

Personally I'm not a fan of "human aspects", that only scratches the surface. I rather like to refer to cyber #culture as that's something recognizable from other domains like safety. Let's not reinvent the wheel in cyber but look at how the culture aspect is embedded in safety in aviation, shipping, NPP's, health, etc. For example Just Culture, part of the ten principles for safety in aviation. https://skybrary.aero/sites/default/files/bookshelf/2882.pdf

To view or add a comment, sign in

Explore topics