The Importance of Security Awareness in the Workplace: Why Awareness is the First Line of Cyber Defense
August 12, 2025

The Importance of Security Awareness in the Workplace: Why Awareness is the First Line of Cyber Defense

In today’s rapidly evolving digital landscape, cybersecurity is no longer the sole responsibility of IT departments. Every employee—from entry-level staff to executive leadership—plays a crucial role in protecting a company’s information assets.

This point is strongly emphasized by Endang Nurakhiri, as Development, Security, and Operations Engineer at Skyworx Indonesia, in his point of view on the importance of security awareness in the workplace.

“Why is security awareness important? Because 80 percent of security incidents are caused by human error. Cyberattacks are becoming more sophisticated and no longer target only IT teams, but employees at all levels,” he said on Monday.

The fact that 80% of cybersecurity incidents stem from human error highlights the critical need for awareness at every level of the organization. Simple mistakes—like clicking on a suspicious link or ignoring security warnings—can open significant vulnerabilities for cybercriminals to exploit.

“The impact? It can be severely damaging—from the loss of critical data, operational disruptions, to lasting reputational harm,” Nurakhiri continued.

These threats go beyond technical issues; they directly affect business operations and organizational credibility. As such, building a strong culture of security awareness is not optional—it is essential.


Four Key Objectives of a Well-Implemented Security Awareness Program

1. Raising Awareness of Cyber Threats

The first step is to increase employees' understanding of the various threats that can strike at any time, from any source.

“If we want to access websites using the office Wi-Fi, we should at least use a VPN. A VPN helps protect or block access to the network from client IPs,” he explained.

Using a VPN is a simple yet effective measure to safeguard connectivity and reduce risks from both public and internal networks.

2. Building a Culture of Information Security

Information security should not just be a set of formal policies—it should be embedded into the daily habits and behaviors of employees.

“A culture of information security often begins with everyday habits. For example, blocking USB storage access at every endpoint. Employees are subject to policies that block all data access from USB devices because USBs can transmit viruses, cause data loss, and again, 80% of incidents are caused by human error,” Nurakhiri explained.

These policies not only enforce limitations but also educate employees to make safer digital decisions.

3. Enhancing Threat Detection Capabilities

Not all cyber threats are obvious. Many are subtle and deceptive. Therefore, employees must be trained to recognize and respond to these threats.

“We must all be able to recognize and prevent phishing attacks, malware infections, and social engineering attempts,” he conveyed.

Ongoing training, simulated attacks, and regular updates are key elements of a strong awareness strategy.

4. Understanding Security Policies and Individual Roles

Every employee should clearly understand their role in maintaining the organization's cybersecurity posture.

“This is also one of the primary goals of security awareness sessions: to understand the company’s security policies and how each employee contributes to them,” Nurakhiri stressed.

By understanding the security framework and their individual responsibilities, employees develop a stronger sense of ownership in protecting company systems and data.


At Skyworx Indonesia, we regularly conduct Security Awareness Sessions for all employees to enhance their understanding of the importance of information security, protecting personal data, and recognizing various cyber threats—from phishing and malware to internal security policies.