Blog
Perspectives on human
risk and realistic practice
Articles for leaders building adaptive human risk programs, not checking a compliance box.

How to Make Cybersecurity Awareness Month Last All Year
Most of October's awareness push has worn off by spring. What the research says about training that fades, and a plan for using this month to build security habits that last.

Open Enrollment Season Is Phishing Season
From benefits deadlines to bonus letters and W-2 requests, Q4 hands attackers a calendar of emails employees already expect. The HR lures to watch for and how to get your team through the season.

ClickFix: The Attack That Talks You Into Hacking Yourself
Fake CAPTCHA pages are tricking people into pasting malware commands into their own machines. ClickFix attacks surged over 500 percent and now appear in nearly half of initial-access incidents.

Social Engineering Is Coming for Law Firms, Big and Small
Privileged communications, deal files, and client escrow accounts make law firms irresistible targets. The FBI says one criminal group has focused on law firms since 2023, and it goes after the people, not the perimeter.

Protecting Accounting Firms from Social Engineering
Tax returns, Social Security numbers, and client financials make accounting firms prime targets. Attackers are going after the people, not the firewalls, and protection needs to reach the moment of decision.

Hackers Are Calling Employees and Walking Them Into the Attack
Voice phishing and fake IT support are often only the setup. The decisive step is usually the credential entry, MFA approval, download, or installation that follows.

What Should Happen After an Employee Fails a Phishing Simulation?
A failed phishing simulation should not be the end of the exercise. It is a behavioral signal that should drive immediate reinforcement, matching remediation, and a smarter next test.

How Often Should You Run Phishing Simulations?
Monthly or quarterly testing is common, but frequency alone does not make a program effective. The better question is whether simulations adapt to the employee and the threat.

AI Phishing Attacks: The Trends We Are Seeing in 2026
Phishing volume is down, click rates are up, and the attack toolkit now sells for the price of a laptop bag. What the industry data says about where AI phishing is heading.

America's Water Utilities Are Under Attack: Why the Human Layer Remains the Most Accessible Target
A coordinated cyberattack just disrupted water systems in at least a dozen states. Critical infrastructure is now a prime target, and the people who run it remain the easiest way in.

Phishing Doesn’t End at the Inbox: Why Human Risk Protection Must Extend Into the Browser
Phishing attacks often become dangerous after an employee clicks. Learn why human risk protection must extend into the browser and reach the point of decision.

Stop Trying to Make Your Employees Care About Cybersecurity
One of the most common misconceptions in cybersecurity is that getting employees to care more is what reduces risk.

Shame Doesn't Teach: How the Cybersecurity Training Industry Gets It Wrong
Punitive security training creates fear and silence. Learn why positive reinforcement builds stronger defenses than shame-based approaches.

What We Can Learn from MGM's Breach
The 2023 MGM cyberattack shows how vishing tactics can bypass technical defenses, with victims now eligible for up to $50,000 in compensation.

The Psychology of a Breach: How Human Error Creates Cybersecurity Risk
Hackers target psychology, not just systems. Discover how behavioral science transforms security training for better results.

Bringing Technology to an Organic Problem
AI can detect patterns in social engineering attacks that humans miss. Learn how this partnership strengthens your cybersecurity defenses.
