Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Wednesday, 3 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

(ISC)2 – Training is a tricky journey, but standards have to be achieved

by The Gurus
March 6, 2015
in Editor's News
Share on FacebookShare on Twitter

Information security training is a journey, it takes time but standards demand capabilities.
Speaking at the Think Charity conference in London, organised by the Charities Security Forum, (ISC)2 EMEA managing director Adrian Davis said that being part of the security profession gives you certain rights and responsibilities, but as we try to create more of a profession, we need to be aware of what is going on.
“There is a 25 per cent growth in Europe in standards,” he said. “The Government is using ISO 27001 and if you are not, there is a gap in your professional knowledge. Also it is not just about PCI DSS compliance, you can implement the Cyber Essentials scheme which is cheap, easy and a great place to start.”
Davis encouraged delegates to consider how the adversary works, and said that what they do is what we “need to know about and implement and recommend and remediate and address”.
He said: “The skills of hackers are good and we deal with people who are interested in you and after your money and you need knowledge to defend against them and the better equipped and better knowledge you have and better you communicate it, the better for you and your organisation.
“Ten to twelve years experience is no longer enough, you need to top up with more knowledge and if you want to change jobs, it always looks better with letters after your name!”
Moving on to staff training, Davis said that as staff are not experts, and never will be unless they follow you, you need to tell them when and how to do things right and do the right thing every day in their jobs. “You have a responsibiliy to employees so you can recommend how to put up minimum defence,” he said.
“Only two policies get read – expenses and holiday. Think about what you get from it, as long as you get value and what the organisation needs. How do you make them secure and help them, and how do you help the organisation do things more securely. That is the key to your training.”
Davis concluded by saying that change what it is you do, as you need to talk to people who understand but may not be experts in communications, so use those staff who have expertise in communications and tailor messages to the different people that you want to reach.
He said: “It is a journey. If they do it once, they remember it for two days. Bring people along and get them to listen and accept what you are telling them is important. It takes time and the only thing you can do is to give it time. It is frustrating but if you don’t, you don’t get anywhere.”

Tags: SkillsStandardsTraining
ShareTweet
Previous Post

NCA arrest 57 across the UK on cyber charges

Next Post

Microsoft warn on Secure Channel FREAK vulnerability link

Recent News

Nagomi Control Brings CTEM Into Action

IT Security Guru picks for Infosecurity Europe 2026

June 1, 2026
Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

June 1, 2026
Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

May 29, 2026
Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

May 28, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol