---
title: Cyber Security In Critical Infrastructures – The Importance Of Cross-Organizational Cybersecurity Training Programs, Beyond SOC & IR
description: With the right awareness and training, every single employee can become part of a human firewall making up a vital frontline of defense.
image: https://9397565.fs1.hubspotusercontent-na1.net/hubfs/9397565/Cross%20Org%20Cyber%20Security%20Blog%20FI.png
---

[![cybergym_logo-1](https://9397565.fs1.hubspotusercontent-na1.net/hubfs/9397565/cybergym_logo-1.svg "cybergym_logo-1")](https://www.cybergymiec.com/)

[request a Demo ](https://blog.cybergymiec.com/blog/cyber-security-in-critical-infrastructures-the-importance-of-cross-organizational-cybersecurity-training-programs-beyond-soc-ir#popupBox)

[request a Demo ](https://blog.cybergymiec.com/blog/cyber-security-in-critical-infrastructures-the-importance-of-cross-organizational-cybersecurity-training-programs-beyond-soc-ir#popupBox)

#### Sophic Defense Solutions

![ZONE](https://9397565.fs1.hubspotusercontent-na1.net/hubfs/9397565/ZONE.svg)

[Zone ](https://cybergymiec.dooble.us/product/sophic-defense-solutions/zone/)

![ACCESS-1](https://9397565.fs1.hubspotusercontent-na1.net/hubfs/9397565/ACCESS-1.svg)

[Access ](https://cybergymiec.dooble.us/product/sophic-defense-solutions/access/)

![path829-1](https://9397565.fs1.hubspotusercontent-na1.net/hubfs/9397565/path829-1.svg)

[INFO ](https://cybergymiec.dooble.us/product/sophic-defense-solutions/info/)

#### Cybergym Training Solutions

![CyberFrame-1](https://9397565.fs1.hubspotusercontent-na1.net/hubfs/9397565/CyberFrame-1.svg)

[Cyber Arenas ](https://cybergymiec.dooble.us/product/cybergym-training-solutions/second-opinion-assessment/)

![VirtualCloudArena-1](https://9397565.fs1.hubspotusercontent-na1.net/hubfs/9397565/VirtualCloudArena-1.svg)

[Virtual Cloud Arena ](https://cybergymiec.dooble.us/product/cybergym-training-solutions/virtual-cloud-arena/)

![TrainingPrograms-1](https://9397565.fs1.hubspotusercontent-na1.net/hubfs/9397565/TrainingPrograms-1.svg)

[Training Programs ](https://cybergymiec.dooble.us/product/cybergym-training-solutions/training-programs/)

![Enabling-Tech-1](https://9397565.fs1.hubspotusercontent-na1.net/hubfs/9397565/Enabling-Tech-1.svg)

[Enabling Tech ](https://cybergymiec.dooble.us/product/cybergym-training-solutions/enabling-tech/)

#### VAS

![flash-1](https://9397565.fs1.hubspotusercontent-na1.net/hubfs/9397565/flash-1.svg)

[Crisis management ](https://cybergymiec.dooble.us/product/vas/crisis-management/)

![gauge-1](https://9397565.fs1.hubspotusercontent-na1.net/hubfs/9397565/gauge-1.svg)

[Penetration Test ](https://cybergymiec.dooble.us/product/vas/penetration-test/)

![shield-bug-1](https://9397565.fs1.hubspotusercontent-na1.net/hubfs/9397565/shield-bug-1.svg)

[Vulnerability Assessment ](https://cybergymiec.dooble.us/product/vas/vulnerability-assessment/)

![presentation-1](https://9397565.fs1.hubspotusercontent-na1.net/hubfs/9397565/presentation-1.svg)

[Intro ](https://cybergymiec.dooble.us/product/vas/intro/)

![toolbox-outline-1](https://9397565.fs1.hubspotusercontent-na1.net/hubfs/9397565/toolbox-outline-1.svg)

[SOC-as-a-Service ](https://cybergymiec.dooble.us/product/vas/soc-as-a-service/)

![shield-account-1](https://9397565.fs1.hubspotusercontent-na1.net/hubfs/9397565/shield-account-1.svg)

[RCMA ](https://cybergymiec.dooble.us/product/vas/rcma/)

![account-group-outline](https://9397565.fs1.hubspotusercontent-na1.net/hubfs/9397565/account-group-outline.svg)

[Workshops ](https://cybergymiec.dooble.us/product/vas/workshops/)

![lightbulb-multiple-outline-1](https://9397565.fs1.hubspotusercontent-na1.net/hubfs/9397565/lightbulb-multiple-outline-1.svg)

[Second opinion ](https://cybergymiec.dooble.us/product/vas/second-opinion/)

![domain](https://9397565.fs1.hubspotusercontent-na1.net/hubfs/9397565/domain.svg)

[About Us ](https://cybergymiec.dooble.us/about-us/)

![dresser-outline-1](https://9397565.fs1.hubspotusercontent-na1.net/hubfs/9397565/dresser-outline-1.svg)

[Resources ](https://cybergymiec.dooble.us/events-webinars/)

![newspaper-1](https://9397565.fs1.hubspotusercontent-na1.net/hubfs/9397565/newspaper-1.svg)

[Blog ](https://blog.cybergymiec.com/blog)

![briefcase-variant-outline-1](https://9397565.fs1.hubspotusercontent-na1.net/hubfs/9397565/briefcase-variant-outline-1.svg)

[Career ](https://blog.cybergymiec.com/jobss?hsLang=en)

![req-demo-1-1](https://9397565.fs1.hubspotusercontent-na1.net/hub/9397565/hubfs/req-demo-1-1.jpg?width=392&height=583&name=req-demo-1-1.jpg)

![sophic_title-1](https://9397565.fs1.hubspotusercontent-na1.net/hubfs/9397565/sophic_title-1.svg) ![access_title](https://9397565.fs1.hubspotusercontent-na1.net/hubfs/9397565/access_title.svg)

Securing the most sensitive file transfer Secure File Sanitation and Transfer for worldwide SCADA Critical Infrastructure operators

![req-demo-2](https://9397565.fs1.hubspotusercontent-na1.net/hub/9397565/hubfs/req-demo-2.jpg?width=392&height=583&name=req-demo-2.jpg)

![sophic_title-1](https://9397565.fs1.hubspotusercontent-na1.net/hubfs/9397565/sophic_title-1.svg) ![zone_title](https://9397565.fs1.hubspotusercontent-na1.net/hubfs/9397565/zone_title.svg)

Cyber Validation Environment Emulate, simulate, test and validated cyber-attack in a near-real-time environment

![req-demo-3](https://9397565.fs1.hubspotusercontent-na1.net/hub/9397565/hubfs/req-demo-3.jpg?width=392&height=583&name=req-demo-3.jpg)

![sophic_title](https://9397565.fs1.hubspotusercontent-na1.net/hubfs/9397565/sophic_title.svg) ![info_title](https://9397565.fs1.hubspotusercontent-na1.net/hubfs/9397565/info_title.svg)

Securing the most sensitive file transfer Secure File Sanitation and Transfer for worldwide SCADA Critical Infrastructure operators

### Request a Demo

# Cyber Security In Critical Infrastructures – The Importance Of Cross-Organizational Cybersecurity Training Programs, Beyond SOC & IR

[Maor Sorero](https://blog.cybergymiec.com/blog/author/maor-sorero)

<https://www.linkedin.com/in/msorero/> January 11, 2022  3 min read

![](https://9397565.fs1.hubspotusercontent-na1.net/hubfs/9397565/Cross%20Org%20Cyber%20Security%20Blog%20FI.png)

#### When it comes to cybersecurity, organizations today require a 24/7 strategy of defense, identification, response and remediation - especially if they are responsible for the provision or management of critical infrastructure. Beyond the protective measures that fall within the domain of IT/OT and cybersecurity experts, with the right awareness and training, every single employee can become part of a human firewall making up a vital frontline of defense.

## **The human factor **

People can be both the key to a successful cybersecurity strategy, and the weakest link in a cyber defense system. Organizations rely on their cybersecurity professionals – especially those such as SOC and IR teams – as the ‘defending heroes’ whose technical expertise and watchful eye keep their assets and operations safe. In reality though, all their efforts to procure, install, configure and operate the right technological solutions can be undone by an individual somewhere else in the organization who, for example, clicks on a link in an innocent-looking email, inadvertently giving a cybercriminal an access point to exploit. After all, firewalls can’t prevent an employee falling for a phishing email, and it is just this type of insidious attack – which a cybercriminal can cook up in minutes – that can cause the most damage. 

***[34%](https://www.verizon.com/business/resources/reports/2019-data-breach-investigations-report.pdf) of cyberattacks involve internal actors***

The increase in remote working in response to the current pandemic inadvertently made employees the masters of their organizations’ cyber destiny, opening up a whole new playground of unsuspecting and unsecured devices for cybercriminals to enjoy. Without the guidance of an expert IT/ OT team, or the corporate resources invested in the most up-to-date technology at the office, employees fell victim to cyber threats that exploited vulnerable virtual private networks (VPNs), unpatched Windows-based systems, and a general lack of internet security at home. 

## **Cyber hot spots**

The control systems behind critical infrastructure – from energy to finance, healthcare to transportation, communications to government – are popular targets for cyber activists and terrorists seeking to cause mayhem to advance their cause. Here, the stakes are infinitely higher, because when critical infrastructure fails, the effects can be devastating on a nationwide scale, in terms not only of the provision of utilities such as power, but of security, public health and safety. 

***56% of utilities* [surveyed](https://press.siemens.com/global/en/pressrelease/siemens-and-ponemon-institute-study-finds-utility-industry-vulnerabilities) reported at least one shutdown or operational data loss per year, due to cyberattack** 

As the energy sector, and in particular electric utilities providers, advances in its digital transformation – think smart grids and the digitalization of the power supply process – power generation and distribution become more connected, and increasingly vulnerable. This means that implementing a proven, effective cybersecurity model, with awareness training at its core, is even more important in this domain.

## **Creating a culture of cyber security awareness **

Cybersecurity really is an organization-wide issue. It takes more than a monthly circular reminding people not to click on ‘suspicious-looking links’ to raise true awareness of cyber risk. A culture of cyber security awareness needs to be cultivated across the whole organization, based on an understanding of the risks and potential outcomes of a cybersecurity attack. Cross-organizational cyber security training for employees – including senior management – may cover a range of topics, from the fundamentals of cyber awareness, to best practices for preventing or reducing breaches that target insiders, to practical, hands-on exercises based on real-life attack scenarios. 

With the right awareness and ongoing training, every employee can serve as an extension to the professional cyber team which, given the current [shortage of cybersecurity professionals](https://www.forbes.com/sites/insights-fortinet/2019/08/27/the-importance-of-training-cybersecurity-awareness-as-a-firewall/?sh=782db63b8b4b) in the market, makes good sense. 

## **Meeting the challenges head on**

As with any new large-scale initiative, initially there may be some resistance to implementing cyber awareness training for employees. Transparency is key to securing buy-in. Begin by educating employees about the ramifications of them falling victim to a cyberattack, thereby exposing the organization to untold damage. Ensure training is tailored to your organization, and taught by trainers with specialized knowledge of how your organization works, the systems your employees use, and the threat landscape you face. 

Reenforce what your employees learn by enabling them to put it into practice, test their growing awareness, and identify blind spots through hands-on simulations of real-life attacks. Once a training exercise is over, have a debriefing session in which employees can learn from their own mistakes, and from each other. Finally, acknowledge that mistakes can still happen and remove the associated shame. Put in place simple, streamlined incident reporting processes and make it clear that, if an innocent error does occur, covering it up only makes it worse. Rather, encourage people to come forward by reassuring them that there will be no negative consequences.  

Watch CybergymIEC's CEO Ofir Hason discuss the Importance of Cross-Organizational Cyber Training [here](https://www.youtube.com/watch?v=MyuICkYnyhs)

To find out how CyberGymIEC can support cyber security training for critical infrastructure employees, [contact us](https://www.cybergymiec.com/#contact). 

##### Share

- <http://www.facebook.com/share.php?u=https://blog.cybergymiec.com/blog/cyber-security-in-critical-infrastructures-the-importance-of-cross-organizational-cybersecurity-training-programs-beyond-soc-ir&utm_medium=social&utm_source=facebook>
- <https://twitter.com/intent/tweet?original_referer=https://blog.cybergymiec.com/blog/cyber-security-in-critical-infrastructures-the-importance-of-cross-organizational-cybersecurity-training-programs-beyond-soc-ir&utm_medium=social&utm_source=twitter&url=https://blog.cybergymiec.com/blog/cyber-security-in-critical-infrastructures-the-importance-of-cross-organizational-cybersecurity-training-programs-beyond-soc-ir&utm_medium=social&utm_source=twitter&source=tweetbutton&text=>
- <http://www.linkedin.com/shareArticle?mini=true&url=https://blog.cybergymiec.com/blog/cyber-security-in-critical-infrastructures-the-importance-of-cross-organizational-cybersecurity-training-programs-beyond-soc-ir&utm_medium=social&utm_source=linkedin>
- [mailto:?subject=Check%20out%20https://blog.cybergymiec.com/blog/cyber-security-in-critical-infrastructures-the-importance-of-cross-organizational-cybersecurity-training-programs-beyond-soc-ir&utm_medium=social&utm_source=email%20&body=Check%20out%20https://blog.cybergymiec.com/blog/cyber-security-in-critical-infrastructures-the-importance-of-cross-organizational-cybersecurity-training-programs-beyond-soc-ir&utm_medium=social&utm_source=email](mailto:?subject=Check%20out%20https://blog.cybergymiec.com/blog/cyber-security-in-critical-infrastructures-the-importance-of-cross-organizational-cybersecurity-training-programs-beyond-soc-ir&utm_medium=social&utm_source=email%20&body=Check%20out%20https://blog.cybergymiec.com/blog/cyber-security-in-critical-infrastructures-the-importance-of-cross-organizational-cybersecurity-training-programs-beyond-soc-ir&utm_medium=social&utm_source=email)

## Subscribe to our newsletter

### Get the latest posts in your email

## Subscribe to our newsletter

## Related Articles

[![](https://9397565.fs1.hubspotusercontent-na1.net/hubfs/9397565/AI-Generated%20Media/Images/ITOT.png) ](https://blog.cybergymiec.com/blog/enhancing-maritime-cybersecurity-insights-from-sines-port-training?hsLang=en)

## [Enhancing Maritime Cybersecurity: Insights from Sines Port Training](https://blog.cybergymiec.com/blog/enhancing-maritime-cybersecurity-insights-from-sines-port-training?hsLang=en)

### The Importance of Maritime Cybersecurity

When attackers target a port, the consequences are...

[Read More](https://blog.cybergymiec.com/blog/enhancing-maritime-cybersecurity-insights-from-sines-port-training?hsLang=en)

September 30, 2025 Daniel Shemesh

 3 min read

[![](https://9397565.fs1.hubspotusercontent-na1.net/hubfs/9397565/Blog%20%2317%20Don%E2%80%99t%20Wait%20for%20the%20Regulator-Blog-553x277.png) ](https://blog.cybergymiec.com/blog/dont-wait-for-the-regulator?hsLang=en)

## [Don’t Wait for the Regulator!](https://blog.cybergymiec.com/blog/dont-wait-for-the-regulator?hsLang=en)

As the number and severity of cyberattacks happening around the world continues to increase, many...

[Read More](https://blog.cybergymiec.com/blog/dont-wait-for-the-regulator?hsLang=en)

November 28, 2022 Barak Davidovich, IEC

 3 min read

[![](https://9397565.fs1.hubspotusercontent-na1.net/hubfs/9397565/Cyber%20Range%20and%20Cyber%20Arena%20%E2%80%93%20Pros%2c%20Cons%20and%20Key%20Differences-Blog-553x277.png) ](https://blog.cybergymiec.com/blog/cyber-range-and-cyber-arena?hsLang=en)

## [Cyber Range and Cyber Arena – Pros, Cons and Key Differences](https://blog.cybergymiec.com/blog/cyber-range-and-cyber-arena?hsLang=en)

Cyber Range and Cyber Arena are both terms that refer to the training facilities used by...

[Read More](https://blog.cybergymiec.com/blog/cyber-range-and-cyber-arena?hsLang=en)

October 3, 2022 Ofir Hason

 3 min read

###### Home

###### About us

###### Resources

###### Solutions

[![Cybergym-logo-1](https://9397565.fs1.hubspotusercontent-na1.net/hubfs/9397565/Cybergym-logo-1.svg "Cybergym-logo-1")](https://www.cybergymiec.com/)

- <https://www.facebook.com/CybergymIEC>
- <https://www.linkedin.com/company/cybergymiec/>
- <https://twitter.com/CybergymIEC>
- <https://www.youtube.com/channel/UCCA70u4ld1U0FbqA8WjIDsg>

© 2022 CybergymIEC. All rights reserved