Cybersecurity, Privacy, & AI

Trending Now
Weaponized Email AI Assistants Could Help Attackers Hijack Accounts • CISA Guidance Targets Water Sector Security, Open Source AI and More • Salesforce Previews Plans to Deliver Newly Authorized ‘AI Agents’ Across DOD • CMS Pivots to Risk-Based Cybersecurity Model, CISO Says • Senate Set to Debate Package of Bills on Privacy, AI and Kids Safety

Why I Changed My Mind about Federal User Cyber Training

FOTO SALE | Shutterstock

John Breeden II, a long-time skeptic of the mandatory workplace cybersecurity training he has received, now believes his criticism has been misplaced. Incidents showing the ineffectiveness of such training don’t indicate that users are “stupid” and untrainable, he argues; the real problem is the nature of the training, which typically lacks the kind of interactivity and individual adaptation that would make it effective.

Furthermore, user training remains a necessary part of a layered protection system. “Even the best mail security programs and appliances I’ve ever tested were only about 99% accurate, and those were the cream of the crop. … If only 1% of those threats are running the gauntlet, that’s 180,000 bad emails getting delivered each day.” For example, he notes the irony that users at highly protected organizations come to let their guard down, becoming more likely to fall for any rare well-crafted phishing attempt that they encounter.

Stay compliant and protected with daily updates on cybersecurity, data privacy, and federal oversight with our Cyber & Privacy newsletter, delivering up-to-the-minute intelligence Monday–Saturday — Subscribe here.