Writing on training, phishing, and compliance
Field-tested ideas for getting security training done, and proving it.
The cyber-insurance training guide: what underwriters actually ask for
Renewals increasingly hinge on proof of security awareness training. Here is what brokers look for, and how to have it ready before they ask.
Cybersecurity training for nonprofits: making the case your board and funders want to see
Nonprofits handle some of the most sensitive data there is, on some of the smallest budgets. That is exactly why attackers target them. Here is how to build a training program that works without a security team.
Why micro-learning beats the 40-minute mandatory video
Completion is the metric that matters. Short episodes people finish outperform long videos they skip through. Here is the data pattern we see.
Phishing scenario quizzes that land: use your own threats, not stock templates
Generic phishing templates train people to spot generic phishing. Scenario quizzes built from your real incidents train them to spot yours.
How to set retraining intervals your team will actually keep
Retraining is only effective if it happens. A practical approach to intervals, reminders, and department-level rollups.