ASAP EN Course Knowledge Organizer
ASAP EN Course Knowledge Organizer
Automated
Security Awareness
Platform
Kaspersky Automated
Security Awareness Platform
Knowledge Organizer
This is the knowledge organizer with a text information from the course, so you can return to the
materials at any time and revise it again with no need to watch the course all over again.
• 37% of people have accidentally found confidential information of their colleagues, e.g.,
salaries/bonuses at work.
• 80% of people don't think they are responsible for ensuring that documents — such as emails,
files, and paper documents — have the appropriate access controls or limits.
• More than 1 in 5 employees said they used the same password for their personal bank accounts
as they did for work-related accounts.
But properly trained, aware staff who practices effective cyberhygiene can also become a very effective
first line of defense reducing the number and cost of incidents.
While companies are eager to implement security awareness programs, many are unhappy with both the
process and the results. Small and medium businesses, which don't usually have the experience or
resources needed, are particularly challenged in this area.
• 42% of SMBs and 43% of enterprises have experienced IT security infringement by employees,
while changes to security policies are the most popular measure that companies use to prevent
the repetition of data breaches.
• 42% of organizations have experienced inappropriate IT resource use by employees.
There are programs that aren't efficient for students and are too time-consuming for administrators. But
there's no doubt that training is essential for raising awareness among employees and motivating them
to pay attention to cyberthreats and countermeasures — even if they don't initially realize that it's part of
their work responsibilities. Unfortunately, many security awareness training programs are ineffective.
Based on our vast experience and practice, we have identified the two main difficulties that customers
face when choosing a Security Awareness solution.
Let's see what kind of challenges companies face while building their security awareness program, what
your buyers' pain points are — and how Kaspersky Security Awareness Products can help.
Here is why
Security Awareness training is often perceived as a difficult, boring, or irrelevant drudge.
Some employees tend to consider this kind of training as too complicated and technical to be worth
devoting their time to, and often fail to see the connection between their actions and possible
consequences.
Training can also be ineffective if employees feel so overwhelmed with instructions about what they
should and shouldn't do, that they can't digest it all and become defeatist — cybersecurity issues get
viewed as nothing more than a series of endless restrictions and hindrances to getting on with the job.
Knowledge is not retained
It's also a fact that training programs are often too short, so that the knowledge acquired just doesn't
have time to sink in and be retained. Or it's too long and tedious to complete, full of peripheral, irrelevant
information. In both these scenarios, employees continue to act just as normal.
Another customer pain point is that training is often an administrative burden: when it comes to training,
many customers' IT teams have to endure painstaking program management, struggling with in-depth
reporting and pressured course corrections, not to mention employee engagement.
How to find a right balance between mandatory half-day sessions, with the learner stuck in front of a
screen, pretending they're focused on a PowerPoint presentation while surreptitiously looking at their
phone, and extensive complex programs, where employees become so overwhelmed with instructions
about what they should and shouldn't do, that they simply fail to absorb anything, become despondent
and lose interest?
• Content based on well-defined secure behavior, comprised of specific, necessary skills, and
using different formats to ensure better mastering.
• Motivation: identification of gaps justifies the need for training. Real-life examples, relevance to
employees’ everyday life, ability to start applying skills immediately after each lesson help
maintain motivation.
• Schedule: an automated learning path clearly following various training activities based on a
training target. The activities are presented at certain intervals, taking into account the
characteristics of human memory, with incremental learning ensuring the use of acquired skills.
• Certification: to ensure that employees have the necessary skills to resist cyberthreats, they
simply need to take a test before training (if they think they are sufficiently advanced) or after
completing the module to certify the required level of knowledge.
• Kaspersky's main advantage is full automation of online training. Program content is structured to
support incremental interval learning, with constant reinforcement.
One of the most important criteria when choosing an awareness program is its efficiency. But how do
you know that an awareness program is efficient? With ASAP, efficiency is built into the content and
automated management, and reinforced by the methodology and our cybersecurity expertise.
Let's see how it works.
ASAP covers all major cybersecurity topics. But in addition to those cybersecurity concepts that
correspond to separate topics, there are many more that are covered in several topics at once. The full
list of concepts covered within a course can be seen in its hashtag list.
ASAP Express course
A short version of the training in audio-video format. We recommend assigning this course when a
customer needs to quickly upskill employees: give a crash course to new staff, raise cybersecurity
awareness of those who were involved in cyberincidents or violate cybersecurity rules, meet regulation
requirements, or refresh what was taught earlier. Each cybersecurity topic contains several short lessons
to help the user grasp basic cybersecurity skills.
• Interactive theory;
• Videos;
• Tests.
Multi-modal content
ASAP offers well thought-out, structured content that includes easy-to-consume interactive lessons,
tests, constant reinforcement, and simulated phishing attacks to ensure that skills will be applied.
Reinforcement emails and lessons packed with real-life examples that highlight the personal importance
of cybersecurity for employees.
Phishing attacks are integrated into the learning path and assigned automatically, but can be also
launched separately as a simulated phishing campaign. Phishing campaigns are offered in addition to
the main course. They test employees' practical skills in avoiding phishing attacks, and help training
managers to quickly identify gaps in users' knowledge and encourage further study of troublesome
topics.
The platform comes with ready-made email templates containing phishing examples that can be sent to
users in all available languages. The templates take into account regional specifics, are regularly
updated and new ones added. There is also a possibility to create custom emails based on predefined
templates.
Propose your customers to try a simulated phishing attack before training to check their
employees' resilience! It will help you to demonstrate the importance of the learning, and for
employees and management to see the benefits of it.
Fact: In 2021, the average victim cost of a phishing attack was $136.
The state of phishing: Report and Statistics 2021.
Source: [Link]
$136 for a phishing attack doesn't sound too bad, right? Wait… let's just do the math.
Small businesses with fewer than 250 employees tend to be more susceptible to email threats like
phishing, spam, and malware. And one in every 323 emails sent to these businesses is malicious. Now
consider that each employee receives an average of 121 emails per day (some of which will be dealt
with by the spam filter). Let's take a company of 100 people. On average, based on the figures above,
they receive up to 37 malicious emails per day, which comes to 8,062 malicious emails per year (only
working days calculated). Now consider the average phishing click rate (taking into account regional
differences), which is about 20% for those who haven't completed security awareness training. What
does this mean in real terms? 1,612 * $136 = $219,232… an amount which far exceeds the cost of
security awareness training.
Use this information to show your customers the benefits of security awareness education.
This simple example will also help you to explain your prospects that security awareness is not an
expense but an investment in business sustainability and efficiency.
Employees can not only demonstrate their understanding of a topic by not being fooled by a simulated
phishing attack, but also illustrate the real change in their behavior and more conscious attitudes by
reporting phishing mails via the "Report phishing" tool.
Flexible learning
The scope of the learning is completely flexible, while retaining the advantages of sequential automated
learning management. For each training group you can choose:
Easy to manage
Fully automated learning management brings every employee up to the skills level appropriate to their
risk profile without any intervention from the platform administrator.
Synchronization with AD (Active Directory), SSO (Single Sign-On), Open API (the ability to interact with
third-party solutions), online onboarding during the first visit, a FAQ section and tips — all make platform
management convenient and efficient.
Easy to control
Clear, actionable, 'all-in-one' dashboard: the platform presents quantifiable results in graphs and
dashboards that objectively demonstrate progress and provide practical recommendations.
Easy to engage
Notifications are part of internal communications. Regular internal communications are embedded into
the platform and ensure the formation of a strong cybersafety culture within the company. The
administrator doesn't need to spend time on it; the platform itself sends reminders, reports, and
recommendations to users.
Regular internal communications ensure the formation of a strong cybersafety culture within the
company.
ASAP saves hours of administration work. Notifications are part of internal communications.
Customization and white labeling
The administrator can easily change the program's appearance:
• Replace the Kaspersky logo with the company’s logo in the admin panel, learning portal, and
platform emails.
• Change domain of the training portal (portal for learners).
• Customize certificates — change certificate background.
• Remove copyright information from the footer both for admins and learners
• Remove links to Kaspersky from the footer in the learners’ interface (only Terms of use, where
Kaspersky is mentioned, remain in the cloud version; in the On-premise version it can be
removed as well).
• Add personalized content to any lesson.
Integration
There is a possibility to use Open API to interact with third-party solutions — Open API works via HTTP
and offers a set of request/response methods.
Value Proposition
• Predefined efficiency through full training automation. Program content is structured to support
incremental interval learning, with constant reinforcement.
• Time-saving product management. The program is very easy to launch, configure, and
monitor, and ongoing management is fully automated. It's an online product with easy delivery.
Those customers who require maximum level of confidentiality and would like to work without
internet connection may benefit from ASAP On-premise edition (launched in Q4 2023) deployed
in the organization's network. This ensures the same functionality as cloud version of the
platform.
• Flexible licensing. The product has a per-user licensing model.
• Pay only for active users (those who are learning). There's no need to pay for those who are
away (left company or on maternity leave, for example).
Kaspersky ASAP can easily be sold by current Kaspersky Partners. It offers the following
benefits for partners:
Financial conditions. Kaspersky Security Awareness product rebates are calculated within the
framework of the partner program. Enrolling for security awareness specialization is another great
opportunity for partners to earn additional financial rewards and access other benefits. For MSP
partners, volume-based discounts are applied — the more customers you have, the less you pay.
Managed services. Even though ASAP is very easy to manage, some customers still prefer to invite
their IT service provider, for example, the Kaspersky partner — to configure and manage it. The income
from these managed services goes directly to the partner (and, of course, we offer free training to their
specialists to provide these services).
Licensing tailored to MSPs. Partners can buy a pool of licenses in their name and distribute them
among their customers. Monthly subscription is also available for these partners.
Managing multiple companies from the same account. The platform enables partners to deploy and
manage awareness training for all customers from a single console ready for multitenancy, with no need
for additional software. Good news! Kaspersky ASAP features License Quota Management, which
allows MSP partners to assign a quota of licenses for each company and set expiration periods for these
licenses. There is also a possibility to add additional administrators for each company and assign them
different roles.
Opportunities for xSPs. The solution perfectly fits xSP needs: many telecom providers, banks, etc., are
interested in selling online awareness platforms to their B2B customers. ASAP's ease of delivery,
automation, and flexible packaging is exactly what they need. Thanks to the On-premise version, they
can install ASAP on their servers or get only the ASAP content as a SCORM package to be integrated
into their LMS.
Tracking training progress with dashboards and advanced individual reporting functionality is easy and
includes recommendations on how to encourage users and foster their skills.
ASAP's universal, practical training curriculum develops specific security skills for all levels, from
beginner to advanced. ASAP covers a comprehensive range of key cybersecurity topics and
recommends training targets based on each participant's risk profile. Each unit includes several lessons
with an average duration of 3-5 minutes, reinforcements, tests, and simulated phishing attacks. This
learning path ensures that students can apply the acquired knowledge and skills in their daily life.
All content elements are localized into major languages and are culturally appropriate. The platform is
available worldwide in 27 languages and the number of languages is growing constantly. The full list of
available languages can be checked on [Link].
Target markets
Kaspersky Security Awareness training can act as a door-opener to winning new accounts. There are
also opportunities for you to upsell and cross-sell to existing customers. Kaspersky ASAP is suitable for
both SMB and enterprise segments as well as public and government bodies.
Kaspersky Automated Security Awareness Platform is integrated with KUMA and XDR and could be
promoted as a unique competitive advantage to the customers who use or plan to use these solutions.
1. Security awareness training from the leading cybersecurity vendor. In the heart of the platform
lies more than 350 practical skills that employees should possess in order to behave cybersafely.
2. Time-saving program management.
3. Training efficiency based on the specifics of human memory that develop 'pattern perception':
employees are able to recognize new dangers and behave safely even when faced with unknown
threats.
4. Well-thought-out program, not just a library of content.
5. Quantifiable results in graphs and dashboards.
Kaspersky products are installed on more than 400 million computers worldwide, and we understand
cybersecurity better than most — we're the most tested, most awarded security vendor. Our interactive
learning course consolidates systematized knowledge on security awareness principles and covers all
major security domains. Using our experience and expertise, we've created a competency model that
differentiates employee categories by typical risk profiles.
When management uses this model, they can easily set up their program objectives by making decisions
about time investments and targets for cybersecurity awareness.
SoftwareReviews, a leading source for insights on the software provider landscape, named Kaspersky a
Gold Medalist with an overall composite score of 8.9/10 in 2023 Security Awareness & Training Data
Quadrant Report. Customers called Kaspersky products critical to professional success (90%), also
noting ease of implementation (90%) and usability & intuitiveness (89%).
Not all training levels are appropriate for all learners — some have less knowledge, and others learn
more quickly. Individual development plans may provide a solution, but who has time for something so
time-consuming? Our platform does this by itself. Automated program management will not just build a
learning schedule and assign all program elements to learners, but will also send reminders and
notifications without any interaction from the administrator's side.
• Constant reinforcement with certain intervals helps to cement the acquired skills.
• Real-world examples and contexts, test questions based on the situations employees may face in
their everyday work help them to better associate themselves with the training materials and,
accordingly, not to lose interest and to make it stick.
• Clear, logical lessons structure and digestible format make the training more convenient for
learners and better to absorb.
• Different content formats like interactive micro-lessons, tests, reinforcements, simulated phishing
attacks help to avoid learners' overload and preserve their attention.
• According to our research, 89% of respondents note behavior changes after taking the course.
Quantifiable results in graphs and dashboards
As the awareness program is implemented, the questions of control and results analysis arise. To enable
timely course corrections and comprehensive reporting to management, simple answers to key
questions are needed.
Our solution allows companies to set measurable goals that can be clearly monitored and are available
to the management team as required. It's not just overloaded with statistics (that you don't know what to
do about), but identifies trends, issues, and problems. This helps the customer take corrective or other
actions. Where goals are not reached, data can be analyzed down to individual level to take
corresponding measures.
In a feature-by-feature comparison, you may not be able to clearly articulate the advantages of
Kaspersky approach. By identifying the tensions* the customer faces (rather than asking them to state
their need), you focus on things that really matter, and avoid embarrassing or demotivating the prospect.
Our advantage lies not in the list of features, number of states and reports, but in the human-centric
approach, learning methodology, and ease-of-use which facilitates true goal achievement.
Let's take a closer look at the functionality of our products in comparison with other solutions currently on
the market.
In addition to learning platforms, there are also other security awareness solutions on the
market. Let's look at their pros and cons.
1. Classroom-based training
Classroom-based training is exactly what it sounds like.
Attendees are taken away from their usual roles and, for at least a few hours, take part in a workshop
where an instructor leads them through the ins-and-outs of at least one security topic.
The pros of classroom-based training:
The major advantage of classroom-based training is the immediate feedback loop both class instructor
and attendees receive. Participants can ask for clarification or request further information and advice,
and get an immediate response.
Classroom-based training also comes with a relatively substantial price tag. The costs of staff away-days
can't be ignored, nor can the cost of hiring specialist instructors.
Finally, the infrequency of classroom-based training further jeopardizes its potential efficacy.
Organizational difficulties, sick days, vacations and workload of employees mean that for every
employee such training takes place annually at best. This raises questions about just how much the
training attendees will be able to recall 11 months down the line, and also how much of the content will
still be relevant a year on.
In ASAP, learning is fully automated, which removes individual assignments and differentiated learning
paths, so that customers don’t waste time fiddling with individual settings. Although the platform interface
is intuitive, and most of our customers grasp it immediately, Kaspersky offers a variety of onboarding and
supporting tools.
Ongoing methodological and technical support is available via instant messages in online chat or by
email. Kaspersky offers guidelines for effective security awareness training — information/suggestions
on how to organize training, how to decide what target levels to set for different employee categories,
which criteria to use for initial user assessment, and so on. There are also suggestions on how to
improve training results, including ready-to-use communication templates. Online automated onboarding
for new users is also available.
The most effective approach — engage all employees, starting from the top, in cybersecurity
initiatives
In the past, many CISOs may have opted for just one of the above training methods. But today, many
are using a combination of all of them in order to effectively address the human aspect of cybersecurity
— an approach that we advocate at Kaspersky. While Kaspersky ASAP remains an essential part of our
offering, the ideal scenario is where customers buy ASAP together with our other role-based offerings.
All the different elements that make up the Kaspersky Security Awareness portfolio address a specific
part and purpose towards building a cybersafe culture. The ideal scenario that we recommend is for
organizations to take all the different components and create a holistic sequence of learning and skills
that result in a true culture of cybersafety at every level of your organization.
To recap: Because sustainable changes in behavior take time, our approach involves building a
continuous learning cycle with multiple components. Game-based learning engages senior management
turning them into advocates of cybersecurity initiatives and supporters of building a culture of cybersafe
behavior: KIPS simulation shows senior managers how IT security threats affect business results and
motivates to maintain a cybersafe working environment. Gamified assessment helps to define gaps in
employee knowledge and motivate them for further learning, while the online platform and simulations
equip them with the right skills, duly reinforced. And training for IT professionals helps build a strong first
line of incident response.
Key advantages
Let's remind ourselves of the key advantages of Kaspersky Security Awareness over competitors'
offerings.
Kaspersky has a family of computer-based training products that utilize the latest learning techniques
and address all levels of the organizational structure, ideal for SMBs and enterprises. Kaspersky ASAP
forms a central part of this comprehensive portfolio and represents an integrated solution that doesn't
focus only on one aspect of cybersecurity — like phishing — and isn't intrusive, but interactive.
1. Efficient learning based on content and methods provided by specialists in education, personal
development and cybersecurity to minimize the number of incidents caused by employees’ errors
or ignorance.
2. Easy implementation — a unique feature in the security awareness market.
3. Training portfolio covers all organizational levels.
Licensing model
Kaspersky ASAP is licensed on per trainee basis. The licensing period is 1, 2, or 3 years. As mentioned
earlier, the minimum initial order quantity is 5 licenses.
Monthly subscription is available for MSP partners. To learn more about the MSP program, please visit
the relevant page on the partner portal. Please note that pricing may be different across regions — for
up-to-date price lists, just contact your local Kaspersky representative.
There is no separate SKU for ASAP On-premise solution. The minimum order quantity for On-premise
installation in the customer’s infrastructure is 250 licenses. To check technical compatibility with the
customer’s infrastructure, please refer to Online Help.
In 2021, small businesses were three times more likely to fall victim to fraudsters than larger companies.
We can't afford to lose productivity while employees spend time on awareness platform
The average loss from a single cyberattack has exploded from $34,000 to just under $200,000. Plus
there's legal fees, compliance penalties, reputational damage, and the loss of customers — could you
survive that sort of hit? There's really no point refusing to invest in the few training hours needed to
protect your business against being wiped out — at which point productivity will no longer be an issue.
Classroom-based training, for example, is good for urgently delivering specific information because of
the immediate feed-back, while visual aids, videos, and games are perfect for engaging employees'
attention and preventing boredom. But they don't ensure knowledge retention and behavioral changes.
And attack simulations keep everyone on their toes! But there are a huge number of other types of
threats that employees need to be aware of — recognizing the signs of danger and knowing how to
avoid them. It's important to choose a program that includes different types of activities and content
formats to address different topics and appeal to different mindsets — based on real-life scenarios and
taking a human-centric approach. Behavioral change is not an 'instant fix'. For training to work properly,
it should also ideally be broken up into small portions throughout the year, constantly reminding and
reinforcing, rather than being offered as a single intensive learning experience which can then be left
behind.
85% of respondents of the Kaspersky ASAP users' survey noted positive changes in behavior in their
daily job as well as in their personal communication on the internet and using personal devices after
completing the course.
Having identified more than 350 practical cybersecurity skills that all employees should have in order to
protect themselves and their employer from cyberattacks, we employ a learning methodology grounded
in the science of the specifics of human memory. Our portfolio includes products for each stage of the
learning cycle: engagement and motivation, determining the current level of knowledge and identifying
gaps, training and consolidation.
Users who fail to respond correctly to a simulated phishing campaign are in the risk area. Our platform
offers an easy way to gather failed users into a training group and assign them a specific learning path to
improve their antiphishing skills.
By the way, did you know that 76% of CEOs admit to bypassing one of their organization's security
protocols to get something done faster? Sounds familiar? We have a specific offering to target this area
— an exciting business simulation team game that vividly demonstrates the impact of cybersecurity on
business continuity and revenues. This can then be reinforced with an interactive workshop.
We also offer training for generalist IT-specialists — a type of employee who often misses out, because
security awareness programs are too basic, and costly advanced programs are built for information
security specialists.
Customers don’t need to run the same training modules for all employees every year: newcomers could
be assigned to a group with the basic training program, and employees who have already completed
training could be assigned to an express course, or you can assign them separately only the topics that
require improvement or where the content has been updated in accordance with actual threats. We
recommend backing up this training at least quarterly with simulated phishing attacks.
Awareness platforms take too much management. We don't have that sort of time
Launching and managing a comprehensive program full of different types of content and offering ample
scope for customization can take time, and the complexities of figuring out which elements to deploy and
what to assign to which employee can prove a stumbling block for smaller businesses.
So we've developed a program that not only addresses different levels in the organization, and where
each product serves a specific purpose, but one that has automated the learning process. To start
learning with our platform, simply register on the site, upload users to the platform and divide them into
groups according to the desired target level of learning. The platform will do the rest!
[Link]