Human Risk Management Blog

Keeping you informed. Keeping you aware.
Stay on top of the latest in security including social engineering, ransomware and phishing attacks.

Cyber Security is About Culture and People, not Technology

Security isn’t just IT’s problem, but everyone’s problem within the organization. The key isn’t “yet another security solution”, but a changing of the way the organization thinks about ...

ISACA Recommends Phishing Simulations and Measurement as Appropriate Defense to Reduce Risk of Successful Phishing Attacks

Organizations are working to limit the effectiveness of phishing attacks using both internal and external collateral and programs. According to ISACA, the important thing is to have ...

Mobile Devices Rise as a Top Attack Vector for Cybercriminals; Malware and Phishing Remain Primary Concerns

Cybercriminals are using every means available to reach their victims. According to Verizon’s latest data, attacks on mobile devices are increasing while security efforts fall behind.

90% of large tech companies vulnerable to email spoofing

Most companies have not implemented standards for authenticating emails and preventing hackers from successful phishing attacks, according to Valimail.

Which Employees are the Cyber Criminals After?

Lower-level employees are the workers most likely to face highly-targeted attacks, according to the online marketing firm Reboot. Citing information from Proofpoint’s most recent ...

Microsoft Takes Control Of 99 Phishing Domains Operated By Iranian State Hackers

The domains had been used as part of spear-phishing campaigns aimed at users in the US and across the world. Court documents unsealed today revealed that Microsoft has been waging a ...

NotPetya act of war exclusion spreads to second insurer

A second insurer has refused to pay out over the NotPetya cyberattack based on an act of war exclusion, prompting growing concerns for businesses relying on cybersecurity insurance to ...

Cybercriminals Double-Down on What Works, Nearly Doubling the Number of Phishing Attacks in 2018

Using a combination of old and new tactics and distribution channels, cybercriminals continue to seek to compromise endpoints and obtain online credentials. The targets haven’t changed. ...

[New Comedy Series] KnowBe4's Popcorn Training Releases 8-Episode Security Awareness Videos - 'Standups 4 Security'

We’re excited to announce the release of this new security awareness video series for our customers called ‘Standups 4 Security’ from our team at Popcorn Training. In this new 8-episode ...

Insurers Creating a Consumer Ratings Service for Cybersecurity Industry

The WSJ reported on news that a Collaborative effort led by Marsh & McLennan would score the best cyber security products for reducing hacking risk, and provide potential discounts on ...

Find out which of your users' emails are exposed before the bad guys do

Do you know how big your email attack surface really is? Open Source Intelligence (OSINT) is the collection of information from public sources on the Internet that both red teams and bad ...

Phishing Attack Compromises Spanish Defense Intranet By Foreign State

Reuters reported that a "computer virus" infected the Spanish Defense Ministry’s intranet this month with the aim of stealing high tech military secrets, El País newspaper said on ...

Norsk Hydro May Have Lost $40M in First Week After Ransomware Infection

Norwegian aluminum giant Norsk Hydro estimates that it may have lost more than $40 million in the first week following the ransomware attack that disrupted its operations.

Canadian Companies See Increases in Attacks, Breaches, and Sophistication in the Last 12 Months

If you read the latest Canadian Threat Report from Carbon Black, the Canadians have it bad… really bad. With increases across the board, Canadian organizations are needing to step up ...

[NEW FEATURE] Upload Your Own Training Content

You asked, we listened! To simplify how you roll out and manage different training programs for your users, you can now use the KnowBe4 security awareness training platform for your ...

How LockerGoga, The Ransomware Crippling Industrial Firms Operates

Technically, LockerGoga is just another ransomware strain and not even a very good one. It's got bugs and it's slow. However, the gang behind it represents a dangerous combination of ...

U.S. Healthcare Employee Engagement with Simulated Phishing Emails Drop by 67% With Repeated Exposure

A long-term phishing study involving 6 healthcare institutions shows employees are vulnerable to phishing attacks, and that they can become more vigilant through exposure.

Kevin Mitnick Demos Password Hack: No Link Click or Attachments Necessary

In this shocking demonstration Kevin Mitnick, KnowBe4's Chief Hacking Officer, shows how hackers can steal a user’s password hash without the user having to click a hyperlink or open an ...

Mandatory vs. Elective Security Awareness Training

I frequently get variations of the following question: "I met with the CISO yesterday to discuss Awareness Training. He asked if KnowBe4's CEO would comment on the value of mandatory ...


Get the latest insights, trends and security news. Subscribe to CyberheistNews.