惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

P
Proofpoint News Feed
博客园_首页
爱范儿
爱范儿
博客园 - 三生石上(FineUI控件)
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
量子位
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
IT之家
IT之家
人人都是产品经理
人人都是产品经理
T
Troy Hunt's Blog
H
Hacker News: Front Page
N
News and Events Feed by Topic
N
News | PayPal Newsroom
www.infosecurity-magazine.com
www.infosecurity-magazine.com
PCI Perspectives
PCI Perspectives
有赞技术团队
有赞技术团队
Google Online Security Blog
Google Online Security Blog
博客园 - 【当耐特】
Schneier on Security
Schneier on Security
S
SegmentFault 最新的问题
博客园 - Franky
T
The Blog of Author Tim Ferriss
罗磊的独立博客
T
The Exploit Database - CXSecurity.com
I
Intezer
Microsoft Security Blog
Microsoft Security Blog
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
B
Blog
L
Lohrmann on Cybersecurity
T
Threat Research - Cisco Blogs
U
Unit 42
Forbes - Security
Forbes - Security
MyScale Blog
MyScale Blog
J
Java Code Geeks
S
Secure Thoughts
G
Google Developers Blog
SecWiki News
SecWiki News
T
Tailwind CSS Blog
T
Tor Project blog
P
Proofpoint News Feed
D
Darknet – Hacking Tools, Hacker News & Cyber Security
Hacker News: Ask HN
Hacker News: Ask HN
P
Privacy International News Feed
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
雷峰网
雷峰网
美团技术团队
T
Threatpost
小众软件
小众软件
W
WeLiveSecurity

Human Risk Management Blog

Trust, Verify, Protect: Modernizing Email Security for the Cloud Report: Social Engineering Remains a Central Part of AI-assisted Attacks ClickFix Social Engineering is Now the Leading Malware Delivery Method CyberheistNews Vol 16 #28 Your 2026 Phishing by Industry Benchmarks: The Findings on Human Risk Scammers Can Use AI Tools to Pinpoint Your Location Based on a Photo Report: Attackers Are Using AI to Automate Social Engineering Your KnowBe4 Fresh Compliance Plus Content Updates from June 2026 From Awareness to Digital Workforce Security Your KnowBe4 Fresh Content Updates from June 2026 Threat Actor Uses Phishing to Breach Orgs for Ransomware Gangs Invoice Phishing Attacks Are Abusing the Shop App Phishing Campaign Impersonates Interpol to Deliver Ransomware Prompt Injection and the Rise of Agentic Risk Hyper-Targeted Social Engineering Needs Real-Time Video Response Your Email is Protected. Is Your Teams Chat? CyberheistNews Vol 16 #27 [HOW TO] Your Cybersecurity Starts at Home on World Social Media Day 2026 Phishing by Industry Benchmarking Report: Findings on Human Risk Static DLP Is Leaving You in the Dark: Why It’s Time for Intelligent, Self-Serve Outbound DLP and Misdirected Content Analysis INC Ransomware Gang Targets the Legal Sector 5 Essential Cybersecurity Defenses for Cloud Email Security Cybercriminals Are Targeting the FIFA World Cup 2026 Why Bite-Sized Security Awareness Training Matters in an Age of TikTok and Digital Distraction Happy 3rd Birthday to Our KnowBe4 Community! Phishing Exposes Employee Data at 86% of Fortune 100 Companies Shadow AI Is Not Shadow IT With a Better Marketing Budget CyberheistNews Vol 16 #26 A New Extortion Scam Uses IT Impersonation to Breach Organizations Cybersecurity Starts At Home This World Social Media Day FTC Report: Americans Lost $3.5 Billion to Imposter Scams Last Year Report: Device Code Phishing is Surging Report: Online Shoppers Increasingly Ignore Scam Warning Signs Turn Account Takeover Into Real-Time Security Coaching Extortion Gang Sends In-Person Attackers to Exfiltrate Data Attackers aren’t loyal to any collaboration channel CyberheistNews Vol 16 #25 [The AI Tell] How To Expose Machine-Written Phishing Fast Social Engineering Attacks Abuse Workplace Collaboration Tools New Extortion Brand Uses IT Impersonation to Breach Organizations APWG Report: Social Media Phishing is Surging Cybersecurity Awareness Training for AI: Key Focus Areas Americans Lost $900 Million to AI-Powered Scams Last Year What AI Can’t Hide When It Writes a Phishing Email Your AI Agents Are Eager to Please And Easy to Exploit From 1% to 26%: How AIDA Orchestration Fixes the Remedial Training Gap Best AI Agent Security Tools for SMB and Enterprise in 2026 4 Hot Summer Travel Tips To Avoid Scams CyberheistNews Vol 16 #24 [FBI Alert] Lock Down Your Microsoft 365 Device Code Flows Now The Role of Agentic AI in Phishing Security Training A Credit Score for Cyber Behavior Agentic AI Security in 2026: What to Know How to Secure AI Agents: 4 Best Practices An Overview of Email Compliance Regulations and Reporting Report: AI-Assisted Fraud is Surging Attackers Use Spoofed ChatGPT Site to Deliver Malware I Love Device-Bound Session Credentials, But They Are Still Phishable and Hackable Nearly Two-Thirds of CEOs Cite Cyberattacks as Their Top Concern A Look at Spam vs. Phishing: 4 Key Differences KnowBe4 Wins Multiple 2026 TrustRadius Top Rated Awards Cyber Insurance for Mid‑Market Organizations in Southeast Asia KnowBe4 Earns Multiple 2026 Buyer's Choice Awards from TrustRadius The New Frontier: Securing Japan’s Hybrid Digital Workforce (2026 & Beyond) CyberheistNews Vol 16 #23 Now Phishing Attacks Use Real Hotel Reservations to Target Travelers Report: AI-Enabled Social Engineering Attacks Are on the Rise Your KnowBe4 Fresh Compliance Plus Content Updates from May 2026 FBI: Kali365 Phishing Kit is Targeting Microsoft 365 Accounts KB4-CON - AI Is Everything How to Secure AI Adoption In Your Organization Your KnowBe4 Fresh Content Updates from May 2026 The Silent Invitation: A Deep Dive into Calendar Invite Phishing Cyber Insurance for Mid‑Market Organizations in Southeast Asia Chinese-Language Phishing Kits Are Growing More Advanced Phishing Attacks Are Using Real Hotel Reservation Info to Target Travelers Warning: Scammers are Exploiting Geopolitical Unrest Athletes Are Increasingly Targeted by Social Engineering Attacks AI Agent Governance Part 3 - Runtime Governance: The Hidden Performance Cost of Agentic AI AI Agent Governance Part 2 - What Good Looks Like: Governing AI Agents in Practice 8 Ways to Reduce False Positives in Email Security Ransomware Attacks Drive a Surge in Cyber Insurance Claims My Favorite 5 KnowBe4 Agents Perry Carpenter KB4-CON 2026 Q&A: Deepfakes & Deception Free Gift Fallacy: How Attackers Harvest Credit Cards via Fake Surveys When Global Conflict Becomes a Cyber Weapon: How Iran Tensions and Other Stressful Events Fuel Social Engineering Attacks CyberheistNews Vol 16 #21 [Heads Up] GitHub Breach Shows Developer Tools Are Social Engineering Targets Alert: Extortion Groups Are Using Phishing Kits to Automate Their Attacks Beyond the Chatbot: Why Your AI Agents are Your Newest (and Most Vulnerable) Colleagues Report: Adversarial Use of AI is Evolving
Security Training Needs Google Maps, Not Christopher Columbus
Javvad Malik · 2026-06-25 · via Human Risk Management Blog

Javvad MalikIf you’re around my age, then you know the joy of using an old paper map. Not real joy, obviously. More the sort of joy normally associated with trying to keep track of 3 pages, getting told off for not holding it the right way up, or for giving instructions too late, and discovering that the road you were confidently following was replaced by a retail park sometime during the Blair years.

A paper map is only useful for as long as the world stays still. The moment roads change, roundabouts vanish, diversions appear, or somebody decides to turn half the town into a one-way system designed by a sadist, that map becomes less a guide and more a historical artefact. Lovely if you are Christopher Columbus. Less useful if you are trying to get to Leeds for a 10am meeting.

That, in essence, is how most security awareness training still works; like a paper map. Printed at a moment in time and handed out at scale. The content may well be fine. The design may be polished. But none of that changes the basic problem. It is static. The threat landscape is not.

Threats do not stand politely still while your annual training cycle catches up. Attackers change tactics constantly because they are trying to succeed, not preserve the integrity of your procurement process. Phishing lures are now shaped by AI, tuned to context, tailored to the individual, and adjusted faster than most organisations can update a slide deck. By the time next year’s awareness module rolls round, the threat it was designed to address has already had several costume changes and a passport renewal.

It’s also worth bearing in mind that people change too, not just the threats. The person who looked low risk six months ago may now be drowning in a new role, dealing with unfamiliar suppliers, handling pressure they did not have before, and are is rushed Friday away from making a regrettable decision. A static programme cannot see that. It cannot reroute. It cannot say there is trouble ahead, avoid this road, try this instead. It just sits there, insisting this field used to be the A41.

This is why custom training needs to look like something much closer to Google Maps. It needs to be responsive and personal. Aware of what is happening now, not what was true when the training content was commissioned and everyone still thought fax machines had a future. If there is a pile-up ahead, it should know. If one route is riskier than another, it should adjust. If someone is driving, cycling, walking, or taking public transport, they should understand that different people need different guidance depending on the context they are in.

Security awareness should work the same way. The new joiner does not need the same intervention as the finance director. The person who just failed a sophisticated phishing simulation does not need a generic reminder that phishing exists, in the same way a driver stuck behind a motorway collision does not need a note explaining that roads can sometimes be busy. They need timely guidance, based on what is happening around them, that helps them make a better decision at that moment.

That is what dynamic training does. It meets people where they are. It takes account of behaviour, context, pressure, patterns, and changes over time. It understands that behaviour change is not achieved by showing everyone the same video once a year and hoping muscle memory somehow forms out of corporate obligation.

Google Maps is also useful because it lets people contribute back. Spot an accident, a speed trap, a closed lane, and you can report it so others benefit. Security culture should have the same quality. If an employee spots something suspicious, reporting it should be easy, encouraged, and actually useful to everyone else. A phish alert button is not just a feature. It is your equivalent of warning the drivers behind you that there is a flaming bin lorry overturned in lane two. Shared visibility matters.

Then there is personalisation. Avoid toll roads. Avoid motorways. Take public transport. Walk instead. The route changes depending on what is sensible for you. Security training should be no different. Some users need more help. Some need less. Some are repeatedly targeted. Some are consistently resilient. Some need coaching at the moment. Some need reinforcement over time. Treating all of them the same is like telling a cyclist and an HGV driver to follow the identical route and then acting surprised when somebody ends up in a canal.

A decent security awareness programme should not behave like a souvenir map from the age of sail. It should behave like a living navigation system. It should reflect current threats, current users, current pressures, and current behaviours. It should help people avoid danger before they fall into it. It should learn. It should adapt. It should reroute.

Because if your training cannot tell the difference between the road as it was and the road as it is, then it is not guiding anyone anywhere. It is just nostalgia with branding.

Javvad Malik is Lead CISO Advisor at KnowBe4 and thinks a once-a-year training module is fine, provided your attackers also agree to only evolve annually.