The GDPR treats health data as a special category. What it asks of the people in a healthcare organization and what to prove in an audit.
Las últimas noticias y novedades en el ámbito de la ciberseguridad, consejos para CISOs sobre programas efectivos de concienciación.
The GDPR treats health data as a special category. What it asks of the people in a healthcare organization and what to prove in an audit.
On audit day your spreadsheet shows all green, but the auditor asks four questions a percentage can’t answer. What they are and why the Excel falls short.
Learning from mistakes in cybersecurity, like in a video game, trains a reflex a security quiz never builds. Why safe practice changes behavior.
How an automatic SSO integration works in a security awareness platform: the end-to-end SAML authentication flow, and how it differs from provisioning.
The annual training is forgotten before it’s needed. Why microlearning, in short and continuous pieces, changes behavior where the long course never reaches.
Your compliance percentage measures completed courses, not how many people should have been trained. Why 100% can hide half your organization.
Human error is not a single thing. Telling error, negligence and intent apart changes how you reduce human risk in cybersecurity.
Control 6.3 of ISO 27001:2022 turns awareness into an auditable control. What it requires, what changed since 2013, and how you prove it in an audit.