Apr 2026 · Interactive

True or false? The cybersecurity quiz your team will actually want to take.

8 statements. Half of them are myths. Small businesses aren't targeted. Phishing emails have obvious tells. Security training changes behaviour. All false — and the stats to prove it.

Apr 2026 · 8 min read

Warning fatigue: why more security alerts are making your organisation less safe.

4,484 alerts per SOC analyst per day. 45% false positives. Employees dismissing warnings in under 2 seconds. The volume approach to security isn't working — and we've known for years. Here's what actually changes behaviour.

Apr 2026 · 3 min read

11,000 fake government portals. Your employees can't tell them from the real ones.

CTM360's GovTrap research exposed a global fraud campaign running over 11,000 cloned government sites. The attack works not because people are careless — but because the portals are indistinguishable from the real thing.

Apr 2026 · 3 min read

Business email compromise doesn't exploit careless employees. It exploits competent ones.

BEC is the world's highest-grossing cybercrime — and AI has made the attacks indistinguishable from legitimate communication. The problem isn't awareness. The fix isn't more training.

Apr 2026 · 2 min read

Stop telling people something is unsafe. Tell them why.

Generic security warnings produce banner blindness — and decades of research explain why. What changes when a warning tells you the specific reason something is risky, not just that it is.

Apr 2026 · 2 min read

68% of breaches don't start with a hack. They start with a conversation.

Most expensive breaches don't begin with code — they begin with someone making a reasonable decision under conditions designed to defeat them. What organisations should actually be measuring instead of training completion rates.

Apr 2026 · 2 min read

Phishing grew up. Most defences are still fighting the last war.

Modern phishing is precise, personalised, multi-channel, and engineered to fool careful people — not careless ones. The mental model most organisations defend against is now a liability.

Apr 2026 · 2 min read

Security awareness training doesn't change behaviour. So why is it still our primary defence?

Human risk management has been quietly redefined to mean "training plus simulations." That's proxy measurement — and it's measuring the wrong things. What a broader, more honest definition looks like.

No posts match that search. Try a different keyword.