Daniel Köhler
Christoph Meinel
Hasso Plattner Institute, University of Potsdam, Prof.-Dr.-Helmert-Str. 2-3, Potsdam, Germany
Security, Awareness, Education, Assessment, Method Overview.
Today, cybersecurity attacks are one of the significant threats companies face. Employees, often the weakest link in the cybersecurity chain, are sensitized to threats in cyberspace by implemented cybersecurity awareness and education programs in companies. Success if often rated using obligatory quizzes. Those, however, do not accurately depict actual employee behavior; they only test for knowledge. Companies often lack accurate measures to validate the success of cybersecurity awareness measures. We aggregate previous literature on measures for education and assessment in the context of cybersecurity awareness and present a taxonomy of education and assessment measures, categorizing them for context, applicability, and effort while summarizing (dis-) advantages identified in previous research. Thereby, we enable easier decisions on specific cybersecurity awareness education and assessment methods for decision-makers with specific restraints.