Your people are the most effective line of defence when it comes to Cyber Security. It’s a message that has been passionately expounded by cyber security experts for many years, but it has taken the recent hike in the profile of cybercrime for people start to really start listening.
Today’s webinar was a chance to gain a little insight into the topics of cybercrime and cyber awareness from two seasoned professionals with a wealth of first-hand experience. Nick Wilding leads the Cyber Resilience Best Practice division of AXELOS GBP – a joint venture between the UK Cabinet Office and Capita; and Vicki Gavin is Compliance Director and Head of Business Continuity, Information Security and Data Privacy at The Economist Group.
At Unicorn we are fortunate to count AXELOS among our strategic partners, and have worked closely with them to develop and continually improve RESILIA – an integrated best practice portfolio designed to put people at the centre of an organisation’s cyber resilience strategy. Ahead of the imminent relaunch of this suite, Nick and Vicki took some time to lend context to the need for cyber awareness training.
This morning’s webinar kicked off with a roundup of the latest statistics relating to cyber attacks:
“One thing’s for sure”, said Nick Wilding, “looking at the stats, it’s clear that at some point you will be breached.” The frequency and nature of these attacks are such that it’s easy to see where he’s coming from: over the past year alone we’ve seen everything from repeated attacks on the SWIFT network, to the sustained efforts of Russian hacking group Fancy Bear in their attempts to upset the US electoral process.
“To be honest, it’s easy to see why people end up with ‘security fatigue’, said Vicki Gavin. “We’re incessantly bombarded with frightening statistics to the point that sometimes these headlines end up just having the opposite effect. For me personally, I’ve found a way to leverage this kind of information, and the key is making it specific and relevant to the activities of your own organisation.”
“If we accept that people are our best line of defence”, continued Nick, “it’s shocking to think that in a recent study, we found that as many as 45% of organisations don’t do any kind of cyber security training, and of those that do, 81% are relying on mandatory training that is completed once a year or less.”
It’s about technology and people, not just bits and bytes.
– Vicki Gavin, The Economist
One of the anecdotes that AXELOS have come back to time and again is that of Jim Baines – a personal friend of Nick Wilding, and a CEO who has spoken at length about his traumatic experience at the hands of cybercriminals. Nick relayed this story today, and followed it with an extract from one of Baines’ letters that poignantly reminded others that none of us are invulnerable when it comes to falling foul of cybercrime. “Interestingly,” said Vicki, “what we seem to see time and again is the prevalence of this culture of blame. Whenever something happens, businesses are quick to want to assign blame – who’s fault was it? Who clicked on a malicious link? Who opened a phishing email? But when we’ve talked about organisations only offering cyber awareness training once a year, how are people supposed to learn?”
“They say it takes a minimum of three weeks to start developing a new habit,” she continued, “so what we really need is to start embracing this idea of continuous learning.”
When you consider AXELOS’ stats that of the firms supposedly running ‘effective cyber awareness training programmes’, no more than 50% of them had full completion rates, it’s little wonder that learning continues to be a barrier to resilience.
“In the simplest of terms, where it comes to awareness there’s too much stick and not enough carrot,” says Nick. “At the heart of it, people sometimes forget that cyber is an interesting topic – so engagement ought not to be something that’s seen as tedious.”
“The problem is often that people think just because someone is a cyber expert, that that automatically means they will be a good trainer”, asserted Vicki – followed by another acknowledgement that in order to achieve real engagement, it’s critical to make learning relevant to your target audience. Sharing her experiences of responding to attempted cyber-attacks mounted on The Economist in the past twelve months, Vicki pointed out that this is now becoming the norm for businesses operating in the digital age.
At the source of every error which is blamed on the computer, you will find at least two human errors, one of which is the error of blaming it on the computer. – Tom Gilb, US Systems Engineer
“I can tell you we’ve had 360 cyber events in the last year, of which 60 we might categorise as ‘incidents’, and 3 that were escalated to crises,” she said. “In the latter part of last year, we had a breach when an individual unwittingly gave away their user credentials by clicking on a link in a phishing email. Although the hackers then used this breach to send a further email to everyone in the business, of the 1400 people we have working for The Economist Group globally, only 50 people actually opened this email, and no one else clicked on anything. In summary, we had the whole thing contained in under 3 minutes. This is exactly the kind of compelling event that shows the true value of cyber awareness training to our board.”
Speaking about the need to promote awareness learning that really works to change behaviours across businesses, Nick said: “What we come back to time and again is this theme of storytelling – making training relevant and relatable. Don’t just tell people what the policy is, help them to make that relevant, and to interpret and understand what you want them to do in order to support it. What we see instead is lots of ‘don’t do this, don’t do that’ – but what about the why?”
“Through our partnership with Unicorn, we have moved beyond the model of once a year training,” he continued. “We have built creative, innovative, engaging learning to help businesses design and implement effective training programmes for their organisations. The RESILIA suite gives you the power to build an adaptive, efficient programme of learning, utilising diagnostic tools to test current knowledge and then deliver only relevant content to address areas of weakness. The content is a mixture of online videos; refresher snippets and tests; games and animations – and in its variety is sympathetic to the notion that people learn in different ways.”
RESILIA is designed for businesses of all sizes to help them on the journey of developing a culture that recognises the need to keep abreast of the threats posed by cybercrime. As both Nick and Vicki explained today, a business is only as resilient as its people – something that unavoidably echoes the old adage about a chain being only as strong as its weakest link. “Critically, we want to get people talking about this stuff,” said Nick. “The more that people talk about it, the more resistant they become.”
If you want to find out more about RESILIA Cyber Awareness Learning – or book a demo – you can do so here.
If I asked you for the time, would you check on your analog wristwatch? Chances are if you are a millennial you wouldn’t, as you’re probably not wearing one and you might not even own one. You’re more likely to check via some piece of versatile technology, which might be a smart phone, smart watch, tablet, fitness tracker or other multipurpose device. It’s amazing to think the effect technology has had on something as simple as telling the time, so how have advances in technology changed learning experiences and styles?
From push to pull
Technology has changed our lives and continues to do so, both at home and at work, in a rapidly evolving digital world. As a result of this, employees now have different expectations and preferences, learning styles have changed from a tradition push model to a more modern pull model. So what is push and pull and what’s the difference between them?
Historically employees would be invited to formal training, typically in a classroom, which would be at a time suitable for the trainer or training team. The employee would sit and listen whilst the trainer would go through a presentation, with the delegate taking reels of notes. The employee might be required to take a formal test (no talking or conferring please), and the success of the training and the employee would be based on the pass or failure of that test. The employee would be sent back to the workplace and often not given an opportunity to put into practice what they had learnt.
The Ebbinghaus forgetting curve, shows 50% of classroom training is forgotten in an hour if theory isn’t put into practice. So how effective could this method of training actually be? And at what cost to the organisation?
Millennials pulling away from the push model
Today’s employees, specifically millennials – who according to PwC will make up 50% of the global workforce by 2020 – expect a different kind of learning experience. The pull model, whereby employees are able to access material whenever (work, home or on the go), however (desktop PCs, laptops, mobiles, tablets and face to face) and through whatever source (search, eLearning, assessment, video share, blogs, forums, knowledge share, mentors, communities and networks) is what these employees expect, desire and need.
The 70.20.10 approach
The 70.20.10 framework, which has been gaining momentum in recent years, takes on a different approach to learning, moving away from a formal classroom environment which provides little to no practice in the workplace after a training course is complete. The principle of this learning framework is 70% experience and practice, 20% conversations with people and networks and 10% formal learning. The approach moves away from formal structured learning techniques, where it’s thought to be more costly, inefficient and does not provide flexibility for the employee or employer. The 70.20.10 approach goes hand in hand with millennial expectations and is complemented in our digital era where information, networks and communities are more easily accessible.
What can employers do?
By creating a culture where employees willingly share skills and knowledge is critical for success within an organisation. A study by BlessingWhite found employee development is one of the biggest drivers of retention and engagement, and aside from just retaining staff, employees are more capable and motivated in the workplace and within their role.
If employees are given access to the right tools and knowledge, they will drive their own development and will seek information themselves. Technology can help organisations to provide collaborative learning environments for their employees and help to create a one stop shop for employee learning, development and training resources, allowing employees to gain access to this information when they need to.
This collaborative learning space can be provided through a virtual hub, whereby learning, development and training tools and resources are all found in one place. This space allows for a continuous learning environment, whereby employees can pull on any information and resources they require at that time, in a format which is conducive to their learning style and from wherever they are. Digital eLearning modules provide interactive learning quickly and effectively to delegates, saving time and resources compared to traditional methods. Other forms of technology can also be utilised such as apps and games, through multiple channels including mobile, harnessing a 70.20.10 learning environment.
The final word on the evolving learning experience
Technology is rapidly changing the world around us, both at home and at work. With millennials soon becoming the majority of employees in the workplace, it is critical to ensure their learning and development needs are met. Moving away from a traditional push model to a pull model, whereby employees are responsible for their own development and are able to seek the information they require when, where and how they need to, will lead to more capable and motivated employees and ensure organisations are retaining talent. Time to autonomy is quicker, employees are competent and confident in their roles and organisations save on costs of traditional formal training and move to digitalised solutions, which can provide a one stop shop for employees.
Unless you’ve been living under a rock for the past few weeks, it’s likely that you’ll have come across the ‘Learning Ecosphere’ in some capacity. Launched at last month’s Learning Technologies show, this brand new concept seeks to reimagine the relationship between traditional and new learning methods – and offers businesses the chance to better understand how they can embrace both in order to strengthen their overall learning strategies.
Here, Mark Jones – Commercial Director of Unicorn – gives a brief overview of the Learning Ecosphere concept:
Don’t forget, you can still get your free copy of the Learning Ecosphere Whitepaper here.
If you’re remotely connected to L&D, this is shaping up to be a pretty big week! Learning Technologies returns to Kensington Olympia across Wednesday 1st and Thursday 2nd February – bringing together over 7000 visitors all keen to get their hands on the latest in education tech. From tomorrow, we’ll be joining over 200 of our contemporaries from across the learning industry as we exhibit at this year’s show. If you’re swinging by, here are the top 5 things you can look forward to:
- Get your hands on the free ‘Learning Ecosphere’ whitepaper.
Discover how learning technologies can smooth the dichotomy between traditional and modern learning with the Unicorn Learning Ecosphere – the subject of our whitepaper launching at the show.
The underlying need for an enterprise to define, manage and report on the competence of its staff has not changed. Environmental, safety and other regulatory demands on organisations are here to stay, while data security requirements are greater than ever.
But how does this fit with such concepts as social learning, collaboration and BYOD? How do we dip our toes into this fast flowing stream of opportunity in a way that is effective, relevant and affordable, and consistent with the practical day to day demands on our time, budgets and resources? What tools should we be using? What are the implications for e-learning design?
Pick up your free copy at stand P14.
- If you need a little persuasion, go and see our very own Mark Jones giving you an overview at one of his two free seminars
12:30-13:00 on both Wednesday and Thursday, Theatre 8. Where are you in the Learning Ecosphere?
Mark will seek to explore some of the issues facing businesses wishing to explore new learning methods. We’ve all heard the buzzwords and seen a flurry of new micro learning and learning Apps, but how do we really go about introducing effective ‘learning reinforcement’ – and where do we start? In a world where learning is changing, and we’re increasingly urged to explore new training formats, how do we ensure that we’re doing is going to work?
Join Mark to find out more, as well as discover our brand new mobile reinforcement app, Minds-i.
- Come and have a go at QuizCom and you could win a Unicorn!
Yep, you read that right – come and try your hand at our giant swipe game and you could be the proud owner of your very own Unicorn. Our enthusiastic quiz hosts will be tough not to spot, as they’ll be sporting bright orange blazers and encouraging you to try your luck with our latest game. Loaded with questions covering everything from learning trends to star wars trivia, this is the perfect way to trial a brand new product from Unicorn aimed at getting your staff engaged whilst challenging them to prove their knowledge in a topic of your choice.
Winners announced at 4pm each day, plus bonus prizes for two players picked at random!
- Check out Mike Hawkyard giving you a little insight into learning games and apps in corporate learning.
15:30-16:00 on Thursday, Theatre 8: Learning games and engagement.
We’ve all heard 101 talks lately about ‘gamification’, but this isn’t one of those talks. Mike is the Managing Director of an award winning games studio who have produced apps played more than two billion times in the last three years.
In recent months, Amuzo have been training people how to fly Star Wars™ Drones and encouraging children to build LEGO® models to rescue LEGO® Mini Figures trapped on erupting volcanoes. Join Mike for a session that will look at:
- How the technology and best practice used in these exciting projects is identical to that being used in work for companies like KPMG and the Chartered Insurance Institute (CII)
- How to explore the possibilities of learning games for your business
- Experiencing Amuzo’s latest product to engage staff with corporate communications; QuizCom
- …And you might even win a prize or two!
- Finally, if you’re at the conference, go and see Richard Owen from the CII talk about their learning journey.
15:30-16:40 on Thursday, Conference Theatre T5S6: Organisational learning – Creating better learning outcomes for the learner and the business.
Richard Owen – Product Manager at the Chartered Insurance Institute (CII) – lifts the lid on how the CII have approached their corporate learning. He looks at the value of online learning for the learner and the business alike, and shares experiences of the challenges that the CII has faced in creating better user experience despite a highly regulated, compliance driven context. From topic-specific pathways, powerful diagnostic tools and a more intuitive interface, discover how the CII has trebled its uptake of its content within just 12 months with a little help from us!
We’ll be live blogging from LT, as well as tweeting from @unicorntraining. Don’t forget to stop by and see us at stand P14 across the event, as well as take some time to relax in the Unicorn café!
We’re just a few days away from eLearning guru, Craig Weiss, revealing his much-anticipated Top 50 LMS Report for 2017, and yep, there are a few nerves kicking in.
In 2016 our LMS topped Craig’s rankings for the world’s top system for the financial sector for the second year running and was fourth overall across all sectors, so we’re super excited to find out if our hard work over the past 12 months can make it an FS table topping hat-trick and see our LMS move up in the overall rankings again.
With this on our minds, it made us ponder just how eventful 2016 had been for Unicorn, and what standards we set ourselves to live up to this year. Not only were we so happy about Craig’s ranking but there were plenty of awards to celebrate too.
Our games arm Amuzo had their industry-leading genius recognised with gold in the Creative Digital Impact category at the Dorset Business Awards while their Playmobil Police Chase game won the 2016 TOMMI Award for Best Kids’ App!
The TOMMI is the children’s software award of Germany. Every year since 2002 the TOMMI Prize has been awarded at the Frankfurt Book Fair to the most innovative and outstanding software title developed specifically for children, showing Amuzo are appreciated far beyond these shores too. Pretty cool huh?
Then there was the awesome success of our partners, FSTP, who were named winners of the Most Effective Training Firm at the Compliance Register Awards.
FSTP work closely with us on developing all of our Governance, Risk and Compliance (GRC) content, and their knowledge and experience proved invaluable in the build up and throughout 2016 as many of our clients grappled with the new Senior Managers’ Regime and Certification amongst other complex mandatory topics.
We were also delighted to scoop a bronze at the eLearning Awards with Clydesdale and Yorkshire Bank for the platform implementation that has introduced MyLearning, and changed the way the whole organisation approaches L&D.
With our partners at Credit Suisse, who joined us for the evening, also taking home a silver in the Learning Technologies Team of the Year category it topped a pretty successful 2016 for us Unicorns.
The bar has been set pretty high for 2017 now, but hopefully Craig’s report will help us kick off the year as we mean to go on. Get crossing everything!
Here at Unicorn HQ we have a favourite quote: “Tell me and I forget. Teach me and I remember. Involve me and I learn.” Originally attributed to Benjamin Franklin, it’s not just a tag line, it’s become something of a mantra to live by…
In the rapidly changing world of digital technology, we’ve got smart-device overload. Nowadays, the possibilities for deploying learning are just about endless, as people’s unrestricted access to the latest tech means almost complete ubiquity of smart phones, tablets and portable computers. Whilst this fact presents new and exciting possibilities for changing the ways we deliver and consume learning, the basic principles that underpin the learning experience remain for the most part unchanged. What Mr Franklin aptly hit upon in his quote of which we are so fond is the idea that in order to catalyse real behavioural (or ‘real life’) change, the learning experience must be both memorable and immersive.
Enhancing knowledge retention and designing learning interventions that reinforce and give practical context goes beyond simply making courses compatible with the latest operating systems, devices and browsers. Instead, we need to go deeper into the psychological process that underpins learning and shift our understanding of the learning problem from a simple question of delivery to something more fundamental.
The Psychology Bit
Taking into account the brain’s capacity to absorb, retain and actively recall information, the challenge we consistently face is to find ways to deliver learning that percolates beyond the superficial layers of a person’s memory and taps into the longer term psyche. We know with the move away from traditional, PC-based linear training towards something more dynamic, that learning requirements are changing. Rather than ‘box-ticking’, organisations increasingly recognise the need to deliver learning that goes deeper to yield real behavioural change.
In order to achieve this, learning solutions must tailor educational experiences to navigate the potential pitfalls of the learning process without causing cognitive overload, or allowing learners to simply forget what they have been taught. In order to achieve this, it’s important to deliver learning experiences in digestible chunks, with follow-up and reinforcement that means learners are then encouraged to use and consolidate the learning soon after the original intervention. In the context of compliance training, this approach begins to reposition learning not simply as an annual necessity, but rather as something embedded in the regular activities of learners.
Getting Ahead of the Curve
Here at Unicorn, we believe that one such way to deliver learning that sticks is through the use of mobile Apps.
The average iPhone user unlocks their phone an average of 80 times per day. -Business Insider
Portable technology is increasingly synonymous with modern life – presenting a unique opportunity to deploy learning content straight to a user’s pocket wherever they may be. By understanding these ‘mobile moments’, we have the opportunity to form the framework for including mobile applications into wider learning strategy. Rather than looking to deploy full learning content to mobile, a more effective proposition is to focus Apps on learning reinforcement using microbites of engaging content – short videos, polls, quizzes, check-lists – with simple gamification elements, nudges and prompts to encourage regular revisits.
Apps then become a key element in a blended solution. Whilst a person might still be expected to complete a mandatory 30-minute course on a particular subject, the added functionality of an App means that we’re now able to add in extra layers to the learning experience.
When we start to reimagine learning as non-linear, we open up opportunities to draw in other psychological principles: whether the challenge and reward balance; social collaboration and knowledge sharing, or ‘just in time’ content that gives users the ability to reference bitesized supplementary learning content for reference in everyday situations. As products of modern society, we are already part-programmed to rely on Apps and other forms of mobile interactions in our day-to-day lives –social networking, news, or even the simple use of a fitness or alarm App. If learning and development professionals can leverage mobile technology as a powerful additional channel through which to deliver timely, relevant learning content, then we are already going some way towards combatting the forgetting curve and making sure that learning sticks.
Our partnership with world class games studio, Amuzo, means that we are already seeing the benefits of extrapolating the ‘sticky’ elements of game and app design into wider learning programmes. Once the underpinning psychological principles involved in gaming are understood, the potential for the scope and context of their application is limitless. Read more about apps in learning here.
You might have seen us wandering around Learning Technologies armed with a large video camera and a smile? Well here are the tantalising fruits of all that labour…
In the first in our series of video blogs from Learning Technologies, conference Chair, Donald H. Taylor reveals that, for him, ‘Who’s in control of learning?’ was the key theme and question that came out of this year’s event.
He adds: “We’ve had people asking more pertinent, probing questions, and I think we’re getting to the stage now where we’re questioning much more about what we’re doing in this space and are prepared to be a little bit assertive about how to change things.”