惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

博客园_首页
B
Blog
V
V2EX
T
Tailwind CSS Blog
Hugging Face - Blog
Hugging Face - Blog
博客园 - 【当耐特】
博客园 - 聂微东
博客园 - 叶小钗
博客园 - 三生石上(FineUI控件)
The Cloudflare Blog
J
Java Code Geeks
H
Help Net Security
雷峰网
雷峰网
Apple Machine Learning Research
Apple Machine Learning Research
H
Hackread – Cybersecurity News, Data Breaches, AI and More
Engineering at Meta
Engineering at Meta
F
Fortinet All Blogs
Martin Fowler
Martin Fowler
D
Docker
L
LangChain Blog
人人都是产品经理
人人都是产品经理
爱范儿
爱范儿
WordPress大学
WordPress大学
V
Visual Studio Blog

Human Risk Management Blog

Future-Proofing Organizations in the Face of AI What Security Can Learn From Dinosaurs Inside the OS-Aware Phishing Kit Profiling Your Device CyberheistNews Vol 16 #30 [Protect Your Users] AI Hallucinations Are Fueling Phishing Attacks Majority of Organizations Hit by Targeted Impersonation Attacks The Open-Source Paradox: Navigating the New Frontier of AI Supply Chain Risk Introducing The Hybrid Nudge Experience: Outbound Email Security Built for Your Risk Appetite Elevating the SOC Experience: Smarter Automation, Richer Threat Intelligence, and AI-Native Investigation New Phishing Tools Enable Attackers to Easily Bypass Multifactor Authentication From Inbox to Encryption: How Ransomware Delivery Has Evolved Attackers Exploit AI Hallucinations to Send Users to Phishing Sites Warning: ARToken Phishing Kit Automates BEC Attacks The New Face of AI Risk Trust Nothing: Tips to Secure AI Tools and Agents CyberheistNews Vol 16 #29 ClickFix Social Engineering is Now the Leading Malware Delivery Method Beyond the Checkbox: How a Proactive Partnership Led to Turnkey Hazing Compliance Trust, Verify, Protect: Modernizing Email Security for the Cloud Report: Social Engineering Remains a Central Part of AI-assisted Attacks ClickFix Social Engineering is Now the Leading Malware Delivery Method CyberheistNews Vol 16 #28 Your 2026 Phishing by Industry Benchmarks: The Findings on Human Risk Scammers Can Use AI Tools to Pinpoint Your Location Based on a Photo Report: Attackers Are Using AI to Automate Social Engineering Your KnowBe4 Fresh Compliance Plus Content Updates from June 2026 From Awareness to Digital Workforce Security Your KnowBe4 Fresh Content Updates from June 2026 Threat Actor Uses Phishing to Breach Orgs for Ransomware Gangs Invoice Phishing Attacks Are Abusing the Shop App Phishing Campaign Impersonates Interpol to Deliver Ransomware Prompt Injection and the Rise of Agentic Risk Hyper-Targeted Social Engineering Needs Real-Time Video Response
Security Training Needs Google Maps, Not Christopher Colu...
Javvad Malik · 2026-06-25 · via Human Risk Management Blog

Javvad MalikIf you’re around my age, then you know the joy of using an old paper map. Not real joy, obviously. More the sort of joy normally associated with trying to keep track of 3 pages, getting told off for not holding it the right way up, or for giving instructions too late, and discovering that the road you were confidently following was replaced by a retail park sometime during the Blair years.

A paper map is only useful for as long as the world stays still. The moment roads change, roundabouts vanish, diversions appear, or somebody decides to turn half the town into a one-way system designed by a sadist, that map becomes less a guide and more a historical artefact. Lovely if you are Christopher Columbus. Less useful if you are trying to get to Leeds for a 10am meeting.

That, in essence, is how most security awareness training still works; like a paper map. Printed at a moment in time and handed out at scale. The content may well be fine. The design may be polished. But none of that changes the basic problem. It is static. The threat landscape is not.

Threats do not stand politely still while your annual training cycle catches up. Attackers change tactics constantly because they are trying to succeed, not preserve the integrity of your procurement process. Phishing lures are now shaped by AI, tuned to context, tailored to the individual, and adjusted faster than most organisations can update a slide deck. By the time next year’s awareness module rolls round, the threat it was designed to address has already had several costume changes and a passport renewal.

It’s also worth bearing in mind that people change too, not just the threats. The person who looked low risk six months ago may now be drowning in a new role, dealing with unfamiliar suppliers, handling pressure they did not have before, and are is rushed Friday away from making a regrettable decision. A static programme cannot see that. It cannot reroute. It cannot say there is trouble ahead, avoid this road, try this instead. It just sits there, insisting this field used to be the A41.

This is why custom training needs to look like something much closer to Google Maps. It needs to be responsive and personal. Aware of what is happening now, not what was true when the training content was commissioned and everyone still thought fax machines had a future. If there is a pile-up ahead, it should know. If one route is riskier than another, it should adjust. If someone is driving, cycling, walking, or taking public transport, they should understand that different people need different guidance depending on the context they are in.

Security awareness should work the same way. The new joiner does not need the same intervention as the finance director. The person who just failed a sophisticated phishing simulation does not need a generic reminder that phishing exists, in the same way a driver stuck behind a motorway collision does not need a note explaining that roads can sometimes be busy. They need timely guidance, based on what is happening around them, that helps them make a better decision at that moment.

That is what dynamic training does. It meets people where they are. It takes account of behaviour, context, pressure, patterns, and changes over time. It understands that behaviour change is not achieved by showing everyone the same video once a year and hoping muscle memory somehow forms out of corporate obligation.

Google Maps is also useful because it lets people contribute back. Spot an accident, a speed trap, a closed lane, and you can report it so others benefit. Security culture should have the same quality. If an employee spots something suspicious, reporting it should be easy, encouraged, and actually useful to everyone else. A phish alert button is not just a feature. It is your equivalent of warning the drivers behind you that there is a flaming bin lorry overturned in lane two. Shared visibility matters.

Then there is personalisation. Avoid toll roads. Avoid motorways. Take public transport. Walk instead. The route changes depending on what is sensible for you. Security training should be no different. Some users need more help. Some need less. Some are repeatedly targeted. Some are consistently resilient. Some need coaching at the moment. Some need reinforcement over time. Treating all of them the same is like telling a cyclist and an HGV driver to follow the identical route and then acting surprised when somebody ends up in a canal.

A decent security awareness programme should not behave like a souvenir map from the age of sail. It should behave like a living navigation system. It should reflect current threats, current users, current pressures, and current behaviours. It should help people avoid danger before they fall into it. It should learn. It should adapt. It should reroute.

Because if your training cannot tell the difference between the road as it was and the road as it is, then it is not guiding anyone anywhere. It is just nostalgia with branding.

Javvad Malik is Lead CISO Advisor at KnowBe4 and thinks a once-a-year training module is fine, provided your attackers also agree to only evolve annually.