Security Awareness Training Blog

Keeping You Informed. Keeping You Aware.
Stay on top of the latest in security including social engineering, ransomware and phishing attacks.

Stu Sjouwerman

Chief Executive Officer & President

Stu Sjouwerman (pronounced “shower-man”) is the founder and CEO of KnowBe4, Inc., which hosts the world’s most popular integrated security awareness training and simulated phishing platform, with over 54,000 organization customers and more than 50 million users. A serial entrepreneur and data security expert with 30 years in the IT industry, Stu was the co-founder of Inc. 500 company Sunbelt Software, a multiple award-winning anti-malware software company that was acquired in 2010.


Recent Posts

Basic training in avoiding phishing is no longer sufficient

Databreaches.net has forums and one of their posts really got our attention. It was an official notification from the legal department of Boise Cascade Company in Utah about a phishing ...
Continue Reading

This ransomware asks victims to name their own price to get their files back

Attackers behind this form of file-encrypting malware - which has similarities with Locky - think that if the victim can set their own price, they're more likely to pay. A form of ...
Continue Reading

48 Servers Of North Carolina County Held Hostage by LockCrypt Ransomware

A hacker’s 1 p.m. deadline to pay $23,000 passed Wednesday, and Mecklenburg County has not decided whether to pay the ransom for a cyber-attack that “paralyzed” the county. County manager ...
Continue Reading

Cyber Warfare in 140 Characters: Social Media Weaponized

David Patriakos's new book about cyber warfare is a fascinating read. From the back cover: "Modern warfare is a war of narratives, where bullets are fired both physically and virtually. ...
Continue Reading

KnowBe4 Prevents Customer From Becoming Social Engineering Victim Of Duke Energy Vendor’s Hack

A customer just sent us this: "Stu, the company who processes payments for Duke Energy’s walk in payments was hacked and as a result about 375,000 bank accounts may have been stolen. "We ...
Continue Reading

Which of Your Employees Are Most Likely to Expose Your Company to a Cyber Attack?

Kon Leong at Harvard Business Review wrote an excellent article about the problem of employees exposing your organization to cyberthreats through human error. Here is a short qoute:
Continue Reading

Phishing Schemes Are Using Encrypted Sites To Seem Legit

WIRED wrote: "A MASSIVE EFFORT to encrypt web traffic over the last few years has made green padlocks and "https" addresses increasingly common; more than half the web now uses internet ...
Continue Reading

Mailsploit Bypasses DMARC And Lets Attackers Send Spoofed Phishing Emails on Over 33 Email Clients

Our friends at Bleepingcomputer reported on something that should cause anyone concern. German security researcher Sabri Haddouche has discovered a set of vulnerabilities that he ...
Continue Reading

KnowBe4 Wins Frost & Sullivan Cyber Security Awareness Training Platform Customer Value Leadership Award

I'm extremely pleased to tell you we have won a prestigious award. Frost & Sullivan is a global research and consulting firm and they recently announced that we received their 2017 ...
Continue Reading

Scam Of The Week: Phishers Target PayPal Users With Fake “Failed Transaction” Emails

Scammers are pushing out fake PayPal emails that use the premise of an unverified transaction to phish for customers’ personal and financial information. With the end-of-the-year holidays ...
Continue Reading

Your Cybercrime Insurance Policy May Not Cover You For Social Engineering Fraud

I have talked about this potentially extremely expensive and very disappointing "CEO fraud" or "Business Email Compromise" problem many times before. Your cybercrime policy may not ...
Continue Reading

Phishing campaigns and malware infections are both up more than 40% since Q2 ‘17

The NTT Security Global Threat Intelligence Center (GTIC) 2017 Q3 Threat Intelligence Report provides a glimpse inside the research conducted by NTT Security researchers over the last ...
Continue Reading

Google Kicks Harmful Apps Out Of Google Play And Offers 5 Steps Against Social Engineering

You're always better off getting apps from reputable stores like Google Play than you are from potentially dodgy, at best unknown, third-party sites. But even Google Play isn't immune ...
Continue Reading

If Willie Sutton were working today, he'd be stealing cryptocurrency, not wasting time on banks

Because that's where the money is. Criminals have been installing cryptocurrency miners on victim machines that turn them into sources of money. These operate without the users' ...
Continue Reading

Proposed New Legislation: "Security Awareness Training For Your Users Or Go To Jail"?

OK, it may be hyberbole, but since 91% of data breaches are caused by successful spear phishing attacks, it's not entirely crazy to say: "security awareness training your users or go to ...
Continue Reading

New CyberThreat Survey Confirms: Biggest Security Obstacle Is Low User Security Awareness

The CyberEdge Group is an award-winning research firm that serves information security vendors and service providers. They recently surveyed 1,100 qualified IT security decision makers ...
Continue Reading

UK Shipping firm Clarksons falls victim to hybrid ransomware / data theft extortion

Shipping company Clarksons has fallen victim to a major ransomware attack that could result in the exposure of private data, the company warned today. The statement continued: "Our ...
Continue Reading

77% of the FTSE 100 Have Compromised Credentials - What is your Stolen-password percentage?

IT security vendor Anomali, released a new report showing the volume of stolen credentials of FTSE 100 employees tripled In 2017, and a whopping 77% of the FTSE 100 were exposed with an ...
Continue Reading

Get the latest about social engineering

Subscribe to CyberheistNews