Proper Training Makes Sure Everyday Users Understand Their Role in Cybersecurity
By Gregory Hale
It wasn’t that long ago with a Massachusetts-based energy supplier ended up hit by a phishing attack. While the attack didn’t shut down operations, it did result in threat actors stealing personally identifiable information.
When workers clicked in a malicious email in the phishing attack, threat actors were able to cull credentials from a couple of email accounts, pivot and exfiltrate customer data and continue on across the network.
RELATED STORIES
- Packaged Systems: Eliminating ‘Inherent Risk’
- Securing Packaged Systems: Podcast
- Learning To Apply A Consequence-Based Risk Assessment
- Understanding Consequence-based Risk: Podcast
That entire attack, which resulted in remediation costs and a damaged reputation with the company’s customers, didn’t have to be that way. For the threat actors, the approach is easy because it has been a tried and true scenario for years: Phishing attacks work because someone will click on a tainted email. For the organization’s workers – all workers – it is not so cut and dried because like Adam and Eve, the temptation is always right there in front of you. They need training to understand what they should or should not do when it comes to a more digital workplace.
Manufacturers are seeing more cyberattacks hitting the industry, and there are more rules, regulations and standards requiring organizations to ensure workers receive cyber training, not just for security professionals, but for everyone.
“There’s been an interesting shift, where quite a bit of training used to be for the practitioners, people at the corporate level or in the plants responsible for designing and implementing OT security,” said John Cusimano, chief strategy officer at industrial cybersecurity solution provider, Armexa. “What we’re seeing now is a bit of a shift, particularly some of the new regulations. And the existing standards are adding requirements OT system users receive training as well.”
Regulatory Security Requirements
There are new maritime cybersecurity regulations from the Coast Guard and the Maritime Transportation Security Act (MTSA), which published a final rule in 2025 that says all reportable cyber incidents must end up reported to the National Response Center. Additionally, by January 12, 2026, and annually thereafter, all personnel must complete specified training.
Moreover, the Transportation Security Administration (TSA) pipeline regulations all emphasize the importance of not just training the practitioners, but the users.
One area in the guidelines describes personnel training where an organization needs to describe security training requirements, to include training in security equipment operation, security awareness, and security incident recognition and reporting procedures for company personnel and contractors.
In OT, there is well-established training available for OT security professionals, but there is a gap.
“In terms of training that’s available for the everyday user; the people, the operators, the instrumentation techs, the control system engineers that interface with these systems every day, and making sure that they understand their role in operational cyber risk, that’s really where there’s new emphasis coming into play,” Cusimano said.
“I think the regulators have hit a point, where they realized operations teams that are not cybersecurity experts and are working 24/7 shifts, there is information they need and decisions they make that can bolster your security, or cause a hole in the fence,” said Dave Gunter, director of OT cybersecurity at Armexa. “The reality is regulators are looking for ways to provide general awareness training and increase the knowledge of the people making those decisions in the field, particularly in off hours. Not everybody has to be an expert but making the right decisions during a maintenance trip or doing coverage, you need a general level of awareness from a cyber standpoint.”
Spread the Word
To that end, security awareness needs to filter further out to ensure a tighter hold, so the company stays up and running and producing product.
“The corporate OT security team usually is going to be well-versed and well-trained,” Cusimano said. “And as you move out to the plant, there will be certain people that have advanced training, but then as you move your way down to field operators or console operators, you are going to find the level of awareness starts to fade away. And that is what regulators recognized, and they’re trying to raise that level, that everybody who touches a control system in some way or another needs to have at least basic knowledge of the risks and their role in protecting these systems.”
They need to understand the rising level of risk because different attack techniques continue to form across the manufacturing sector with threat actors are using tools such as AI to work faster at every stage, from spotting security gaps to writing malware, according to the Verizon 2026 Data Breach Investigations Report.
Threat actors employ GenAI to assist them with various stages of their attacks, such as choosing targets, gaining a foothold within those targets, conducting vulnerability research, and developing malware and other tools to make their efforts more effective and efficient, according to the report.
Meanwhile, social engineering is evolving with attackers increasingly using voice and other mobile-centric techniques to catch workers off guard.
Human element was present in 62 percent of breaches, which is an increase from the previous year, according to the report. Social engineering was the third most common breach pattern, representing 16 percent of all breaches.
Select Proper Training
“We think there’s a place – a very important place – for general OT cybersecurity practitioner level training that trains on best practices and standards and technology,” Cusimano said. “And then there’s a place for corporate-level training, awareness training that covers company-specific policies, standards.”
That mindset falls into role-based training which appears in most industry standards.
“The idea that you first define these roles and what they need to know to do their job, and then you effectively present them with a training curriculum, and it might be just one module. For other roles, it might be a series of training, all the way from general awareness to some very in-depth third-party training.
“One thing is to first get everything on the table, understand all of those requirements and how they affect your facilities, your operating environment. Then we put together a matrix of all our plans, here are all the requirements that we need to satisfy. We then create base material that work across all facilities, all plants, and then work on slight variations that might be regional or sector specific. What’s really important is that upfront planning and then making sure you’re developing something that works for your operating environment.”
Gearing the training for your specific industry and your focused company standards remains vital.
“I can’t emphasize enough that meeting the intent that you train on for the standard or whatever corporate policies and procedures it may be,” Gunter said. “Meeting the intent of your corporate words provide the level of training for people in their own words, with their own standards is fundamental to a company, and it’s very effective.”
Best Practices
In terms of training, Cusimano and Gunter suggested a few best practices:
- Understand your regulatory environment and the way it works
- Tie your training efforts to your governance efforts
- If you have your governance in place, tie your training right to it
- Create training for the role the worker plays
- Layer training that everybody takes on top of that for different roles
- Good documentation for auditors and insurance and regulators
- Understand people’s time, for instance executives have so much time to spend on training
- Keep the training dynamic
“Training is not a substitute for good technical controls, but industry experts always say the three-legged stool of people, process and technology is really important,” Cusimano said. “So are trained people on repeatable processes. Training is certainly one leg of that three-legged stool, and a very important one.”

