Failure rates in phishing simulations range from 1.8% to 30.8% depending on the lure. So what does a repeat-clicker list measure, and what can you do with it?
Failure rates in phishing simulations range from 1.8% to 30.8% depending on the lure. So what does a repeat-clicker list measure, and what can you do with it?
Self-efficacy predicts secure behavior better than knowledge does, and no awareness dashboard tracks it. What the evidence says and what a program can decide.
The clues for spotting a scam expire with the technology that produced them. STEEL://CODE is a cybersecurity manga built on the attack technique.
Automation bias shows up when an AI layer rules on an email before the person does. What the evidence shows and which programme decisions change.
A habit fires on a context cue rather than on the intention of the moment. Which behaviours can become habits, and when it pays to intervene.
Normalization of deviance explains why an unsafe practice becomes the team’s norm, and why punishing the case leaves that norm untouched.
What security fatigue is, why habituation makes response to security warnings decline, and how to redesign an awareness program once it shows up.
Passing a security quiz doesn’t measure behavior. What a validation question actually measures, what it can measure, and what a CISO should report.