security governance. Organizations should consider
different interventions to assist the workforce realize
the nature of cyber threats, how attacks are delivered,
the impact to individual safety and business
operations, recognize what behaviours can put the
organization at risk and what actions they need to
apply when they are under attack. A common cyber
threat that organizations and individuals are facing is
SE. A typical approach to address SE attacks is to
deliver awareness-raising training to empower and
upskill the workforce. However, this should not be
perceived as a solution that can be adopted by all
organizations as this depends on different factors,
with the economic aspect and lack of engagement
being the most prevailing. Given that awareness-
raising and training activities can complement the
objectives of security policies, this should be taken
into account to propose new interventions to
empower small businesses that have limited budgets
to increase awareness of their workforce. This work
proposes the development of a social engineering
awareness-raising policy, incorporating awareness-
raising and educational principles alongside policy
rules. The aim is to offer an open, cost-free baseline
intervention that can help the workforce realize how
SE attacks can be delivered in the context of their
working environment and job role, better understand
the objectives of specific security policies, identify
and apply the relevant policy rules that can help in
addressing SE attacks. Future work will expand upon
the concept of delivering tailored SE awareness-
raising and training initiatives.
REFERENCES
Aldawood, H., Skinner, G. (2019). Reviewing Cyber
Security Social Engineering Training and Awareness
Programs—Pitfalls and Ongoing Issues, Future
Internet, vol. 11, no. 3, p. 73.
Aldawood, H. (2020). A Policy Framework to Prevent
Social Engineering, 3rd International Conference
Middle East and North Africa Conference of
Information System, Casablanca, Moroco.
Alharthi, D., Regan, A. (2021). A Literature Survey and
Analysis on Social Engineering Defense Mechanisms
and INFOSEC Policies, Int. Journal of Network
Security & Its Applications (IJNSA) Vol.13, No.2.
Charalambous, A., Stavrou, E. (2023). Building societal
resilience against social engineering attacks:
Unleashing the power of instructional design and
microtargeting, 16th Annual International Conference
of Education, Research and Innovation (ICERI).
CIS, MS-ISAC. (2019a). NIST Cybersecurity Framework,
SANS Policy Templates.
CIS, MS-ISAC. (2019b). NIST Cybersecurity Framework,
Policy Template Guide.
CIS. (2023). Security Awareness Skills Training Policy
Template, CIS Critical Security Controls.
https://www.cisecurity.org/insights/white-
papers/security-awareness-skills-training-policy-
template-for-cis-control-14. (Accessed on 28/10/2023)
CIIS. (2023). Chartered Institute of Information Security -
The Security Profession 2022/23.
ENISA. (2023). ENISA Threat Landscape 2023.
https://www.enisa.europa.eu/publications/enisa-threat-
landscape-2023. (Accessed on 28/10/2023)
GOV.UK. (2023) Cyber security skills in the UK labour
market 2023.
Healthit.gov. (2018). Info Security Policy Template.
https://www.healthit.gov/resource/information-
security-policy-template. (Accessed on 28/10/2023)
ISO/IEC. (2022). ISO/IEC 27002:2022 Information
security, cybersecurity and privacy protection:
Information security controls
Kävrestad, J., Furnell, S., Nohlberg, M. (2023). User
perception of Context-Based Micro-Training – a
method for cybersecurity training, Information Security
Journal: A Global Perspective
Merrill, M. D. (2002). First principles of instructional
design, Educational Technology Research and
Development, vol. 50, no. 3, pp. 43–59.
NIST. (2018). Framework for Improving Critical
Infrastructure Cybersecurity
Piki, A., Stavrou, E., Procopiou, A., Demosthenous, A.
(2023). Fostering Cybersecurity Awareness and Skills
Development Through Digital Game-Based Learning,
10th International Conference on Behavioural and
Social Computing (BESC)
SANS (2022). SANS Security Policy Templates.
https://www.sans.org/information-security-policy.
(Accessed on 28/10/2023)
Smith, A., Papadaki, M., Furnell, S. M. (2013). Improving
awareness of social engineering attacks, IFIP Advances
in Information and Communication Technology, vol.
406, pp. 249-256.
Stavrou, E. (2020). Back to basics: Towards building
societal resilience against a cyber pandemic, Journal on
Systemics, Cybernetics and Informatics (JSCI), vol. 18,
no. 7, pp. 73-80.
Stavrou, E. (2023). Planning for Professional Development
in Cybersecurity: A New Curriculum Design.
International Symposium on Human Aspects of
Information Security and Assurance (HAISA), UK.
Steinmetz, K.F., Holt, T.J. Brewer, C.G. (2023).
Developing and implementing social engineering-
prevention policies: a qualitative study. Security
Journal.
Venkatesha, S., Reddy, K.R., Chandavarkar, B.R. (2021).
Social Engineering Attacks During the COVID-19
Pandemic. SN Computer Science, vol. 2, no. 78.