Blog

Perspectives on human
risk and realistic practice

Articles for leaders building adaptive human risk programs, not checking a compliance box.

How to Make Cybersecurity Awareness Month Last All Year
TRAINING & CULTUREOCTOBER 1, 2026

How to Make Cybersecurity Awareness Month Last All Year

Most of October's awareness push has worn off by spring. What the research says about training that fades, and a plan for using this month to build security habits that last.

Read more
Open Enrollment Season Is Phishing Season
THREAT TRENDSSEPTEMBER 24, 2026

Open Enrollment Season Is Phishing Season

From benefits deadlines to bonus letters and W-2 requests, Q4 hands attackers a calendar of emails employees already expect. The HR lures to watch for and how to get your team through the season.

Read more
ClickFix: The Attack That Talks You Into Hacking Yourself
THREAT TRENDSSEPTEMBER 17, 2026

ClickFix: The Attack That Talks You Into Hacking Yourself

Fake CAPTCHA pages are tricking people into pasting malware commands into their own machines. ClickFix attacks surged over 500 percent and now appear in nearly half of initial-access incidents.

Read more
Social Engineering Is Coming for Law Firms, Big and Small
PROFESSIONAL SERVICESSEPTEMBER 9, 2026

Social Engineering Is Coming for Law Firms, Big and Small

Privileged communications, deal files, and client escrow accounts make law firms irresistible targets. The FBI says one criminal group has focused on law firms since 2023, and it goes after the people, not the perimeter.

Read more
Protecting Accounting Firms from Social Engineering
PROFESSIONAL SERVICESSEPTEMBER 3, 2026

Protecting Accounting Firms from Social Engineering

Tax returns, Social Security numbers, and client financials make accounting firms prime targets. Attackers are going after the people, not the firewalls, and protection needs to reach the moment of decision.

Read more
Hackers Are Calling Employees and Walking Them Into the Attack
THREAT TRENDSAUGUST 28, 2026

Hackers Are Calling Employees and Walking Them Into the Attack

Voice phishing and fake IT support are often only the setup. The decisive step is usually the credential entry, MFA approval, download, or installation that follows.

Read more
What Should Happen After an Employee Fails a Phishing Simulation?
PHISHING SIMULATIONAUGUST 21, 2026

What Should Happen After an Employee Fails a Phishing Simulation?

A failed phishing simulation should not be the end of the exercise. It is a behavioral signal that should drive immediate reinforcement, matching remediation, and a smarter next test.

Read more
How Often Should You Run Phishing Simulations?
PHISHING SIMULATIONAUGUST 19, 2026

How Often Should You Run Phishing Simulations?

Monthly or quarterly testing is common, but frequency alone does not make a program effective. The better question is whether simulations adapt to the employee and the threat.

Read more
AI Phishing Attacks: The Trends We Are Seeing in 2026
THREAT TRENDSAUGUST 14, 2026

AI Phishing Attacks: The Trends We Are Seeing in 2026

Phishing volume is down, click rates are up, and the attack toolkit now sells for the price of a laptop bag. What the industry data says about where AI phishing is heading.

Read more
America's Water Utilities Are Under Attack: Why the Human Layer Remains the Most Accessible Target
CRITICAL INFRASTRUCTUREAUGUST 10, 2026

America's Water Utilities Are Under Attack: Why the Human Layer Remains the Most Accessible Target

A coordinated cyberattack just disrupted water systems in at least a dozen states. Critical infrastructure is now a prime target, and the people who run it remain the easiest way in.

Read more
Phishing Doesn’t End at the Inbox: Why Human Risk Protection Must Extend Into the Browser
HUMAN RISKJULY 24, 2026

Phishing Doesn’t End at the Inbox: Why Human Risk Protection Must Extend Into the Browser

Phishing attacks often become dangerous after an employee clicks. Learn why human risk protection must extend into the browser and reach the point of decision.

Read more
Stop Trying to Make Your Employees Care About Cybersecurity
HUMAN RISKAPRIL 7, 2026

Stop Trying to Make Your Employees Care About Cybersecurity

One of the most common misconceptions in cybersecurity is that getting employees to care more is what reduces risk.

Read more
Shame Doesn't Teach: How the Cybersecurity Training Industry Gets It Wrong
TRAINING & CULTUREAPRIL 3, 2025

Shame Doesn't Teach: How the Cybersecurity Training Industry Gets It Wrong

Punitive security training creates fear and silence. Learn why positive reinforcement builds stronger defenses than shame-based approaches.

Read more
What We Can Learn from MGM's Breach
REAL-WORLD THREATSMARCH 21, 2025

What We Can Learn from MGM's Breach

The 2023 MGM cyberattack shows how vishing tactics can bypass technical defenses, with victims now eligible for up to $50,000 in compensation.

Read more
The Psychology of a Breach: How Human Error Creates Cybersecurity Risk
HUMAN-CENTERED SECURITYMARCH 2, 2025

The Psychology of a Breach: How Human Error Creates Cybersecurity Risk

Hackers target psychology, not just systems. Discover how behavioral science transforms security training for better results.

Read more
Bringing Technology to an Organic Problem
AI & INNOVATIONFEBRUARY 14, 2025

Bringing Technology to an Organic Problem

AI can detect patterns in social engineering attacks that humans miss. Learn how this partnership strengthens your cybersecurity defenses.

Read more