Sponsor Temet: One size fits all was yesterday - efficient awareness made @SBB (2023)

Опубликовано: 17 Июль 2026
на канале: Swiss Cyber Storm
59
0

One size fits all was yesterday - efficient awareness made @SBB
By Jörg Jungblut Information Security Officer, SBB, Markus Günther Security Consultant, Temet
visit https://2023.swisscyberstorm.com/sche... & https://www.swisscyberstorm.com for more information

The following summary was machine generated from the YouTube transcript and then reviewed by human eyes. If you spot any errors, please comment below.

Summary
Presenter: Jörg Jungblut
Title: One size fits all was yesterday – efficient awareness made @SBB
Category: SCS2023
Subcategory: Sponsor
Video:    • Sponsor Temet: One size fits all was yeste...  
Length: 35:35
Content: The presentation explores how SBB, a public transportation company, evolved from a one-size-fits-all approach to a more tailored, decentralized awareness program for cybersecurity. The speaker discusses the limitations of traditional training methods and the benefits of a customized approach that considers diverse employee roles and needs.

Keywords:
Cybersecurity Awareness
Decentralized Training
Leadership Engagement
Risk Assessment
Compliance vs. Risk Management

Ideas
Traditional one-size-fits-all cybersecurity training often fails to address the specific needs of diverse employee roles within large organizations.
Decentralized awareness programs, which empower local leaders to tailor training to their teams' needs, can be more effective than standardized approaches.
A combination of leadership involvement, transparent communication, and tailored resources can significantly improve the effectiveness of cybersecurity training.
Continuous feedback and adaptation of training materials are crucial for maintaining relevance and effectiveness.
The use of dashboards and KPIs can help leaders understand and manage their teams' cybersecurity risks more effectively.

Quotes
"If they don't fit, they don't make sense. They're useless."
"One size fits all doesn't work all the time in most cases it probably even doesn't work at all."
"The only thing you do is you measure did you complete the training or not. That's the only thing you do. You don't have a look at behavior or change."
"What makes it complicated or easy depending on the perspective is we used to have a centralized approach meaning we have Switzerland, we have many sites, people are spread all over the place."

Facts
SBB has around 33,000 employees and up to 10,000 external staff, spread across 50 locations and various professions.
The company moves approximately 1 million people per day in Switzerland, making its cybersecurity critical for national infrastructure.
A centralized training approach at SBB was deemed inefficient and costly, estimated at around 10 million francs per year.
The maturity of SBB's cybersecurity program is aimed at reaching level four, but it is a complex and challenging process.

Resources
SANS Maturity Model (Model) - Provides a framework for assessing and improving cybersecurity awareness programs, referenced to critique compliance-focused training.
ISO 271, IEC 62443, Cybersecurity for Railways (Standards) - Regulatory requirements mentioned that impact SBB's approach to cybersecurity training and compliance.
PowerBI (Tool) - Used for data analysis and visualization to track and improve the effectiveness of the awareness program.

Recommendation
Adopt a decentralized approach to cybersecurity awareness that allows teams to tailor training based on their specific roles and risks.
Invest in leadership training to ensure that managers are actively involved in and accountable for their team's cybersecurity posture.
Utilize dashboards and KPIs to provide leaders with actionable insights and encourage continuous improvement in cybersecurity practices.