< ciso
brief />
Tag Banner

All news with #human risk management tag

65 articles · page 2 of 4

Human-centric Failures: Why BEC Survives Despite MFA

🔒 Multi-factor authentication reduces credential risk but does not stop many business email compromise (BEC) attacks, because adversaries target human decision points and process gaps rather than accounts. High-profile cases — Toyota Boshoku (2019, ≈$30M) and Arup (2024, ≈$25M) — show attackers using cloned messages and deepfakes without stealing credentials. Organizations should redesign approval workflows, require out-of-band verification for high-risk requests, run realistic BEC simulations, embed micro-learning, introduce purposeful friction and assign clear ownership of payment verification to close operational blind spots.
read more →

Only 34% of Cyber Pros Plan to Stay With Employers

🔍Only 34% of cybersecurity professionals plan to remain with their current employer, according to a survey of 500 respondents by IANS and Artico Search. The report finds that flexible work models, visible leadership support, and structured career development influence retention more than absolute pay. Hybrid schedules, mentorship, and modern tooling help reduce burnout and turnover.
read more →

Cyber Threat Literacy Tops Global People Risks 2026

🛡️ Marsh's 2026 People Risks report, compiled from interviews with over 4,500 HR and risk professionals across 26 markets, finds cyber-threat literacy is the top global people risk, with technological change, tech skills shortages and AI-related mindset barriers also ranking highly. The report highlights mishandling of data and low employee security awareness as persistent threats that can increase exposure to breaches and reputational damage. Marsh recommends reframing cyber risk to cover OT, HR and third-party systems, recruiting cyber talent, building a cyber-centric culture, reducing fatigue, and ensuring human oversight with robust governance and insurance cover.
read more →

Most Cybersecurity Staff Feel Undervalued and Underpaid

🔍 Over three quarters of cybersecurity professionals did not receive a pay rise last year, and roughly half report feeling undervalued, according to the Harvey Nash Global Tech Talent & Salary Report. Only 45% expect a pay increase in the next 12 months, placing information security professionals among the most pessimistic about pay prospects. Just 22% said their organisations increased cybersecurity resources after high-profile incidents, driving dissatisfaction and turnover risk.
read more →

CISOs Must Innovate to Retain Cybersecurity Talent

🔒 A new 2026 Cybersecurity Talent Report from IANS and Artico Search warns CISOs must be aggressive and innovative to retain staff amid a volatile jobs market. Based on interviews with over 500 US cybersecurity professionals, the study found only 34% plan to stay in their roles while 43% are considering a change, with turnover intent higher among senior staff. The report links job satisfaction to career progression, compensation movement and work-life balance, and highlights hybrid working and visible senior support as key retention drivers.
read more →

A Taxonomy of Cognitive Security and Reality Pentesting

🧠 Bruce Schneier highlights K. Melton’s recent framework on cognitive security, cognitive hacking, and “reality pentesting.” Melton organizes cognition into five architectural layers—sensory interface, neurocompiler, mind kernel, the mesh, and cultural substrate—and shows how fast, unconscious processes (Kahneman’s System 1) create exploitable backdoors. The taxonomy frames human perception as an IT-like attack surface and suggests practical implications for testing, defense, and threat modeling.
read more →

Rethinking Human Risk: Awareness Isn't a Control, Period

🔒 Organizations frequently treat security awareness training as a control, but this article contends it is primarily a cultural measure that cannot guarantee consistent outcomes. While training and phishing simulations reduce risk at the margins, they do not eliminate human variability or stop sophisticated business email compromise, credential harvesting, and modern MFA bypass techniques. The author recommends engineering systems to assume human fallibility—through phishing-resistant authentication, enforced financial controls, continuous identity telemetry, and real-time anomaly detection—so a single mistake cannot cause material harm.
read more →

Low-Cost Steps to Strengthen Your Security Posture Now

🔒 This piece presents eight practical, low-cost measures CISOs and security teams can deploy to materially improve enterprise protection. Recommendations emphasize better enforcement of MFA, fuller use of existing tool capabilities, regular tabletop exercises, and adoption of passkeys for high-risk users. The focus is on disciplined execution, configuration, and human risk management rather than large new purchases.
read more →

Rethinking Cybersecurity Hiring: Skills-First Talent

🔍 Many organizations treat the cybersecurity skills gap as a supply problem, but the 2025 Cybersecurity Skills Gap Global Research Report shows restrictive hiring definitions are a major cause. Rigid filters like four-year degrees exclude candidates with military, technical, or vendor-certified experience who already possess relevant, hands-on capabilities. Adopting a skills-first approach and mapping role-aligned certifications to job requirements expands the qualified pool, shortens onboarding, and reduces operational risk. Fortinet emphasizes partnerships and free, scalable training as practical ways to build and certify talent at scale.
read more →

Insider Threats Surge as AI and Remote Work Expand Risk

🚨 Insider threats are rising again: the Mimecast State of Human Risk Report found 42% of organizations saw increases in both malicious and negligent insider incidents, with an average of six insider-driven incidents per month at an estimated cost of $13.1 million per incident. Two-thirds of surveyed IT leaders expect insider-related data loss to grow over the next 12 months. Experts warn the insider perimeter now includes contractors, fraudulent hires, and AI agents, and they recommend adaptive, behavior-driven controls, coordinated legal/HR response plans, and extending protections to nonhuman identities to reduce risk.
read more →

Encouraging Women in Cybersecurity at Every Career Stage

🔐 Women early in their careers are shaping the future of cybersecurity and AI security, bringing fresh perspectives, curiosity, and collaborative leadership that strengthen detection, design, and resilience. The post argues that diversity is a security imperative, citing research such as the ISACA paper and workforce data showing women comprise roughly 24% of the field. It highlights leaders and programs like Girl Security and recommends practical steps—mentorship, inclusive hiring, sustained training, and community partnerships—to support women from introduction through leadership.
read more →

Half of US CISOs Now Working Equivalent to Six-Day Weeks

📊 A Seemplicity survey of 300 CISOs and equivalents finds nearly half of US security leaders are effectively working an extra day each week, with 45% logging 11+ additional hours and 20% putting in 16+ hours. Forty-four percent say the role feels emotionally exhausting and 43% cannot take time off without undue stress, yet 94% would still choose cybersecurity. The report warns AI is shifting work from execution to interpretation, increasing the need for communication and business skills.
read more →

Seven Key Factors Driving the Cybersecurity Skills Gap

🔐 The article summarizes seven factors limiting organizations' ability to build sustainable cybersecurity talent pipelines and cites World Economic Forum data showing only 14% of organizations feel they have the required people and skills. Contributors highlight constrained budgets and rising burnout, the rapid emergence of AI and other technologies, and misaligned employer–candidate expectations as core drivers. Additional issues include outdated processes, training mismatches, strategy disconnects, and failures to simplify and scale operations. Experts recommend internal upskilling, using managed services and automation, and framing the skills gap as a clear business risk to leadership.
read more →

Cyber Resilience Requires People, Skills, and Training

🛡️ The 2025 Global Cybersecurity Skills Gap Report shows that human risk and workforce shortages—not technology alone—are driving frequent, costly breaches: in 2024, 86% of organizations experienced at least one breach and 28% reported five or more. Awareness deficits, phishing, and skills gaps account for most incidents, so training must be preventive, continuous, and role-based. Fortinet pairs security products with a broad training and certification program to help organizations close these gaps and improve detection, response, and recovery.
read more →

Majority of CISOs Open to Career Moves, Many Exit Now

🚨 A recent IANS Research and Artico Search survey found that 69% of enterprise CISOs are open to a career move within the next year, often targeting larger-company CISO roles, other executive posts, or non-CISO paths. Analysts attribute the trend to chronic exhaustion, misaligned authority, and a structurally broken role that leaves leaders accountable without matching influence. Experts recommend giving CISOs enterprise-level standing, direct CEO and board access, and authority and budget that match their responsibilities to retain top security talent.
read more →

Why Smart People Fall for Phishing: Psychological Tactics

🧠 Unit 42 examines why phishing remains effective despite advanced defenses, highlighting the role of human psychology, cognitive bias and AI-enabled deception. The article outlines a three-stage attack model—The Bait, The Hook and The Catch—and common social engineering tactics such as urgency, authority and distraction. It urges a zero-trust mindset, continuous education and a simple habit: pause and verify before acting.
read more →

Human Risk Management: Rethinking Security Training

🧠Human Risk Management reframes employee training as measurable behavioral risk reduction rather than a compliance checkbox. HRM tools integrate with email and identity systems to detect risky actions in real time and deliver immediate, contextual remediation such as micro-learning, automated controls, or role-specific simulations. Vendors like Fable Security, KnowBe4 and Mimecast combine standard SAT content with AI-driven nudges to improve real-world digital hygiene.
read more →

Human Risk Management: Rethinking Security Training

🔒Security awareness training (SAT) increasingly fails to reduce real-world human risk, even as organizations spend billions and meet regulatory mandates like HIPAA, GDPR, and PCI. The article argues that firms should move from knowledge-focused SAT to human risk management (HRM), which measures actual user behavior through email, web, and IAM integrations and targets the riskiest users. Leading vendors such as Fable Security, KnowBe4, and Mimecast bundle SAT content into HRM platforms and use AI to deliver personalized micro-learning, simulations, and behavioral nudges that aim to create lasting habit change.
read more →

Building Cyber Readiness Early: Youth Education Imperative

🔐 Cyber security should begin in childhood, not only as a late-stage workforce specialization. The piece argues that threat actors target schools, hospitals, municipalities and small businesses as aggressively as large enterprises, and that waiting for workforce pipelines to mature leaves communities exposed. Early, practical education—covering ransomware awareness, phishing resistance, hands-on skills and teacher training—reduces immediate risk and strengthens future talent pools.
read more →

Six Strategies to Build a High-Performing Security Team

🔒 Building a high-performing cybersecurity team requires deliberate hiring, clear mission alignment, and empowered leadership. Veteran security leaders advise assembling a balanced mix of ambitious innovators and dependable 'rock stars,' promoting diverse backgrounds, and giving teams targeted training, tools, and AI-enabled analytics. They emphasize strong prioritization, business-focused communication skills, and appointing deputies to scale leadership, speed decision-making, and sustain operational resilience.
read more →