Skip to content

Blog

Research, guides and category thinking on Behavioral Defense.

phishingHow Often and How Fast Should I Phish My Colleagues in 2026?

How many phishing simulations to run and how often users should face cybersecurity eLearning is a recurring question in awareness programs – and far from academic. A sensitization effect begins to crumble after about three months, yet it would be dangerous to derive simple, universally applicable rules from that.

comparisonWhat CUSTOMERS DO WRONG when starting Cybersecurity Awareness Programs

Like any other project, a cybersecurity awareness program can get off to a very bumpy start when it begins with an inappropriate mindset and management fails to recognize the value of awareness. We examined the mistakes and false expectations documented in a USENIX study and compared them with our own experience.

aiCan AI Detect Malicious Intent in an Email?

Phishing emails are becoming harder to detect, even for humans. A recent study tested various large language models (LLMs) for their ability to recognize malicious intent in emails and revealed significant differences in performance.

comparisonRisk Attitude vs Risk Behavior: Are You Training the Wrong Thing?

Despite comprehensive security awareness training, many organizations still have cybersecurity breaches resulting from human error. This article is about the gap between risk attitude (knowing what is risky) and risk behavior (actually acting securely).

researchWhat the 2025 IBM Data Breach Report Really Says?

The IBM Cost of a Data Breach Report has been published every year for two decades. It’s often read for the numbers, but this year’s report says something more fundamental about cybersecurity awareness.