Skip to main content

Posts

Showing posts with the label research

Security Awareness Training Has Been Polished Into Irrelevance

Disclaimer: The views and opinions expressed are my own and do not reflect the views, policies, or positions of my employer or any organization with which I am affiliated. ---  (Cyber)security awareness training (SAT) has long focused on recognizing threats inside the enterprise, but anyone who has dealt with a real compromise knows attacks rarely respect those boundaries. Real breaches are messy. They’re personal.  They involve bad timing, strange messages, compromised friends, personal accounts, social media, reused credentials, AI-generated likenesses, family members, phone calls, desperation, embarrassment, deception, and sometimes outright threats or blackmail. Yet we teach security awareness with polished graphics, spotless templates, friendly AI-generated illustrations, and scenarios where the suspicious answer is practically given. What are we actually teaching people to recognize? The problem is that training today focuses too heavily on... Recognizing sp...