A health technology firm has run the same security awareness e-learning module for three consecutive years. Phishing simulation click rates have plateaued and the latest staff survey shows that most respondents find the content stale. The security manager is preparing a recommendation to the executive sponsor. What should the security manager recommend FIRST?
- AShorten the existing module to fifteen minutes so that staff are more likely to engage with it next cycle.
- BIncrease the frequency of phishing simulations from quarterly to monthly to push the click rate down further.
- CRefresh the awareness programme content and delivery channels based on a review of current threats, audience feedback, and metrics. Correct
- DOutsource delivery of the awareness module to an external training provider to bring in fresh material.
Why A is wrong: A shorter module may lift completion comfort and looks like a quick win, but trimming stale content does not address the underlying problem that the material no longer reflects current threats or audience needs. It rearranges symptoms rather than treating the cause.
Why B is wrong: More frequent simulations can sharpen vigilance and feel like decisive action, but without refreshed underlying content they tend to produce fatigue and diminishing returns. Simulation cadence is a tactical lever, not a substitute for programme review.
Why C is correct: A periodic review that drives content and channel refresh is the explicit CISSP expectation for sustaining an awareness programme. Anchoring the refresh in current threats, feedback, and metrics ties the change to evidence rather than fashion and addresses the stalled behavioural results.
Why D is wrong: An external provider can be part of the refresh and feels like a clean way to inject new content, but choosing a delivery model before the review is complete skips the diagnostic step. The provider decision is downstream of the periodic review.