Security Awareness Blog

Free Planning/Deployment Kit for your Security Awareness Program

Creating a security awareness program for compliance is simple. Creating an active, long term and engaging security awareness program that has an impact is hard. To help you and your organization with your security awareness program I updated the SANS Securing The Human Deployment kit. This is package has been completely updated with over 15 … Continue reading Free Planning/Deployment Kit for your Security Awareness Program


You Know Your Security Awareness Program is Having An Impact When ...

Creating a security awareness program so you are compliant is easy. Creating a security awareness program that changes behaviors and has an impact is hard. One of the challenges is how do you know when you are having an impact? Here are some metrics I've noticed - you know you are having an impact when … Continue reading You Know Your Security Awareness Program is Having An Impact When ...


Gamifying Security Awareness

One of the challenges we have with security awareness is when you come down to it, awareness training and education can become boring over time. Yes there are steps you can take to make it exciting, and there are many things you can do to sexy training up, but how often do you have employees … Continue reading Gamifying Security Awareness


Webcast on Phishing / Spearphishing Your Organization

I just listened in on a great webcast by John Strand, one of SANS' lead instructors on their penetration testing courses. John spends an hour discussing the latest tools and techniques in conducting human based penetration testing, specifically phishing and spear phishing. If you are involved in penetration testing and/or awareness training this is a … Continue reading Webcast on Phishing / Spearphishing Your Organization


HOWTO Awareness Training for APT

The APT (Advanced Persistent Threat) has popped-up on the radar for many organizations, including those in government, defense or research. As many of you already know, APT is a type of threat (it is a WHO, not a HOW). Specifically a highly trained threat that is motivated to compromise your organization, and they have both … Continue reading HOWTO Awareness Training for APT