Cybersecurity Training: The Science, Challenges, and Impact

This episode of ‘Cybersecurity Today’ delves into the dynamics of cybersecurity awareness and training. Host Jim Love discusses the natural decline in vigilance over time with guests Michael Joyce, CEO of the Human-Centric Cybersecurity Partnership, and David Shipley, CEO of Beauceron Security. Key insights include the temporality of awareness, the importance of ongoing training, and the optimal frequency for phishing simulations. The conversation also critiques recent research suggesting the ineffectiveness of phishing training, highlighting the importance of context, methodology, and continuous improvement in cybersecurity practices.

Links referred to:

Note: the first link is not endorsed by us. In fact this is the paper that we criticized. We think that it is not only incorrect and sloppy research, but it actually does damage. Those are our opinions. But we will let you reach your own conclusions.

Anti-Phishing Training Does Not Work: A Large-Scale Empirical Assessment of Multi-Modal Training Grounded in the NIST Phish Scale

Exploring the evidence for email phishing training: A scoping review

Show Timeline

00:00 Understanding Human Vigilance and Awareness Decay
00:33 Introduction to Cybersecurity Today
00:46 Meet the Experts: Michael Joyce and David Shipley
01:39 Exploring the Human-Centric Cybersecurity Partnership
03:38 The Role of Liberal Arts in Cybersecurity
04:23 Challenges in Cybersecurity Culture and Behavior
06:37 David Shipley’s Research and Insights
09:07 Michael Joyce on Academic vs. Corporate Research
13:20 Impact of Cybersecurity Awareness Month
18:32 Phishing Simulations and Security Fatigue
21:34 The Importance of Reporting and Feedback Loops
23:14 Analyzing Awareness Decay and Vigilance
39:38 Experimenting with Phishing Training Frequency
39:51 Critiques and Insights on Cybersecurity Training
41:51 Optimal Training Intervals and Their Impact
43:23 The Role of Awareness in Cybersecurity
44:13 Understanding Phishing Reporting and Skills Decay
45:22 Ethical Considerations in Phishing Simulations
46:38 New Data on Why People Click Phishing Links
55:52 The Importance of Psychological Safety
57:23 Debunking Misleading Headlines on Phishing Training
01:05:44 Challenges in Cybersecurity Research
01:16:41 Final Thoughts and Recommendations

Related Podcasts

Jim Love

Jim is an author and podcast host with over 40 years in technology.

Share:
Facebook
Twitter
LinkedIn