International Journal of Computer Applications |
Foundation of Computer Science (FCS), NY, USA |
Volume 185 - Number 3 |
Year of Publication: 2023 |
Authors: Samo Tomažič, Matej Mertik, Tadej Šeruga |
10.5120/ijca2023922686 |
Samo Tomažič, Matej Mertik, Tadej Šeruga . Systematic Approach to Awareness Training at Slovenian Nuclear Safety Administration. International Journal of Computer Applications. 185, 3 ( Apr 2023), 30-36. DOI=10.5120/ijca2023922686
Social engineering techniques are a type of cyber-attack that exploit human nature and behavior. One of such techniques is phishing. Phishing attacks include spear phishing, whaling, smishing and vishing, and they are on the rise. Malicious actors target general population, business environments and critical infrastructure. Nuclear sector is a part of state critical infrastructure and must be protected according to national regulations and international standards or guidelines. Nuclear facility operators, regulators, suppliers, and technical support organizations in Slovenia are ensuring cyber security is on the highest possible level. One way they do this is by making sure that people, who are the weakest link, are aware of the potential consequences of a successful compromise. When conducting the research study presented in this paper, a descriptive method was applied to review publicly available legislation and regulations, international standards, guides, and best practices. Based on the analysis, training program and phishing tests were developed. After completion of the trainings and conducted phishing test, the data was collected, and development of the Systematic Approach to Awareness Training (SAAT) by Slovenian nuclear safety regulator Slovenian Nuclear Safety Administration (SNSA) has begun. This paper presents the results of the research in a form of five essential elements of the SAAT (Figure 1): awareness policy, preparation, implementation, lessons learned and a feedback loop.