< ciso
brief />
Tag Banner

All news with #security awareness tag

231 articles · page 6 of 12

Internet Voting Remains Too Insecure for Elections

🔐 Bruce Schneier and a broad group of security scientists warn that internet voting is fundamentally insecure and that no known or foreseeable technology can make it safe for public elections. They criticize persistent claims from vendors and advocates—specifically naming Bradley Tusk and the Mobile Voting Foundation—for promoting misleading assurances. The letter calls on election officials and policymakers to reject online voting and stick with proven, auditable processes.
read more →

Old Habits Die Hard: 2025’s Most Common Passwords Worldwide

🔐 Two 2025 analyses by NordPass and Comparitech show that simple numeric strings like '123456' continue to dominate leaked password lists worldwide. Across 44 countries, 25% of the top 1,000 passwords are purely numeric, while predictable entries such as 'admin', '12345678' and '12345' remain widespread, including in the US and UK. Security advice is clear: change weak or reused passwords, use a reputable password manager, and enable two‑factor authentication or passkeys to reduce account takeover risk. Organizations should combine technical controls with user training to mitigate large‑scale exposure.
read more →

LinkedIn: Why Threat Actors Target Professionals Now

🔒 LinkedIn's vast professional network provides abundant intelligence that threat actors exploit to support spear-phishing, business email compromise and direct recruitment efforts. Profiles and connections help attackers craft highly credible lures, while messages sent within the platform can bypass corporate email controls. To reduce risk, users should limit public detail, enable MFA, maintain patched devices and complete targeted security awareness training focused on fake profiles and malicious DMs.
read more →

Four Ways to Break Free from Security Acronym Hell

📣 Excessive use of abbreviations in cybersecurity creates real communication and onboarding problems across organizations. The article notes that a dense list of acronyms — from MFA and EDR to SASE and SIEM — can act as an exclusionary shorthand that slows new hires, reduces transparency, and increases the risk of misunderstandings. It recommends four practical fixes: standardized glossaries, concise explanations, avoiding unnecessary acronyms, and regular training. Implemented sensibly, these steps restore clarity without sacrificing efficiency.
read more →

Empowering Latinas in Cybersecurity through Training

🔒 Fortinet's Education Outreach program partners with Latinas in Cyber (LAIC) to increase representation of Latina women in cybersecurity through mentorship, practical training, and career pathways. Participants report that Fortinet's self-paced coursework and hands-on labs built technical confidence and clarified real-world security roles. Complimentary exam vouchers enabled candidates to pursue Fortinet certifications aligned with employer needs, helping translate training into tangible opportunities and career advancement.
read more →

Fortinet NSE Training Now Eligible for ISC2 CPE Credits

🔒 Fortinet has joined the ISC2 CPE Submitter program, enabling many Fortinet Training Institute offerings to count as continuing professional education (CPE) credits toward CISSP maintenance. Qualifying activities include NSE certification courses, Fast Tracks, webinars, and other online or in-person sessions; ISC2 recognizes one hour of Fortinet instruction as one CPE credit, up to eight credits per day. Participants must log in to their ISC2 portal and submit the Fortinet course name, duration, and completion date to claim credits.
read more →

Credential stuffing: risks and protection advice today

🔐 Credential stuffing exploits reused login credentials harvested from breaches or captured by infostealer malware, then systematically automates login attempts across services. Attackers increasingly use bots, IP rotation and AI-assisted scripts to mimic human behavior and evade basic defenses, enabling stealthier and larger-scale attacks. Because it uses valid credentials, it often bypasses alarms that detect brute-force failures. Protect yourself with a password manager, enable 2FA/MFA, and monitor for exposed credentials.
read more →

Cybersecurity Isn't Underfunded — It's Poorly Executed

🔒 Boards increasingly accept cyber risk, yet funding rarely follows purely rational ROI debates. The author contends that budget availability is often reactive — unlocked by imminent regulatory reviews, adverse audits or recent incidents — rather than the result of careful risk quantification. The core obstacles, he argues, are chronic execution failures, governance and cultural misalignment. CISOs should focus on building trust and strategic influence during the first hundred days to convert goodwill into lasting programs.
read more →

Six Strategies to Build a High-Performing Security Team

🔒 Building a high-performing cybersecurity team requires deliberate hiring, clear mission alignment, and empowered leadership. Veteran security leaders advise assembling a balanced mix of ambitious innovators and dependable 'rock stars,' promoting diverse backgrounds, and giving teams targeted training, tools, and AI-enabled analytics. They emphasize strong prioritization, business-focused communication skills, and appointing deputies to scale leadership, speed decision-making, and sustain operational resilience.
read more →

Cybersecurity Stress Driving Burnout and Employee Loss

🧠 New survey shows cybersecurity roles are causing widespread stress and burnout. Object First polled 500 IT and security professionals and found 84% feel uncomfortably stressed and 78% fear being personally blamed after incidents. The pressure is pushing many to seek new jobs, worsening staffing shortages and increasing organizational risk. Recommended actions include building a blame-free culture, reducing alert noise, and investing in mental-health and resilience resources.
read more →

Organizational Risk Culture Standard for Cybersecurity

🛡️ The Organizational Risk Culture Standard (ORCS) provides a practical framework to turn cyber intentions into daily behavior that reduces silence, speeds detection and improves decision-making. It stresses that most cyber failures stem from cultural drift—not code—especially in VUCAD (volatile, uncertain, complex, ambiguous, digitized) environments. The article translates ORCS into ten actionable dimensions, outlines a five‑level maturity path and prescribes measurable KCIs and a first 90‑day plan leaders can use to embed lasting habits.
read more →

Cybersecurity Skills Trump Headcount in the AI Era

🛡️ ISC2’s 2025 Cybersecurity Workforce Study of 16,029 professionals finds that skills shortages have overtaken headcount as the primary concern for security teams. Budget constraints leave 33% of respondents unable to adequately staff and 29% unable to afford skilled hires, while 88% reported at least one incident linked to skills gaps. The report highlights rapidly accelerating AI adoption—69% are at some adoption stage—and stresses capability development, targeted training, and realistic workload expectations over simple headcount increases.
read more →

Cyber Resilience Through Practical Security Training

🔒 Organizations face an escalating threat landscape and an expanding cyber skills gap that compliance-focused training cannot close. Platforms like Cybrary, in partnership with Check Point Infinity Global Services, emphasize role-based, hands-on learning—combining industry certifications, simulated labs, and tailored learning paths to better prepare security teams for incident response, SOC operations, and threat hunting. This practical approach strengthens resilience by enabling measurable skills and reducing real-world vulnerabilities.
read more →

Cybersecurity Needs Diverse Skills Beyond Traditional STEM

🔐 Samantha Stallings argues that cybersecurity benefits from a wide range of backgrounds and talents, not just traditional STEM training. She challenges common stereotypes — the lone hacker or the inevitable technical prodigy — and shows how many roles contribute to effective threat research. Drawing on her own path from art school to Technical Writing Manager and referencing examples such as Dr. Sian Proctor, Stallings emphasizes that writers, marketers, product managers, and social media professionals all have valuable places in security teams. The piece is a direct invitation for nontechnical professionals to consider careers in cybersecurity.
read more →

Positive Thinking for Security Leaders: 6 Mindsets to Drop

🔒 The article argues that cybersecurity succeeds when practitioners replace damaging mindsets with sustainable ones. It highlights six common but harmful beliefs—security as a destination, security only for specialists, the idea that security always gets harder, treating security as a product, assuming criminals control priorities, and chasing perfect metrics—and explains how each fosters burnout and reactive behavior. The author recommends reframing security as a continuous, shared discipline embedded in daily operations and development lifecycles to improve resilience and team cohesion.
read more →

Check Point Launches AI Security Training Courses Globally

🔐 Infinity Global Services (IGS) has launched its first dedicated AI security training courses, the initial release in a growing AI services portfolio. The programs offer expert-led instruction and hands-on labs to help security teams, developers, and leaders defend against AI-driven threats and implement AI securely across operations and product development. IGS also plans upcoming offerings in AI red teaming, governance, and implementation consulting to extend defensive and advisory capabilities.
read more →

Caring for the Future: Youth Views on AI and Learning

🤖 The Future Report, based on responses from over 7,000 European teenagers, finds young people largely optimistic and adept at using AI and algorithmic platforms in daily life. Many report educational benefits—47% say AI explains complex topics, and 81% of users feel it improved aspects of learning or creativity—while also expressing concerns about over-reliance, trust, and skill erosion. The report calls for strengthened digital literacy, age-appropriate experiences, and youth participation in shaping responsible AI design.
read more →

Young Europeans' Views on AI and the Digital Future

📘 The Future Report, produced with youth consultancy Livity, surveyed over 7,000 teenagers (13–18) across France, Greece, Ireland, Italy, Poland, Spain and Sweden about their digital lives and expectations. It finds that 40% use AI daily or almost daily and that 81% of users report AI improved aspects of learning or creativity. Teens are largely optimistic yet express concerns about over-reliance, skill erosion and information trustworthiness. The report recommends stronger digital literacy, safety measures and meaningful youth participation in design and policy.
read more →

CISA Joins OPM CyberCorps® Scholarship for Service

🔒 CISA announced participation in the Office of Personnel Management’s CyberCorps® Scholarship for Service (SFS), offering internship and postgraduate career pathways to eligible scholarship recipients. With OPM adding 100 new SFS internship roles, CISA will place undergraduate selectees in time-limited excepted service appointments and may offer full-time excepted service positions to postgraduates. The initiative is intended to develop a skilled federal cybersecurity workforce and accelerate leadership in national cyber defense.
read more →

Cruise Line Bans Smart Glasses to Prevent Covert Recording

🕶️ MSC Cruises has added smart glasses and similar wearable devices to its list of prohibited items in public areas, citing the risk of covert recording and security exposures. The new rule means devices such as Ray‑Ban Meta or Google Glass may be confiscated by ship security if used in restricted spaces. The line argues that smart glasses are harder for bystanders to notice than phones or cameras, increasing privacy concerns. Critics counter the ban restricts helpful features like translation and accessibility.
read more →