Read articles about security awareness, risk management, behavior change, and more
How quishing is being used in attacks, what these threats look like in the wild and best practices for avoiding them.
Here's how to change the narrative around cybersecurity to get employees engaged.
Your ultimate breakdown on how effective security awareness training really is and why traditional compliance programs fall short.
How do you achieve cybersecurity behavior change? A breakdown of how science-based training transforms awareness into real-world risk reduction.
Your essential guide to building a robust security culture. How to implement effective training, policies, and recognition systems to mitigate human cyber risk.
The essential security awareness topics that truly change employee behavior and how Hoxhunt blends behavioral science, real-world simulations, and adaptive learning to boost engagement.
With Hoxhunt, on average more than 60% of employees are engaged in the training after just one year. But some organizations manage to push past 85%, even into the 90s. What's their secret?
Fantasy football can teach us how to learn stop worrying and love the art and chaos of starting a new leadership position.
Recent research published in the wall street was correct: bad phishing simulations produce bad results. So what now?
The CISO Fantasy Phish Bowl 2025 brings together some old friends and new joiners. There's one heavy absence: Shawn Bowen, to whom this year's Phish Bowl is dedicated. Here's to you, Shawn!
Phishing simulation best practices with real case results from Bird & Bird - ethical lures, instant feedback, and KPIs that drive reporting.
Best phishing simulation tools for enterprises (2025) - AI-powered, gamified platforms with multi-vector realism, SOC integrations, and risk dashboards.
Cybersecurity Awareness Month ideas that work: run a focused 10-day campaign, launch phishing simulations, boost MFA adoption, and use our 2025 toolkit.
Cybersecurity awareness training has become crucial to getting cyber insurance and lowering premiums in 2021. That trend will continue to grow.
What is the real cost of phishing in 2021? The answers will surprise you. Especially cyber insurance; premiums have exploded while in the industry has imploded.
David X Martin is one of the world’s leading authorities on risk management and cybersecurity. Here he discusses the ideas and experiences behind the genesis of his latest book.
The difference between measured risk and true risk of a phishing attack breach is based on user engagement, and the difference is critical to resilience.
CISOs need the soft skills and business expertise to shake hands with the board and high five the C-suite in their role's evolution to business enablers
The hybrid work environment is here to stay and security teams must face its unique challenges with great technical controls and training.
Repeat phishing offenders aren’t the problem... static training is. Learn how we use adaptive simulations to convert clickers into security assets.
Learn how behavior-based cyber security training drives lasting employee behavior change. A breakdown of the key components, benefits, and why it’s essential for building a strong security culture.
Discover how Hoxhunt outperforms competitors in cybersecurity training. Based on real reviews, compare Hoxhunt's features, quality, and effectiveness to leading alternatives.
Empower your team to be a human firewall. Discover how training, vigilance, and smart habits protect against cyber threats.
Password protected attachments can evade spam filters and raise users' curiosity and trust
Updated from its 2021 version, the 2022 spoofed US Department of Transportation credential harvesting site is extremely effective
Pretexting a form of phishing that hooks victims with a simple but convincing message without malicious links.
Breaking the phishing attack kill chain requires understanding the three steps that drive its process, and the five most common effects of a successful attack.
Fax phishing uses fake email notifications spoofing e-fax services to trick people into entering sensitive data onto credential harvesting pages
The war in Ukraine has spawned two widespread types of phishing campaigns we're monitoring. Here are three ways to spot them.
Your SaaS suite is leaving your backdoor open. Here's how to fix it.
Log4J Log4Shell vulnerability explained to help you understand what it is and how to stay protected
A security vulnerability was recently reported in the default guest permissions of Microsoft Azure Active Directory. Here’s how to fix it and stay safe from attackers.
This phishing email was sent from outside the organization but is replacing the Caution! External Sender banner with a safe sender banner.
Apple just recently confirmed the most significant vulnerability in iOS history after ZecOps made a public announcement about their discovery of a security flaw.
According to security researchers, the iOS mail app, which is the email client that can be found on most Apple iPhones and iPads, has a severe security flaw making it vulnerable to attacks.
Stop deepfake, smishing & vishing scams with 8 proven tactics: Feel→Slow→Verify→Act, no approvals in live calls, out-of-band callbacks, and a reporting culture.
Your ultimate guide to the process behind social engineering training and all of the tips and know-how you need to ensure your training successfully changes behavior.
Vishing attacks are spiking, and they’re powered by AI voice clones and social engineering. Here's how to prevent vishing with real-world tactics and simulation-based training.
From Spear-Phishing, to Credential Harvesting, To Possible Ad Fraud. Keep Reading To Find Out How This Story Unfolded and How You Can Avoid Getting Caught.
We're seeing an uptick in social engineers targeting social media accounts
Now that cookies are on their way out, a much sneakier way of identifying you is on its way in.