Authored by Alison Cripps, Head of Workplace, In-House and Technology, Practical Guidance Privacy Awareness Week 2025: Australia's Bold Leap into a New Era of Privacy Law Australia has taken a bold...
As law firms navigate a highly competitive and evolving market, the need for technology that drives efficiency, reduces costs, and delivers exceptional client service has never been more crucial. A recent...
Q&A with Richard Douglas KC, Gerard Mullins KC, and Simon Grant Annotated Civil Liability Legislation - Queensland, 6th edition is the essential companion for practitioners engaged in the conduct of...
Q&A with Dr Greg Byrne and Dr Jacqui Horan Sexual Assault Trials: Challenges and Innovations offers a comprehensive examination of the systemic issues in sexual assault trials across common law jurisdictions...
The Total Economic Impact™ of LexisNexis® Lexis+ AI for Large Law Firms, a commissioned study conducted by Forrester Consulting on behalf of LexisNexis, May 2025, projects that large law firms could achieve...
It’s becoming increasingly obvious that in order to mitigate cyber security risk, companies need to train their staff in how to identify and respond to IT threats. When over 90% of IT breaches are via staff, it would be prudent to accept this as major risk.
In its simplest form, there are three stages in the cyber security awareness maturity model:
Of course, it’s ideal if you can build an amazing security first culture with highly skilled staff as your main defence, and the results should pay for themselves many times over. Here’s some pointers on how you can get started:
Realise: Staff are your biggest target for IT criminals, and they are also your greatest asset in waiting. Use them wisely to achieve amazing results.
Human Error: For so long we’ve been told that staff being tricked by cyber criminals is human error. It’s not. If your staff have not been educated in cyber scams, how can they avoid being tricked? Remember - you don’t start a program of change by telling people they are the problem. You start it by telling them they are the solution!
Change Management: Get people along for the ride. Get them excited about what’s coming up, tell them how it will keep them and their family safer at home. Their money, their identity, their bank accounts, their kids online. What they apply at home, they will apply at work.
Perceptions: People think that IT criminals are hooded characters trying to hack firewalls. The reality is that largely they are normal people who are good at tricking people! It’s vital that staff understand that they are the primary target, at home and in the office.
Management Mindset: People will make mistakes, but you must nurture and encourage them. Hit them over the head with a book one time for making a mistake, and you’ve lost them. Praise them for asking for help or reporting being tricked, and they will continue to fight the fight, and you’ve effectively identified your weak spots and can help them to improve further.
Champions: Change should flow top down, so get management onboard, and attending training initiatives. Build a team of staff who can act as ‘go to’ resources for when people have questions. Live it, breathe it!
The most important thing however is just getting started. There are plenty of free resources available to at least get started on the maturity journey, and as you identify what works and doesn’t work for your company, you can tailor your program for better results over time.
Read full article via the Risk Management Bulletin. For more information, contact us below.