Human risk, explained.
Research and practical guidance on social engineering, security awareness, and measuring the human side of your attack surface.

Remote and Hybrid Work: Closing the Human Risk Gap
Hybrid work is now the norm — and attackers follow employees home. The human risks of distributed work and how to manage them with training and controls.

Insider Threat Management: Reducing Risk from Within
Insider incidents now cost organizations $19.5M a year, and negligence causes over half. How to build an insider threat program that actually works.

Shadow AI at Work: The Human Risk Nobody Approved
Shadow AI now figures in 43% of breached organizations, and most have no AI policy. How unapproved AI use leaks data — and how to govern it without a ban.

AI-Generated Email Attacks: When the Lure Writes Itself
AI now shapes over 8 in 10 phishing emails and beats elite human red teams. What machine-written lures change — and how to defend your workforce.

ClickFix Attacks: When the Victim Runs the Malware
ClickFix fake-CAPTCHA lures grew over 500% and now trail only phishing. How the copy-paste attack works, why users comply, and how to stop it.

Third-Party Human Risk: When the Breach Starts at a Vendor
Verizon says 48% of breaches now involve a third party. How attackers exploit your vendors' employees to reach you — and how to manage that risk.

Executive Security Training: Why the Board Goes First
Executives are the most targeted, least trained people in a company. What NIS2, DORA and the SEC require — and how to train a board without wasting time.

New Hire Security Training: Onboarding That Sticks
Why the first 90 days are the riskiest, what regulators require at hire, and a six-step onboarding model that builds reporting habits instead of ticking a box.

Security Champions: How to Build a Program That Works
How to design a security champions program that changes behavior — selection, time budget, what champions actually do, and how to measure it.

Beyond the Click Rate: Simulation Metrics That Matter
Click rate alone is a weak signal. The simulation metrics that predict real resilience — report rate, time-to-report, miss rate — with honest benchmarks.

Pig Butchering Scams: An Enterprise Defense Guide
Pig butchering is now a $64B criminal industry that reaches employees at work. Why the long con is an enterprise risk — and how to build a defense.

NIS2 and Human Risk: What the Directive Requires
NIS2 makes management liable for cybersecurity training and gives you 24 hours to report incidents. What Articles 20, 21 and 23 mean for the human layer.

Tailgating, Shoulder Surfing and Dumpster Diving: The Physical Side of Social Engineering
Four physical social engineering techniques, what actually separates them, and why the controls that stop one are useless against the others.

Passkeys and FIDO2: An Enterprise Migration Guide
Push prompts and OTP codes are being phished at scale. How to move your workforce to passkeys — in which order, and without breaking recovery.

Help Desk Impersonation: Defending the IT Service Desk
Attackers don't hack the help desk — they call it. Inside the password-reset attacks that hit MGM, Clorox and M&S, and the controls that stop them.

Business Email Compromise: A Defense Playbook
BEC outearns almost every other cybercrime and carries no malware. A practical playbook: payment controls, mailbox tells, simulation, and recovery.

Incident Response for Social-Engineering Attacks
Most IR plans are built for malware. A practical playbook for the first hours after a social-engineering breach: identity, money, and the 72-hour clock.

GDPR and Security Awareness Training: What the Law Requires
GDPR never says 'security awareness training' — yet regulators fine its absence. What Articles 32 and 39 require and how to build a defensible program.

How to Run a Social-Engineering Tabletop Exercise
A step-by-step guide to social-engineering tabletop exercises: five scenarios from real breaches, who belongs in the room, and how to turn gaps into fixes.

MFA Fatigue Attacks: How Push Bombing Defeats 2FA
MFA fatigue breached Uber and Cisco with nothing but repeated push prompts. How push bombing works, why users approve, and the controls that stop it.

Deepfake Voice Attacks on Finance Teams: A Defense Guide
Three seconds of audio can clone a voice. How deepfake calls target finance teams, what the Arup and Ferrari cases teach, and the playbook that stops them.

QR Code Phishing (Quishing): Why It Works and How to Stop It
QR code phishing grew 146% in one quarter. How quishing attacks evade email filters, why phones are the weak point, and a practical defense playbook.

Human Risk Score: How to Quantify Employee Security Risk
A practical guide to building a human risk score: which signals to use, how to weight them, and how to turn employee risk into a metric boards understand.

Security Awareness Training ROI: What the Evidence Actually Shows
Does security awareness training pay off? A hype-free look at the ROI evidence — peer-reviewed studies, benchmark data, and a model you can run yourself.

Vishing and Smishing Attacks: Real-World Examples and How to Defend Against Them
Vishing surged 442% in 2024. Real vishing and smishing attack examples — MGM, toll scams, callback phishing — and a practical defense playbook.

Phishing Simulation Best Practices: How to Test Employees Without Breaking Trust
Evidence-based phishing simulation best practices: cadence, difficulty, metrics beyond click rate, and a 90-day rollout plan for security teams.

What Is Human Risk Management? A Practical Guide for Security Teams
Human risk management (HRM) goes beyond annual awareness training: it continuously measures, scores, and reduces the risk created by how employees respond to real-world social engineering.

Social Engineering Statistics 2026: The Numbers Behind the Human Element
The key social engineering statistics for 2026 — from the 62% of breaches involving the human element to the 442% surge in vishing and the $40B deepfake fraud forecast — with sources.