Awareness with Our Cybersecurity Team — The Real Attack Perspective
In the awareness work conducted by the Nesil Teknoloji Cyber Security Team, it was emphasised that cybersecurity is not only about technical measures and must be addressed along the axis of the human factor, behavioural vulnerabilities and social engineering.
Going beyond the classic presentation format, the training and awareness session was supported with examples and symbolic narratives reflecting the real attacker's perspective. The aim is to enable participants to recognise cyber threats not just as a "technical risk" but as a natural part of their daily work practices.
1. Awareness Approach
The work was designed with an experience-sharing-based approach centred on the question "how does an attacker think?". It was conveyed to participants that defence reflexes cannot be developed without understanding the logic of attack.
- The critical role of the human factor in cybersecurity
- The effect of behavioural vulnerabilities on technical vulnerabilities
- Making invisible risks visible
2. Content Topics Covered
- Social engineering and psychological manipulation techniques
- Current scenarios used in phishing attacks
- The concept of insider threat
- Risks that arise unnoticed in daily workflows
- How cybersecurity teams view incidents
3. Realistic Scenarios and Narratives
In the awareness work, the attacker's methods of hiding, concealing identity and gaining trust were conveyed to participants using symbolic and visual narratives.
- Unauthorised access being presented as an innocent behaviour
- Obtaining information by establishing a relationship of trust
- How the perception of "they know me" is exploited
4. Corporate and Individual Gains
- Gaining behavioural awareness against cyber threats
- Earlier recognition of human-caused risks
- The formation of a common language between cybersecurity teams and users
- Strengthening of the culture of secure behaviour