Building Information Security Culture: How Welcome Training Turned Rules into Engaging Dialogue
A large software company has shared how it replaced dry policy documents with an interactive Welcome Training program to build genuine information security culture among its staff.
The organization already deploys advanced controls such as access restrictions, security policies, an SIEM system, and antivirus solutions. However, these tools proved ineffective when employees lacked basic understanding of why rules exist and what consequences follow from violations.
What did not work
Signing a policy document during onboarding proved insufficient, as staff rarely retained the content. Posting rules on the corporate portal also failed to drive compliance, since no verification mechanism existed.
The target audience consists of developers, analysts, testers, product managers, and designers. While these professionals often master complex product security technologies, many still store passwords in Google Sheets, showing that technical skill does not automatically translate into security culture.
Welcome Training structure
The company therefore introduced 45-minute in-person sessions limited to groups of 7–10 people. The format encourages questions and discussion. The curriculum includes:
- Current threat landscape with examples of major Russian incidents
- Step-by-step attack mechanics to illustrate individual impact
- Assets under protection, including code, data channels, and personal information
- Consequences of sharing credentials or personal data
- Password requirements and use of corporate password managers
- Proper use of corporate email
- Storing sensitive data on encrypted volumes with VeraCrypt
- Secure credential transfer using the pbin service
- File checking via VirusTotal and antivirus tools
- Recognition and response to social engineering
- Signs of workstation compromise and reporting procedures
- Overview of deployed corporate protections such as Kaspersky Endpoint Security, Kaspersky Secure Mail Gateway, and SIEM
Results include higher engagement, better retention, increased awareness of personal responsibility, and a measurable drop in human-factor incidents.
Related articles
Global AI Regulation: From Strict School Bans to Unregulated AI Havens
Countries are adopting sharply different approaches to AI oversight, ranging from comprehensive risk-based frameworks to outright prohibitions on generative tools in education. The United States relies on a patchwork of state laws and presidential actions, including Texas TRAIGA restrictions on high-risk AI systems and New York’s moratorium on generative AI in grades 2–8. The European Union enforces the AI Act with four risk categories, while Italy adds criminal liability and human oversight requirements in critical sectors. Norway and China have implemented some of the strictest classroom and content-authenticity rules, and Russia introduced its first baseline AI law defining sovereign models effective September 2026. Several nations have also blocked popular chatbots such as ChatGPT, DeepSeek, and Grok. Meanwhile, commercial platforms like FinamX continue integrating multiple AI models into financial workflows despite the regulatory tightening.
How Russian Companies Can Legally Transfer Personal Data to Contractors Under 152-FZ
The article explains the legal distinction between data processors and independent operators when outsourcing tasks involving personal data. It details that the role of a contractor is determined by who sets the processing purpose, not by the service contract itself. For processors, a detailed data processing instruction under Article 6 of 152-FZ is required, while independent operators need a separate legal basis such as consent or contract performance. Special rules apply to employee data under Article 88 of the Labor Code, mandating written employee consent for transfers to third parties. The guidance also covers sub-processing risks, transparency obligations, and penalties under Article 13.11 of the Code of Administrative Offenses. Practical checklists help organizations classify contractors and prepare the correct documentation.
Russian Data Centers May Face Temporary State Management Under Decree 604 for Protection Shortfalls
Large Russian data centers could be placed under temporary government administration if they fail to meet security requirements outlined in presidential decree No. 604. The measure targets critical infrastructure operators that neglect physical and cyber protections, create operational risks, or respond slowly to incidents such as drone strikes. Rosimushchestvo would typically assume management duties by default. Market participants note that Tier III and higher facilities generally maintain strong cyber defenses, shifting the main compliance burden to physical safeguards for generators, cooling systems, and network nodes. Operators including RTK-DC and RUVDS have already begun reviewing and upgrading external equipment protection. Additional costs for redundant communications, DDoS mitigation, vulnerability management, and faster recovery are expected to be passed on to clients in government, finance, and telecom sectors. First Deputy Prime Minister Denis Manturov stated that decisions will remain targeted and will not trigger widespread nationalization.
iMazing 3.6.3 Restores Sideloading of Removed iOS Apps via macOS After Apple Authentication Changes
Developers of iMazing have released version 3.6.3 that restores the ability for users to download and install applications previously removed from the App Store onto iPhone devices. The update currently functions only through macOS, with Windows support still pending further development. The changes address authentication and download errors that appeared in macOS 26 and earlier versions following modifications by Apple to its CommerceKit system. Apple began returning HTTP 403 Forbidden responses to tools including iMazing, ipa_downloader, and 3uTools by deactivating legacy tokens and revoking certificates used for app authentication. The restrictions have particularly affected Russian users who relied on these tools to reinstall banking and other applications removed due to sanctions. Support for macOS 27 Golden Gate and Windows remains unavailable and requires additional engineering work.