Read articles about security awareness, risk management, behavior change, and more
How quishing is being used in attacks, what these threats look like in the wild and best practices for avoiding them.
Stop deepfake, smishing & vishing scams with 8 proven tactics: Feel→Slow→Verify→Act, no approvals in live calls, out-of-band callbacks, and a reporting culture.
Fantasy football can teach us how to learn stop worrying and love the art and chaos of starting a new leadership position.
Recent research published in the wall street was correct: bad phishing simulations produce bad results. So what now?
The CISO Fantasy Phish Bowl 2025 brings together some old friends and new joiners. There's one heavy absence: Shawn Bowen, to whom this year's Phish Bowl is dedicated. Here's to you, Shawn!
Phishing simulation best practices with real case results from Bird & Bird - ethical lures, instant feedback, and KPIs that drive reporting.
Best phishing simulation tools for enterprises (2025) - AI-powered, gamified platforms with multi-vector realism, SOC integrations, and risk dashboards.
Cybersecurity Awareness Month ideas that work: run a focused 10-day campaign, launch phishing simulations, boost MFA adoption, and use our 2025 toolkit.
The Human Risk Manager controls the process of identifying, evaluating, and mitigating the cybersecurity risks associated with people.
This NIS 2 Checklist gives the compliance basics for the CxO and Board of Directors to satisfy this European cybersecurity regulation.
The top 10 costs of phishing are direct, indirect, and far reaching.
Noora Ahmed-Moshe's presentation to an exclusive group of CIOs at Kocho View in London explains why building a security culture is vital to reducing human risk.
How to measure and drive behavior change that shields your organization from cyber-attacks.
In the world of cybersecurity, the unknown represents your biggest risk. A miss today is a phish tomorrow.
Repeat phishing offenders aren’t the problem... static training is. Learn how we use adaptive simulations to convert clickers into security assets.
Here's how to change the narrative around cybersecurity to get employees engaged.
How do you achieve cybersecurity behavior change? A breakdown of how science-based training transforms awareness into real-world risk reduction.
Learn how behavior-based cyber security training drives lasting employee behavior change. A breakdown of the key components, benefits, and why it’s essential for building a strong security culture.
Discover how Hoxhunt outperforms competitors in cybersecurity training. Based on real reviews, compare Hoxhunt's features, quality, and effectiveness to leading alternatives.
Empower your team to be a human firewall. Discover how training, vigilance, and smart habits protect against cyber threats.
Gift card phishing attacks use an old trick that fell by the wayside with the rise of cryptocurrency phishing attacks. It's a trick, never a treat.
As celebrities attract stalkers, so too are cryptocurrencies attracting cybercriminals. Beware of these new cryptocurrency phishing attacks!
The domain registration phishing attack has been banging around the internet for a while, but we've seen it make a big comeback lately.
Death. Taxes. And phishing attacks. We're monitoring a new tax phishing attack based on the IRS CP 2100 notice campaign claiming missing TINs.
Today we’ll take a sneak peek at the top 5 things lurking behind forbidden phishing links, so your curiosity doesn’t get the best of you!
Social media phishing campaigns use your publicly shared info against you in a spearphish attack, or get you to click on a fake social media notification
We train our users to always hover over links in emails and to validate the domain where the links points to. This can’t be trusted if you are using Microsoft Edge to view your emails in Office 365.
Your ultimate guide to the process behind social engineering training and all of the tips and know-how you need to ensure your training successfully changes behavior.
Vishing attacks are spiking, and they’re powered by AI voice clones and social engineering. Here's how to prevent vishing with real-world tactics and simulation-based training.
From Spear-Phishing, to Credential Harvesting, To Possible Ad Fraud. Keep Reading To Find Out How This Story Unfolded and How You Can Avoid Getting Caught.
We're seeing an uptick in social engineers targeting social media accounts
Now that cookies are on their way out, a much sneakier way of identifying you is on its way in.