< ciso
brief />
Tag Banner

All news with #security awareness tag

231 articles · page 4 of 12

Cybersecurity Certifications: A Business Imperative

🔒 The Fortinet 2025 Global Cybersecurity Skills Gap Report shows persistent talent shortages are driving higher breach rates and financial losses, making validated skills essential. Certifications provide standardized, role-aligned evidence of operational readiness, support staged career progression, and signal employer investment to improve retention. Structured programs map learning to real roles and help close the readiness gap between knowing concepts and applying them under pressure.
read more →

Meta's New AI Glasses Raise Urgent Privacy Concerns

👓 Meta's new AI glasses are a privacy disaster, capturing audio, images, and contextual data in public and private spaces without meaningful consent. Security expert Bruce Schneier warns the technology is inevitable and difficult to regulate effectively. He notes an Android app now claims to detect nearby smart glasses, but detection is limited and insufficient to address broader surveillance and policy challenges.
read more →

Reflections on Diversity, Threats, and Cyber Guidance

🔒The author opens this week’s Threat Source newsletter with personal reflections on being raised by a single mother, connecting those experiences to the gender imbalance in STEM and cybersecurity. He cites sobering statistics — for example, women comprise 28.2% of the global STEM workforce and occupy only 16% of CISO roles — and highlights mentorship programs like WiCyS and CTFs. Talos also summarizes a March 10 update on cyber activity tied to the Middle East conflict and provides practical defensive advice for destructive malware, DDoS, and website defacement.
read more →

GSEC Summit 2026: Building Safer, Balanced Teen Experiences

🛡️ At the Growing Up in the Digital Age Summit in Dublin, Google presented product safeguards and policy principles designed to support teen digital wellbeing, emphasizing defaults like SafeSearch and private YouTube uploads as baseline protections. The company announced improvements to Family Link, a unique option to set Shorts time to zero for supervised teens, and additional Gemini Apps guardrails for users under 18. It also unveiled a $20 million global initiative to create multilingual, open-source wellbeing resources and urged a risk-based approach to age assurance rather than blanket bans.
read more →

Microsoft Teams Will Tag Third-Party Bots in Lobbies

🛡️Microsoft will update Teams to clearly label external third-party bots that appear in meeting lobbies, and organizers will be required to explicitly admit them. The change is slated for May 2026 and will reach Windows, macOS, Android, and iOS for worldwide standard multi-tenant and GCC clouds. By distinguishing bots from human attendees, the feature aims to prevent malicious or unwanted automated participants from being inadvertently accepted into meetings and complements recent Teams security enhancements such as call-reporting, fraud-protection warnings, and Defender-based admin controls.
read more →

Encouraging Women in Cybersecurity at Every Career Stage

🔐 Women early in their careers are shaping the future of cybersecurity and AI security, bringing fresh perspectives, curiosity, and collaborative leadership that strengthen detection, design, and resilience. The post argues that diversity is a security imperative, citing research such as the ISACA paper and workforce data showing women comprise roughly 24% of the field. It highlights leaders and programs like Girl Security and recommends practical steps—mentorship, inclusive hiring, sustained training, and community partnerships—to support women from introduction through leadership.
read more →

2025 Security Awareness Report: Training Works, Gaps Remain

🔒 AI-driven threats have increased employee awareness, but readiness remains uneven: only about 40% of leaders say staff are prepared to identify, avoid, and report AI-based threats. The 2025 report, based on responses from 1,850 senior IT and security leaders, shows training reduces incidents—67% of organizations report moderate or significant reductions—and measurement is shifting toward behavior-focused programs. However, low completion rates, rising insider risk, and outdated content limit impact; practical fixes include microlearning, role-based content, and clearer accountability backed by leadership.
read more →

Half of US CISOs Now Working Equivalent to Six-Day Weeks

📊 A Seemplicity survey of 300 CISOs and equivalents finds nearly half of US security leaders are effectively working an extra day each week, with 45% logging 11+ additional hours and 20% putting in 16+ hours. Forty-four percent say the role feels emotionally exhausting and 43% cannot take time off without undue stress, yet 94% would still choose cybersecurity. The report warns AI is shifting work from execution to interpretation, increasing the need for communication and business skills.
read more →

Scorecard for Cyber and Risk Culture Transformation

🔒 This article argues that security culture must be measured and designed, not celebrated as events. It contrasts awareness (what people can repeat) with ownership (what they do under pressure), shows where culture appears in daily decisions, and warns that campaigns and checklists alone won’t create durable change. The author prescribes a practical scorecard and an operating-system redesign so secure choices become the obvious path.
read more →

From Classroom to Cyber Career — Fortinet and UniSA

🔐 Fortinet's Academic Partner Program partners with the University of South Australia to expand access to cybersecurity careers by delivering NSE training, hands-on labs, and free exam vouchers that remove financial barriers. With more than 800 partner institutions worldwide and a goal to train 1 million individuals by 2026, the initiative readies students for internships and full-time roles. Industry networking events with distributors such as Wavelink translate certification into interviews and hires, while practical lab work builds technical confidence and employability.
read more →

Mobile App Permissions Still Matter: Protect Your Privacy

🔒 App permissions determine which data and device features an app can access, and many users accept prompts without considering the consequences. The article, by Phil Muncaster, explains how modern Android and iOS versions surface sensitive permissions at runtime and distinguishes between benign “normal” permissions and higher-risk “dangerous” ones. It highlights particularly sensitive requests — accessibility, background location, SMS/call logs and overlay — and recommends using Allow once or While using, regularly auditing permissions via App Privacy Report or Privacy Dashboard, and installing apps only from reputable stores.
read more →

Redesigning Turnstile and Challenge Pages at Cloudflare

🔐Cloudflare describes a comprehensive redesign of its Turnstile widget and full-page Challenge Pages, interfaces that are served billions of times per day. After a detailed audit and international user testing, the team consolidated inconsistent error states into a single information architecture and simplified messaging to reduce user friction. The refresh emphasizes AAA accessibility (WCAG 2.2 AAA), clearer in-widget troubleshooting, consistent localization across 40+ languages, and subtle visual cues that lower abandonment without weakening security.
read more →

Cyber Resilience Requires People, Skills, and Training

🛡️ The 2025 Global Cybersecurity Skills Gap Report shows that human risk and workforce shortages—not technology alone—are driving frequent, costly breaches: in 2024, 86% of organizations experienced at least one breach and 28% reported five or more. Awareness deficits, phishing, and skills gaps account for most incidents, so training must be preventive, continuous, and role-based. Fortinet pairs security products with a broad training and certification program to help organizations close these gaps and improve detection, response, and recovery.
read more →

Rethinking the Human Layer: Farmers vs. Mercenaries

🛡️ Employees are commonly labeled "the last line of defense," but this article argues that such expectations misplace responsibility. The real human layer is the trained security team—CISOs, SOC analysts and threat hunters—whose capacity is being consumed by high false-positive volumes and noisy user-reporting. Organizations should reduce alert noise, improve tooling and restore analyst capacity rather than relying on broader awareness programs.
read more →

Recognizing Red Flags of Business Email Compromise

🔎 Business Email Compromise (BEC) exploits social engineering and subtle technical deception to manipulate employees and bypass controls. Attackers use domain tweaks, display-name spoofing, urgent off-hours requests, and impersonation to pressure finance, HR, or operations into transfers or data disclosure. Inspect headers and SPF/DKIM/DMARC, enforce MFA, run phishing simulations, and maintain a strict verification culture.
read more →

EC-Council Expands AI Certifications, Adds CISO v4

🔐 EC-Council launched the Enterprise AI Credential Suite, introducing four role-based AI certifications alongside an updated Certified CISO v4 to strengthen executive readiness. The programs target a growing skills gap—cited as $5.5 trillion in unmanaged AI exposure and a 700,000-person U.S. reskilling shortfall—and align with U.S. AI workforce priorities. The suite maps to an Adopt. Defend. Govern. framework and includes Artificial Intelligence Essentials, CAIPM, COASP, and CRAGE to operationalize secure, responsible AI.
read more →

Bridging the Cyber Skills Divide Through Local Partnerships

🔒 Fortinet’s Education Outreach Program partners with local organizations to expand access to cybersecurity training and industry-recognized certifications. By offering free NSE curriculum and hands-on labs, the program removes cost and access barriers for learners in underserved regions. Partnerships with EduTek in Guatemala and PAICTA in South Africa demonstrate measurable outcomes: participants gain practical skills in firewall management and network security operations, and many progress into employment and improved professional standing.
read more →

Mature Leadership Needed: Move Beyond Security Checklists

🔒 Cybersecurity is not a game; it demands mature leadership, sustained strategy, and clear accountability. The article argues that treating compliance as an achievement, relying on flashy tools, or measuring vanity metrics produces pseudo-security that offers visibility but not protection. CISOs should prioritize people, processes, and risk-based decisions, and build long-term resilience rather than chasing short-term wins.
read more →

Phishing Abuse of Google Tasks to Steal Credentials

🔔 Attackers are abusing Google Tasks notifications to bypass email filters and trick employees into submitting corporate credentials. Recipients receive legitimate-looking @google.com notices urging urgent action and a link to a credential-harvesting form. Organizations should train staff, maintain clear lists of authorized services, and consider mail gateway security and endpoint protection to block phishing sites. Use tools like Kaspersky Automated Security Awareness Platform to automate training.
read more →

Board Accountability for Cyber Risk and Training Gaps

🔒 Cybersecurity has shifted from a technical issue to a board-level business and financial risk, yet many directors remain underprepared to govern it. The 2025 Cybersecurity Skills Gap Global Research Report shows 96% of organizations call cybersecurity a business priority, but only 49% of leaders believe boards fully understand the risks, particularly as AI reshapes threats. Persistent skills and awareness gaps correlate with higher breach frequency and costs, and training programs are often reactive rather than embedded as continuous governance.
read more →