F.A.Q.

Isometric Graphic. Three people and a laptop and graphs.

Getting
Started

What is preventative security awareness?

Preventative security awareness is about delivering guidance to your people exactly when they need it, at the point of risk. Traditional awareness tends to come too infrequently, too soon and thus forgotten, out of context or after the fact as a “telling off” and is therefore ineffective at changing behaviour and reducing risk.

What isn't preventative security awareness?

Preventative security awareness should not simply be about finding new mediums over which to deliver awareness, such as appearing in Teams, WhatsApp, Slack, and SMS – unless it is timely and relevant to what people are doing. Preventative awareness is not about responding after the event e.g. with phishing simulations or drawing on events in the SIEM or other tools to trigger awareness after the fact. This can be useful data, but preventative is about delivering the learning as the behaviour is occurring.

Why is it important to get preventative awareness right?

Truly preventative security awareness supports and guides people, steering them towards secure behaviours and habits and thus reducing risk. The alternatives tend towards “punishment with training” or simply become new mediums to nag people over!

Why is preventative awareness more effective?

Behavioural science models, from BJ Fogg to those of the Behavioural Insights Team, as well as research on habit formation, all highlight the importance of Context and Timeliness. Effective behaviour change therefore requires interventions to be as timely and close to the context/point of risk as possible. And ideally before – otherwise our ego is threatened and we quickly rationalise away any guidance we are offered.

Can real-time awareness be predictive and preventative?

YES. By intervening as people engage in potentially risky behaviours, not only can we embed and reinforce secure behaviours, but we can nudge people towards a new course of action preventing a link from being clicked, a file from being uploaded, or credentials from being lost.

Nudges

Are nudges annoying/intrusive?

Our clients and their staff don’t find them so, no! Nudges are carefully configured, based on our years of experience to support, guide and embed behaviours, not to annoy or get in the way. All nudges can be configured to be easily dismissed simply by mousing over, clicking OK etc. Furthermore, we never turn all nudges on at the same time but recommend running focused campaigns on one or two behaviours at a time to see real impact. Nudge frequency can be dialled up or down to suit your organisation.

How do you prevent nudge fatigue?

With Redflags® , we recommend running focused campaigns on one or two behaviours (max) at a time to see real impact. This results on a total of 1/2 nudges running at the same time. Furthermore, nudges can be set up to show on every occasion or just sometimes to reduce the fatique. For example, a nudge to remind to “check the sender” can be set up to appear every 4 times someone over a link in their inbox, instead of everytime. Remember, nudge frequency can be dialled up or down to suit your organisation.

What tools can Redflags work with?

Redflags can nudge on any window from any executable, in any browser tab/URL. It can nudge users as they use Teams, Slack, MS Word, Outlook, Chrome etc. Most common use cases include nudging when:

  • users type their email address in their browser (e.g. log-in into an online portal)
  • users hover/click a link in the email copy or around attachment usage in Outlook.
Can we nudge on unauthorised downloads (iTunes, angry birds E.G)?

We can nudge on certain file types in downloads folder, or on the URL for the downloads, like a plug-ins page.

How do we ascertain what we need to nudge on?

Redflags only nudges on behaviours that we agree with you the client, by default, no nudges are on. We have a set of behavioural triggers that allow us to respond to events on the device. These events are generated by Redflags through operating system events e.g. which application is in focus, has media been inserted. Some of these triggers are chained together e.g. link clicked in an email from an unknown sender immediately followed by entry of text into a text box in a browser.

How are nudges actually triggered? i.e: How do you know when to trigger a nudge on an email/web browser?

There is detailed documentation for customers on how to test various nudges, which they use when previewing content. We can also make nudges trigger on specific cues, e.g. visiting a certain website, or opening a specific application.

The tech

How is the agent updated on devices?

We tend to provide a new installer for the agent once every 6 months although it may be less regular than this. The content and nudges are pulled down to the client allowing nudge and content capabilities to be updated all the time.

Can Redflags integrate with my phishing sims/ e-learning provider

Redflags does not have any direct integrations with LMS or phishing providers, but it can happily run side by side such that your people are nudged as they do a phishing simulation. Data can be exported from Redflags to allow combined reporting. We often work with clients to combine nudge and phishing sim data sets for analysis.

How does this impact MSFT Defender

We have never seen any interaction issues with other security tools. Redflags is registered as an application with Microsoft and does not carry out ‘suspicious’ kernel level activities that would trigger such a tool. We are agnostic to URL re-writing. We will need a few URLs allow listed for Redflags to talk to our servers.

How does the product integrate with the new Outlook (HTML5/Edge based)?

It currently works with new Outlook but as there are ongoing changes and upgrades to New Outlook we have to take an iterative approach to functionality.

Can we integrate with Google Workspace?

Integration with Google Workspace is currently under development.

Are you ISO ISO27001 certified?

We hold Cyber Essentials Plus and are accredited to level 2 of the IASME governance standards, which is based on the same principles as ISO27001.

Still need help?