We've all heard about the security awareness training programs, yet problems still abound. So how should these programs evolve and what can companies do to better equip and entice their end-users to help protect critical data. And which departments should be involved to prevent a non-malicious or disgruntled employee from leaking data?