Cyber Security Hub Awareness and training

Awareness and training

Cyber Security Awareness and Training Approach

There is a shared responsibility at JCU for Cyber Security.  Cyber attackers often compromise systems by first targeting people, and this means what we do/don’t do goes a long way to mitigate risks and protect JCU from damaging cyber-attacks.

The approach of the Cyber Security Awareness and Training program is based on the knowledge that small behaviour changes can make a significant difference to keep you and your loved ones safe online and this flows into the workplace. The intersections between Cyber Security, Privacy and Information Security will also be addressed in awareness and training materials.

Ultimately, the objective is to grow a cyber risk aware culture in JCU where staff and students become our first line of defence.

The Security Awareness and Training plan includes:

Mandatory foundation Cyber Security Training for Staff

Starting November 2024, JCU will roll out a new mandatory training course for staff, this course is based on the JCU Digital Technologies Acceptable Use Policy that was approved earlier in 2024.

The training course will be delivered via the Staff Learning Hub for JCU Australia and the Proofpoint external cyber security training platform for JCU Singapore.

Please review the FAQs for the mandatory training .

Awareness Initiatives

  • Online Cyber Awareness Information presented on the Cyber Hub and via Instagram, Facebook and Yammer and more traditional delivery mediums including email and newsletters
  • Cyber Security Presentations and Outreach program
  • Cyber Exercises such as phishing campaigns, competitions and incident response simulations
  • Cyber Safety Training Modules delivered via an external platform; Proofpoint
    • Training modules are designed to provide training to address the top risks and there is additional training for individuals and teams with unique roles or high risk profiles
  • Role, Function and Risk specific Cyber Security Training and Education delivered via external training providers, often in face to face settings
    • Secure By Design development and advanced training for technical ICT staff
    • Threat modelling and Developer training
    • Executive Awareness and Risk Management training
    • Finance specific scams, phishing and  fraud training
  • Special events and campaigns to address emerging risks and threats.
  • Student centric presentations and awareness workshops particularly during Orientation Week and  for special events throughout  the year