Security Awareness Training Blog

Security Awareness Training Blog

Read the latest news about security awareness training, best practices, why you need it, and what happens when you don't have it in place.

Your KnowBe4 Fresh Content Updates from August

With 18 new pieces of training content added this month, check out the always fresh content update highlights and new features from the month of August.
Continue Reading

When the URL Domain Is Not Enough To Avoid a Phish

One of the most common mantras in security awareness training is “Examine the URL to determine if it points to the legitimate vendor or not!”
Continue Reading

“Compromise” is the “C” in “MICE”

The FBI is warning Silicon Valley companies to be wary of insider threats, Protocol reports. FBI special agent Nick Shenkin told Protocol in an interview that authoritarian ...
Continue Reading

KnowBe4’s Automated Security Awareness Program Builder Now Available in Nine Languages

Now that the KnowBe4 Security Awareness Training and Simulated Phishing Platform is available in nine localized languages, starting your organization's security awareness training program ...
Continue Reading

Words of Advice for Organizations on Cybersecurity Best Practices

We recently attended Black Hat USA 2021 this year and Erich Kron, Security Awareness Advocate for KnowBe4, sat down with Cybersecurity Ventures to give words of advice for all ...
Continue Reading

Your KnowBe4 Fresh Content Updates from July

With 25 new pieces of training content added this month, check out the always fresh content update highlights and new features from the month of July.
Continue Reading

12 Steps to a Security Ignorance Program

Most people working for organisations have been exposed at some point in their careers to security awareness programs. Some of these programs are well-executed and delivered, while others ...
Continue Reading

79% of Employees Have Knowingly Engaged in Risky Online Activities in the Past Year

With employees not believing that it’s important to personally worry about cyber security risks, they also tend to believe they’re not a target, new data suggest as the reason for the ...
Continue Reading

Remote Employees Adopt Bad Cybersecurity Habits While Working from Home

A new report focused on businesses looking to bring employees back to the office makes it very clear that security leaders are concerned, as remote workers have been anything but secure.
Continue Reading

Microsoft Takes Down Homoglyph Domains

Microsoft has taken legal action to shut down eighteen domains that were being used in business email compromise (BEC) attacks. The sites in question used homoglyphs to impersonate ...
Continue Reading

[On-Demand Webinar] 2021 Phishing By Industry Benchmarking Report

As a security leader, you have a lot on your plate. Even as you increase your budget for sophisticated security software, your exposure to cybercrime keeps going up. IT security seems to ...
Continue Reading

KnowBe4 Fresh Content Updates from June

Here are important fresh content updates to share with you that happened in the month of June.
Continue Reading

Social Engineering and Organizational Culture

Consistent awareness training is necessary to fend off phishing attacks, according to Keatron Evans, a principal security researcher, instructor, and author with Infosec. In an interview ...
Continue Reading

Yet Another Disk Image File Format Spotted in the Wild Used to Deliver Malware

Disguised as an invoice, cybercriminals use a Windows-supported disk image to obfuscate malware from email gateways and security scanners. The question is how viable will it be?
Continue Reading

Cybersecurity and Business Priorities Don’t Appear to Be Aligning – and That’s Bad for Your Security Stance

Despite organizational leadership believing cyber security initiatives can support business goals, the way businesses approach cybersecurity seems to prove otherwise.
Continue Reading

An Unusual Attachment is Most Likely a Phishing Campaign

A phishing campaign is using Windows Imaging Format (WIM) files to deliver malware, according to researchers at Trustwave. WIM files aren’t commonly thought of as potentially malicious, ...
Continue Reading

Misconfigured Cloud Database Increases Risk of Social Engineering

DreamHost, a major website hosting provider, exposed 814 million user account records in an unsecured database, researchers at Website Planet have found. The data exposed included a ...
Continue Reading

Threat Actors use Google Ads to Target People Migrating to Encrypted Messaging Services like Signal and Telegram

Researchers at eSentire warn that threat actors have been using Google Ads to target people migrating from WhatsApp to other encrypted messaging services, particularly Signal and Telegram.
Continue Reading

60% of Orgs Needed New Security Policies to Secure Their Remote Workforce

According to security compliance vendor ThreatSwitch in their 2021 Industrial Security Benchmark Report, organizations are waking up to the need for better awareness training.
Continue Reading

KnowBe4 Makes eSecurity Planet's Best Security Awareness Training for Employees 2021 List

Security awareness training has made leaps and bounds in the last couple of years. With the old-school approach, a few bagels and long, boring powerpoint presentations can only get you so ...
Continue Reading

Get the latest about social engineering

Subscribe to CyberheistNews