NOUSEC Blog

Human risk, explained.

Research and practical guidance on social engineering, security awareness, and measuring the human side of your attack surface.

House outline with Wi-Fi waves and a shielded laptop beside a risk gauge on a navy NOUSEC-branded background
GuideSeptember 15, 2026 · 6 min read

Remote and Hybrid Work: Closing the Human Risk Gap

Hybrid work is now the norm — and attackers follow employees home. The human risks of distributed work and how to manage them with training and controls.

Office floor plan with one highlighted workstation radiating risk signals on a navy NOUSEC-branded background
GuideSeptember 13, 2026 · 6 min read

Insider Threat Management: Reducing Risk from Within

Insider incidents now cost organizations $19.5M a year, and negligence causes over half. How to build an insider threat program that actually works.

Corporate laptop sending documents into an unapproved AI chatbot cloud on a navy NOUSEC-branded background
GuideSeptember 11, 2026 · 7 min read

Shadow AI at Work: The Human Risk Nobody Approved

Shadow AI now figures in 43% of breached organizations, and most have no AI policy. How unapproved AI use leaks data — and how to govern it without a ban.

AI chip generating a stream of tailored phishing emails on a navy NOUSEC-branded background
GuideSeptember 9, 2026 · 6 min read

AI-Generated Email Attacks: When the Lure Writes Itself

AI now shapes over 8 in 10 phishing emails and beats elite human red teams. What machine-written lures change — and how to defend your workforce.

Fake CAPTCHA verification dialog with a hidden terminal command on a navy NOUSEC-branded background
GuideSeptember 7, 2026 · 7 min read

ClickFix Attacks: When the Victim Runs the Malware

ClickFix fake-CAPTCHA lures grew over 500% and now trail only phishing. How the copy-paste attack works, why users comply, and how to stop it.

A supply chain diagram where the attacker's path enters through a vendor node before reaching the company, on a navy NOUSEC-branded background
GuideSeptember 5, 2026 · 7 min read

Third-Party Human Risk: When the Breach Starts at a Vendor

Verizon says 48% of breaches now involve a third party. How attackers exploit your vendors' employees to reach you — and how to manage that risk.

A boardroom agenda card with security training as item one and a personal liability notice on a navy NOUSEC-branded background
GuideSeptember 3, 2026 · 8 min read

Executive Security Training: Why the Board Goes First

Executives are the most targeted, least trained people in a company. What NIS2, DORA and the SEC require — and how to train a board without wasting time.

A day-one onboarding checklist card with a highlighted 90-day risk window on a navy NOUSEC-branded background
GuideSeptember 1, 2026 · 11 min read

New Hire Security Training: Onboarding That Sticks

Why the first 90 days are the riskiest, what regulators require at hire, and a six-step onboarding model that builds reporting habits instead of ticking a box.

A champion network diagram card showing a central security team connected to department champions on a navy NOUSEC-branded background
GuideAugust 31, 2026 · 8 min read

Security Champions: How to Build a Program That Works

How to design a security champions program that changes behavior — selection, time budget, what champions actually do, and how to measure it.

A simulation metrics dashboard card showing report rate rising above click rate on a navy NOUSEC-branded background
AnalysisAugust 29, 2026 · 7 min read

Beyond the Click Rate: Simulation Metrics That Matter

Click rate alone is a weak signal. The simulation metrics that predict real resilience — report rate, time-to-report, miss rate — with honest benchmarks.

A chat conversation card showing a long-con investment lure beside a fake trading chart on a navy NOUSEC-branded background
GuideAugust 27, 2026 · 7 min read

Pig Butchering Scams: An Enterprise Defense Guide

Pig butchering is now a $64B criminal industry that reaches employees at work. Why the long con is an enterprise risk — and how to build a defense.

EU stars beside a NIS2 enforcement timeline card on a navy NOUSEC-branded background
GuideAugust 25, 2026 · 7 min read

NIS2 and Human Risk: What the Directive Requires

NIS2 makes management liable for cybersecurity training and gives you 24 hours to report incidents. What Articles 20, 21 and 23 mean for the human layer.

A badge-locked office door, an open laptop and a paper recycling bin, on a navy NOUSEC-branded background
GuideAugust 23, 2026 · 8 min read

Tailgating, Shoulder Surfing and Dumpster Diving: The Physical Side of Social Engineering

Four physical social engineering techniques, what actually separates them, and why the controls that stop one are useless against the others.

A passkey sign-in card with a fingerprint icon replacing a password field, on a navy NOUSEC-branded background
GuideAugust 23, 2026 · 6 min read

Passkeys and FIDO2: An Enterprise Migration Guide

Push prompts and OTP codes are being phished at scale. How to move your workforce to passkeys — in which order, and without breaking recovery.

Service desk password reset ticket flagged as identity not verified, on a navy NOUSEC-branded background
GuideAugust 21, 2026 · 7 min read

Help Desk Impersonation: Defending the IT Service Desk

Attackers don't hack the help desk — they call it. Inside the password-reset attacks that hit MGM, Clorox and M&S, and the controls that stop them.

A fraudulent bank-detail change email flagged for out-of-band verification on a navy NOUSEC-branded background
GuideAugust 19, 2026 · 6 min read

Business Email Compromise: A Defense Playbook

BEC outearns almost every other cybercrime and carries no malware. A practical playbook: payment controls, mailbox tells, simulation, and recovery.

Incident containment checklist beside a countdown clock on a navy NOUSEC-branded background
GuideAugust 17, 2026 · 7 min read

Incident Response for Social-Engineering Attacks

Most IR plans are built for malware. A practical playbook for the first hours after a social-engineering breach: identity, money, and the 72-hour clock.

EU flag stars beside a GDPR training compliance checklist on a navy NOUSEC-branded background
GuideAugust 15, 2026 · 7 min read

GDPR and Security Awareness Training: What the Law Requires

GDPR never says 'security awareness training' — yet regulators fine its absence. What Articles 32 and 39 require and how to build a defensible program.

Scenario card with an inject timeline illustrating a social-engineering tabletop exercise on a navy NOUSEC background
GuideAugust 13, 2026 · 7 min read

How to Run a Social-Engineering Tabletop Exercise

A step-by-step guide to social-engineering tabletop exercises: five scenarios from real breaches, who belongs in the room, and how to turn gaps into fixes.

Phone flooded with authentication push notifications on a navy NOUSEC-branded background
GuideAugust 11, 2026 · 7 min read

MFA Fatigue Attacks: How Push Bombing Defeats 2FA

MFA fatigue breached Uber and Cisco with nothing but repeated push prompts. How push bombing works, why users approve, and the controls that stop it.

Stylized incoming-call card with a cloned voice waveform and warning badge on a navy NOUSEC-branded background
GuideAugust 9, 2026 · 7 min read

Deepfake Voice Attacks on Finance Teams: A Defense Guide

Three seconds of audio can clone a voice. How deepfake calls target finance teams, what the Arup and Ferrari cases teach, and the playbook that stops them.

Stylized QR code with a phishing warning on a navy NOUSEC-branded background
GuideAugust 7, 2026 · 6 min read

QR Code Phishing (Quishing): Why It Works and How to Stop It

QR code phishing grew 146% in one quarter. How quishing attacks evade email filters, why phones are the weak point, and a practical defense playbook.

Human risk score gauge and contributing signal bars on a navy NOUSEC-branded background
GuideAugust 5, 2026 · 5 min read

Human Risk Score: How to Quantify Employee Security Risk

A practical guide to building a human risk score: which signals to use, how to weight them, and how to turn employee risk into a metric boards understand.

Chart showing phishing failure rates declining from baseline to 12 months of security awareness training, on a navy NOUSEC-branded background
AnalysisAugust 3, 2026 · 6 min read

Security Awareness Training ROI: What the Evidence Actually Shows

Does security awareness training pay off? A hype-free look at the ROI evidence — peer-reviewed studies, benchmark data, and a model you can run yourself.

Illustration of a smartphone receiving a fraudulent call and text message, representing vishing and smishing attacks
GuideAugust 1, 2026 · 6 min read

Vishing and Smishing Attacks: Real-World Examples and How to Defend Against Them

Vishing surged 442% in 2024. Real vishing and smishing attack examples — MGM, toll scams, callback phishing — and a practical defense playbook.

Illustration of a phishing simulation email being inspected against a navy background with the NOUSEC wordmark
GuideJuly 31, 2026 · 7 min read

Phishing Simulation Best Practices: How to Test Employees Without Breaking Trust

Evidence-based phishing simulation best practices: cadence, difficulty, metrics beyond click rate, and a 90-day rollout plan for security teams.

Diagram showing human risk management as a continuous loop of simulate, measure, train, and report
GuideJuly 30, 2026 · 4 min read

What Is Human Risk Management? A Practical Guide for Security Teams

Human risk management (HRM) goes beyond annual awareness training: it continuously measures, scores, and reduces the risk created by how employees respond to real-world social engineering.

Chart-style graphic summarizing key social engineering statistics for 2026
StatisticsJuly 30, 2026 · 3 min read

Social Engineering Statistics 2026: The Numbers Behind the Human Element

The key social engineering statistics for 2026 — from the 62% of breaches involving the human element to the 442% surge in vishing and the $40B deepfake fraud forecast — with sources.