Avantec AG
Zug
Layer 8 as a Key Element of IT Security – Tec-Bite IT Security
- 08 August 2026
- 100%
- Permanent position
- Zug
Job summary
Cybersecurity is a shared responsibility between IT and users. Together, we can enhance security awareness and practices.
Tasks
- Foster collaboration between IT and users for better security outcomes.
- Simplify security guidelines to improve user understanding and compliance.
- Utilize engaging storytelling to enhance security training effectiveness.
Skills
- Experience in IT security and user engagement strategies is essential.
- Strong communication skills to convey complex concepts simply.
- Ability to create engaging training content that connects with users.
Is this helpful?
About the job
Many risks can be averted through multi-layered security technologies. The major residual risk is often seen by many security officers in the user. A final, learning-resistant link in this fragile chain? This is how we can turn the user into our partner in crime or partner against crime. It starts with the basic attitude – who actually is the "Luser"? Luser, DAU, Layer 8 problem, EIFOK – the list of "funny" names for users is long. Often two fronts form: the IT or IT security departments against the users. There is a lack of a fundamental, shared understanding and respect for each other's tasks. The user wants to do their job as quickly and easily as possible – they are usually neither interested in IT nor in IT security. It is rather seen as a necessary evil. And it often looks the same on the other side: the IT departments want to enforce their guidelines but often do not really care about the user's processes. A very poor starting point to achieve our common goal: to do our work without becoming victims of a cyberattack. In this scenario, both sides are losers because unnecessary trench warfare is fought, energy is wasted, and the goal is often not achieved in the end. Cooperation instead of confrontation We must open our eyes to reality: the user cannot be forced to understand security. If the guidelines are too long and complicated, they will not read them. If the awareness training is too boring, they will not listen. And if the processes are too complicated, they will find a way to bypass them. Coercion therefore does not work to achieve our goal. Not to mention, we are not in North Korea. So why not make the user a cooperation partner? Instead of dictating from top to bottom – from the expert down to the "DAU" – we can also work together towards a goal – as partners on equal footing. And as a security department, we can really use every reinforcement we can get. Because no matter how clever the artificial intelligence of our security technologies is, it is not always smarter than a human brain. Targeted attacks in particular are difficult to intercept. But with all the users in the company, we have many human brains available that we can use profitably. We just have to activate these brains for us. Multiplayer game – to win, you have to understand each other Henry Ford realised this early on: "The secret of success is to understand the other person's point of view." We therefore want to proactively bring the users on board. We want them to understand our point of view and actively help to comply with security guidelines. An important element for this is the justification of measures. People find it easier to accept something if they know the reason for it. It is completely irrelevant that the reason does not change the actual fact, yet it is central to acceptance. For example, the Swiss Federal Railways (SBB) has been indicating for several years, if possible, the reason why a train is delayed. Although this has no influence on the delay, commuters apparently cope better if they know the background. We should also use this knowledge with regard to the users. We should not only explain that they should do something, but also why they should do it. And ideally also what happens if they do not do it. This should definitely be illustrated with understandable (!) examples. I deliberately emphasise "understandable" here – this means that it must be comprehensible to the user from A to Z – the meaning of every word used must be clear to the user. This may sound trivial now, but it is not so easy, because many words belong to the everyday life of security specialists, but users often do not know in detail what they mean. For example, phishing, malware, patching, proxy, and what a firewall actually is and how the cloud works. We must be aware that the user usually comes from a completely different field and only very rarely comes into contact with these terms. They may know that phishing has something to do with emails, but often do not know how it actually works. If we want the user to understand our explanations, we have to use words whose meaning they know exactly. So it is better to mention fewer technical details and rely on simplified explanations that everyone can follow. What happened at other companies? How do attackers proceed? Who are the attackers anyway and what do they want? How were employees lured into the trap? What damage was caused as a result? It helps if it is shown that the security department is not completely paranoid but is oriented towards real scenarios. These real dangers, communicated in understandable language, will convince the user, because in the end no one wants to be the cause of a major virus outbreak. Storytelling at its best So now we know that we want the user on our side and that we have to communicate understandably. Now we just want to convey the whole thing in the best possible form. The great thing about IT security is that it is so easy to build a good story. Compared to other departments that also want to assert their interests, we have a perfect opportunity. When the accounting department tells us why we now have to use this or that cost centre and why the cost type must always be entered the same (wrong) way, it is rightly boring. And my sympathy goes to the poor accountants, because the story is not a box office hit at all. Quite different in IT security! While cybercrime was still in need of explanation a few years ago, today it is on everyone's lips, on the front pages of newspapers and even in cinemas – thanks to Edward Snowden! This situation offers ideal conditions for entertaining user training where you don't have to yawn constantly. Simulations of attacks are also excellent for this, as personal experience stays in the memory even better. We should best orient ourselves on the stories that life writes and provides us with in abundance. How about the Maersk case, for example? It is known to everyone in the security world – but most ordinary people have never heard of it. Or perhaps the Meier-Tobler case? There are plenty of examples and they can be found for every scenario – unfortunately... Conclusion Respect and understanding towards the user, understandable language and an exciting form of information transmission – and then it will work with the user. Because they may not be directly interested in security, but they are certainly inspired by a good story. My suggestion: wrap the training in an exciting story and have it visually enhanced by the marketing department. And for those who like to combine the useful with the pleasant, add a pizza for everyone on top. Lunch & Learn on IT security. Costs around 20.- per participant and is definitely cheaper than a security breach. Enjoy! Links BTW: Our newcomer solution xorlab has also recognised the user as an important element and integrated it accordingly into the solution: www.avantec.ch/loesungen/avantec-newcomers/#xorlab The article Layer 8 as a Key Element of IT Security first appeared on Tec-Bite.