Security Awareness Topics With Greatest Impact

Okay, I had some ideas all lined up for a blog post, but Cormac Herley's paper The Rational Rejection of Security Advice by Users really got me thinking. I posted my initial thoughts on his paper the other day, but I wanted to take things a step farther. As you may remember (of if you have not read his paper) Cormac does a cost benefit analysis on three different security awareness topics and determines they are not cost effective. While I may not agree with all of his analysis or findings I agree with that different topics have different ROI (Return On