Sep 17, 2026 · 31 min · 9 segments
In this episode of InfoSec Insider, George Ryan and Jack Woods, both Consultants at URM, provide practical advice on how organisations can improve cyber security training and awareness, and why…
Jack WoodsGuestGeorge RyanGuestAnnieHostSo first question for you guys is what is training and awareness within cyber security?
So, you know, what are you getting in terms of phishing, how to actually follow policies properly, how to actually secure yourself.
And then you've got the awareness aspect of actually knowing that you, you know, you have policies, how to report an incident, um, and actually knowing what your roles and responsibilities are in terms of cybersecurity within the organization.
You can mention a policy and someone looking and be like, I didn't know we had that.

Yeah, and to be fair, you see that quite often, don't you, when you go into an organisation and you're kind of, if you're conducting an audit or you're doing a gap analysis and things like that, and they've got documentation and you're talking to other areas of the business that aren't necessarily as included in information security as they probably should be.

And they ask, you ask the question relating to those policies and you just get blank looks and you're like, okay, so there's the gap.


Whereas the awareness aspect is more kind of what George was talking about in terms of understanding the policies, procedures, their responsibilities, their contribution to security, making sure they don't click on phishing emails, that kind of stuff.

Those are the kind of distinctions that we should make between training and awareness, because oftentimes they're kind of viewed as the same thing.

People think, oh, if we put them through some multiple choice questions on information security, that means that they're competent in that aspect whereas actually what you're probably doing is increasing their awareness but their level of competency if that if that training happens when they start the organization and then doesn't happen again that competency isn't there it's just an awareness activity right at the start and then it's gone um so i think there's the cl there's a clear distinction between those two points
So first question for you guys is what is training and awareness within cyber security?
So, you know, what are you getting in terms of phishing, how to actually follow policies properly, how to actually secure yourself.
And then you've got the awareness aspect of actually knowing that you, you know, you have policies, how to report an incident, um, and actually knowing what your roles and responsibilities are in terms of cybersecurity within the organization.
You can mention a policy and someone looking and be like, I didn't know we had that.

Yeah, and to be fair, you see that quite often, don't you, when you go into an organisation and you're kind of, if you're conducting an audit or you're doing a gap analysis and things like that, and they've got documentation and you're talking to other areas of the business that aren't necessarily as included in information security as they probably should be.

And they ask, you ask the question relating to those policies and you just get blank looks and you're like, okay, so there's the gap.


Whereas the awareness aspect is more kind of what George was talking about in terms of understanding the policies, procedures, their responsibilities, their contribution to security, making sure they don't click on phishing emails, that kind of stuff.

Those are the kind of distinctions that we should make between training and awareness, because oftentimes they're kind of viewed as the same thing.

People think, oh, if we put them through some multiple choice questions on information security, that means that they're competent in that aspect whereas actually what you're probably doing is increasing their awareness but their level of competency if that if that training happens when they start the organization and then doesn't happen again that competency isn't there it's just an awareness activity right at the start and then it's gone um so i think there's the cl there's a clear distinction between those two points
The rest of this transcript — segmented and speaker-labeled, so you land on the exact moment something was said
Search every transcript — by keyword, by phrase, or by meaning, across every show Radar indexes
Trends — what is surging across podcasts, measured against its own baseline
Alerts — when a name you follow appears in a newly indexed episode
No account is needed to search Radar.