Human Risk Management Blog

Keeping you informed. Keeping you aware.
Stay on top of the latest in security including social engineering, ransomware and phishing attacks.

Security in Three Keynotes

I had the pleasure of attending (ISC)2 Congress this year in Orlando with my colleague and fellow advocate James McQuiggan.

You Need To Start Thinking Differently About This Whole "Insider Threat" Concept

In order to defend against insider threats, you need an accurate picture of the problem. The CyberWire’s Carole Theriault spoke to a number of industry experts about insider threats and ...

Ransomware Attack Blocks Hundreds Of Law Firms From Their Trial Records

I could not come up with a better scenario to get sued by a pack of angry lawyers. Reams of digital legal documents have been held hostage under a ransomware threat to TrialWorks, a ...

Healthcare Industry Names KnowBe4 As The 2019 Top Rated Platform For Cybersecurity Training & Education

Black Book Market Research LLC surveyed over 2,876 security professionals from 733 provider organizations to identify gaps, vulnerabilities and deficiencies that persist in keeping ...

American Nikkei Employee Falls For Social Engineering Scam And Loses 29 Million Dollars

Phil Muncaster at InfoSec Mag had the (painful) scoop: "Media giant Nikkei has become the latest firm to suffer a humiliating Business Email Compromise (BEC), after it admitted losing ...

A Transformational Rant: Why People Question the Value of Security Awareness

In my last post, I spent a bit of time discussing the “technology vs. training” debate; and based on the feedback received, I can tell that this is a debate that many of you have had to ...

Phishing Kits Hosted on More than Six Thousand Domains

Akamai’s 2019 State of the Internet / Security Report found that 6,035 domains were being used to host 120 different phishing kits, according to BleepingComputer. The phishing kits ...

[Heads Up] Scam Of The Week: Phishing Attacks Using Better Benefits And Pay Raise Bait

Millions of employees use KnowBe4's Phish Alert Button to report suspect emails, and thousands of organizations share these reports with us. This has become a fascinating threat source, ...

KnowBe4 Fresh Content & Features Updates - October 2019

Check out the content and feature updates in the KnowBe4 platform for the month of October!

Webroot Threat Researchers Take a Fresh Look at Phishing Tactics

Most people aren’t aware of how sophisticated phishing email templates and websites have become, according to David Dufour from Webroot. Dufour recently told the CyberWire that criminals ...

SAVE THE DATE!! KnowBe4 User Conference - April 15-17, 2020

KnowBe4’s third annual KB4-Con user conference will be held at the Gaylord Palms Resort & Convention Center in Orlando, FL. KnowBe4 customers get twofree event passes per ...

KnowBe4 Achieves FedRAMP Authorization from the US Federal Government

On October 25, 2019, KnowBe4 became the first and only security awareness training and simulated phishing provider to receive FedRAMP authorized status. We are very proud of this ...

Captain Awareness Has A Halloween Message For You

Think Before You Click!

It's Benefits Enrollment Season Again...And That Means Prime Phishing Season!

By Eric Howes, KnowBe4 Principal Lab Researcher. Not content just to make tax season even more miserable than it already is, malicious actors are increasingly maneuvering to capitalize on ...

[Heads-Up] North Korean Malware Found On Indian Nuclear Plant's Network

I am not a happy camper. This is exactly why I have been insisting on security awareness training for employees at critical infrastructure organizations. This could have been a Real Life ...

Lessons Learned From Vishing Robocall Attacks In Mandarin

Among the specialized forms of vishing are those that target specific language communities. Chinese-speaking people in the US and around the world are increasingly being targeted with ...

Ransomware Attack Causes School 'District-Wide Shutdown'

A ransomware attack hitting Las Cruces Public Schools forced the district to shut down the entire computer system to contain the infection.

Vishing, from (not) the Bank

We saw yesterday how phishing affects the financial sector. Here we see another, related trend: impersonation attacks that purport to be from the victim’s bank.


Get the latest insights, trends and security news. Subscribe to CyberheistNews.