Guarantees
Our post

Resources and Insights

The latest cyber security news, interviews, technologies, and resources.
A Positive Security Awareness Training Program Reduces Insider Cyber Threats
Educational

A Positive Security Awareness Training Program Reduces Insider Cyber Threats

The vast majority of employees do their level best to exercise due diligence and protect a company’s digital assets. However, many employees lack the necessary training, and The effectiveness of security awareness training efforts is largely dependent on how employees perceive the program. If staff members view it as another task that reduces their productivity and leads to more stress, they are likely to treat it like an unwelcome chore. That’s why positive employee attitudes are the bedrock of successful cybersecurity programs.
JOSHUA CRUMBAUGH
JOSHUA CRUMBAUGH
April 18, 2024
2022 Election Cyber Security
Educational

2022 Election Cyber Security

The approach of the US election season is a good time to reflect on cyber threats to our political process, particularly from foreign state adversaries due to their vast resources, advanced capabilities, and malign intent. Cyber threats to our election system also come from other sources, such as hacktivists and criminal organizations, but while they too can create problems, they are not on the same scale or level of competence as those posed by autocratic states like China, Russia, and Iran.
GREGORY SIMS
GREGORY SIMS
April 18, 2024
Top 5 Cognitive Biases Used by Social Engineers
Educational

Top 5 Cognitive Biases Used by Social Engineers

Phishing attacks are a common form of cybercrime that rely on psychological manipulation to trick victims into giving away sensitive information or funds. These attacks often use cognitive biases, which are mental shortcuts that people use to make decisions quickly and easily. Here are the top five cognitive biases used in phishing attacks, along with examples of what the phish might look like for each bias.
JOSHUA CRUMBAUGH
JOSHUA CRUMBAUGH
April 18, 2024
2023 CyberSecurity Predictions: An Escalation of Cyber Warfare
Cyber News

2023 CyberSecurity Predictions: An Escalation of Cyber Warfare

The threat from nation state threat actors will loom much larger in 2023 as the gloves come off between the market-based democracies and authoritarian adversaries like China, Russia, and Iran. Up to now the narrative about cybersecurity has mostly centered on criminal threats. Next year will bring greater attention to state-conducted and state-sponsored cyber espionage efforts and infrastructure attacks.
GREGORY SIMS
GREGORY SIMS
April 18, 2024
Punishment to Partnership: Improve Your Phishing Simulations
Educational

Punishment to Partnership: Improve Your Phishing Simulations

One of the most common features of phishing simulations within the enterprise is landing pages that are designed to determine if users will type in their credentials. At first glance, this might seem like a good idea for identifying vulnerable employees. However, it’s actually a form of exploitation that can lead to a punitive culture within the organization.
CRYSTAL FONTAINE
CRYSTAL FONTAINE
April 18, 2024
You better watch out. Holiday Cyber Grinches are about.
Educational

You better watch out. Holiday Cyber Grinches are about.

Cyber crime is on a historic rise this year, and that means you and your employees are also more vulnerable than ever to emerging cyber threats. This Cyber Monday, making sure your workforce, remote and otherwise, understand online shopping safety basics should be a top cybersecurity priority for your organization. According to February 2022 Gallup survey, 42% of US employees have a hybrid work schedule, and 39% work entirely from home, increasing the odds that your employees are doing more online shopping on-the-clock than ever before.
JOE LAHART
JOE LAHART
April 18, 2024
Social Engineering: The Modern Hacker’s Toolset
Educational

Social Engineering: The Modern Hacker’s Toolset

Social engineering refers to any attempt made by one bad actor to influence another person to do something. In the case of cyber security, social engineering is commonly used as a tactic to gain access to systems or credentials that allow the hacker to carry out a malicious cyber attack. If you are a frequent internet user, you must have encountered some intriguing pop-ups on your browser or notifications in your email like “congratulations, you just won an iPhone. Click here to claim,” which tries to lure you into interacting with corrupted links. These are a basic form of social engineering where a hacker is trying to impersonate a trusted source in order to have you give them your information or to have you access their trapped website.
JOSHUA CRUMBAUGH
JOSHUA CRUMBAUGH
April 18, 2024
2023 CyberSecurity Predictions: AI vs AI – The Future of Cybersecurity
Cyber News

2023 CyberSecurity Predictions: AI vs AI – The Future of Cybersecurity

One of the biggest trends in cybersecurity expected in 2023 is the rise of AI-driven phishing attacks. These attacks are particularly dangerous because they use artificial intelligence to create customized, highly targeted messages that are designed to trick individuals into giving away sensitive information or clicking on malicious links.
JOSHUA CRUMBAUGH
JOSHUA CRUMBAUGH
April 18, 2024
The Lucifer Effect: Understanding the Roots of Toxic Cybersecurity Culture
Educational

The Lucifer Effect: Understanding the Roots of Toxic Cybersecurity Culture

Explore the toxic culture within the cybersecurity industry, identify factors fueling this mindset, and discover strategies for promoting positive change, including the adoption of innovative tools!
JOSHUA CRUMBAUGH
JOSHUA CRUMBAUGH
April 18, 2024
The Cost of a Data Breach
Educational

The Cost of a Data Breach

Data breaches are becoming increasingly common occurrences, but they are also increasingly expensive. According to a recent report by IBM and the Ponemon Institute, the average cost of a data breach was estimated to be $3.86 million in 2020. This includes recovery costs, disruption to business operations, and reputational damage, as well as myriad other financial losses. Companies should strive to protect their data and information assets in order to avoid such a costly event.
JOSHUA CRUMBAUGH
JOSHUA CRUMBAUGH
May 9, 2024
Cyber Insurance Premiums: A Changing Landscape of Risk Assessment
Educational

Cyber Insurance Premiums: A Changing Landscape of Risk Assessment

Defending against cyberattacks appears to be trending in favor of hackers as the growing number of phishing attacks trick employees into downloading malware or clicking on a malicious link. That’s why companies of every size would be well-served to improve their cybersecurity awareness training and secure an affordable cyber insurance policy.
JOSHUA CRUMBAUGH
JOSHUA CRUMBAUGH
May 9, 2024
From Wrong Number to Romantic Nightmare: The Shocking Scam That's Claiming New Victims Every Day
Educational

From Wrong Number to Romantic Nightmare: The Shocking Scam That's Claiming New Victims Every Day

🚨scam alert! 🚨 Wrong number texts are leading to a sinister scheme called pig butchering, where scammers use love as a weapon to manipulate and financially devastate victims. 💔💸 Our latest blog post exposes the shocking truth behind these scams and provides essential tips to protect yourself. 🛡️ #wrongnumbertextscam #pigbutcheringscam #scamawareness
JOSHUA CRUMBAUGH
JOSHUA CRUMBAUGH
May 9, 2024
Why Your Security Awareness Program is Failing: The Behavioral Science Perspective
Educational

Why Your Security Awareness Program is Failing: The Behavioral Science Perspective

Want to know why your cybersecurity awareness training isn't working? It's time to ditch the boring, check-the-box approach and embrace behavioral science. By leveraging principles like spaced learning, psychological safety, cognitive load, growth mindset, and situated learning, you can create training that actually sticks. And don't forget the power of gamification – it's not just fun and games, it's a serious tool for driving engagement and retention. Ready to take your training to the next level? Check out our latest blog post, "Why Your Security Awareness Program is Failing: The Behavioral Science Perspective," and learn how to build a culture of security, one behavior at a time. 🔒💡 #cybersecurity #behavioralscience #gamification
JOSHUA CRUMBAUGH
JOSHUA CRUMBAUGH
April 30, 2024
A Positive Security Awareness Training Program Reduces Insider Cyber Threats
Educational

A Positive Security Awareness Training Program Reduces Insider Cyber Threats

The vast majority of employees do their level best to exercise due diligence and protect a company’s digital assets. However, many employees lack the necessary training, and The effectiveness of security awareness training efforts is largely dependent on how employees perceive the program. If staff members view it as another task that reduces their productivity and leads to more stress, they are likely to treat it like an unwelcome chore. That’s why positive employee attitudes are the bedrock of successful cybersecurity programs.
JOSHUA CRUMBAUGH
JOSHUA CRUMBAUGH
April 18, 2024
2022 Election Cyber Security
Educational

2022 Election Cyber Security

The approach of the US election season is a good time to reflect on cyber threats to our political process, particularly from foreign state adversaries due to their vast resources, advanced capabilities, and malign intent. Cyber threats to our election system also come from other sources, such as hacktivists and criminal organizations, but while they too can create problems, they are not on the same scale or level of competence as those posed by autocratic states like China, Russia, and Iran.
GREGORY SIMS
GREGORY SIMS
April 18, 2024
Top 5 Cognitive Biases Used by Social Engineers
Educational

Top 5 Cognitive Biases Used by Social Engineers

Phishing attacks are a common form of cybercrime that rely on psychological manipulation to trick victims into giving away sensitive information or funds. These attacks often use cognitive biases, which are mental shortcuts that people use to make decisions quickly and easily. Here are the top five cognitive biases used in phishing attacks, along with examples of what the phish might look like for each bias.
JOSHUA CRUMBAUGH
JOSHUA CRUMBAUGH
April 18, 2024
Punishment to Partnership: Improve Your Phishing Simulations
Educational

Punishment to Partnership: Improve Your Phishing Simulations

One of the most common features of phishing simulations within the enterprise is landing pages that are designed to determine if users will type in their credentials. At first glance, this might seem like a good idea for identifying vulnerable employees. However, it’s actually a form of exploitation that can lead to a punitive culture within the organization.
CRYSTAL FONTAINE
CRYSTAL FONTAINE
April 18, 2024
You better watch out. Holiday Cyber Grinches are about.
Educational

You better watch out. Holiday Cyber Grinches are about.

Cyber crime is on a historic rise this year, and that means you and your employees are also more vulnerable than ever to emerging cyber threats. This Cyber Monday, making sure your workforce, remote and otherwise, understand online shopping safety basics should be a top cybersecurity priority for your organization. According to February 2022 Gallup survey, 42% of US employees have a hybrid work schedule, and 39% work entirely from home, increasing the odds that your employees are doing more online shopping on-the-clock than ever before.
JOE LAHART
JOE LAHART
April 18, 2024
Social Engineering: The Modern Hacker’s Toolset
Educational

Social Engineering: The Modern Hacker’s Toolset

Social engineering refers to any attempt made by one bad actor to influence another person to do something. In the case of cyber security, social engineering is commonly used as a tactic to gain access to systems or credentials that allow the hacker to carry out a malicious cyber attack. If you are a frequent internet user, you must have encountered some intriguing pop-ups on your browser or notifications in your email like “congratulations, you just won an iPhone. Click here to claim,” which tries to lure you into interacting with corrupted links. These are a basic form of social engineering where a hacker is trying to impersonate a trusted source in order to have you give them your information or to have you access their trapped website.
JOSHUA CRUMBAUGH
JOSHUA CRUMBAUGH
April 18, 2024
The Lucifer Effect: Understanding the Roots of Toxic Cybersecurity Culture
Educational

The Lucifer Effect: Understanding the Roots of Toxic Cybersecurity Culture

Explore the toxic culture within the cybersecurity industry, identify factors fueling this mindset, and discover strategies for promoting positive change, including the adoption of innovative tools!
JOSHUA CRUMBAUGH
JOSHUA CRUMBAUGH
April 18, 2024
The Power of Warm Fuzzies: Elevating Your Cybersecurity Culture with Positive Relationships
Educational

The Power of Warm Fuzzies: Elevating Your Cybersecurity Culture with Positive Relationships

Explore the importance of positive relationships in fostering a strong security-conscious culture within the cybersecurity industry and learn how tools like PhishFirewall can empower employees with tailored education and simulations.
JOSHUA CRUMBAUGH
JOSHUA CRUMBAUGH
April 18, 2024
The Human Side of Insider Threat Management: Why Mental Health Matters
Educational

The Human Side of Insider Threat Management: Why Mental Health Matters

Explore the importance of addressing mental health in insider threat management and learn how PhishFirewall's AI-driven platform creates an empathetic work environment while improving your organization's security posture.
JOSHUA CRUMBAUGH
JOSHUA CRUMBAUGH
April 18, 2024
Redefining Cybersecurity Training: Why Fear Tactics Need to Go
Educational

Redefining Cybersecurity Training: Why Fear Tactics Need to Go

Explore the importance of positive reinforcement in cybersecurity training and learn how companies like PhishFirewall cultivate a positive culture, empowering employees to combat cyber threats and thrive in an increasingly challenging digital world.
JOSHUA CRUMBAUGH
JOSHUA CRUMBAUGH
April 18, 2024
The Power of Ego Bias: How It Can Compromise the C-Suite's Cybersecurity
Educational

The Power of Ego Bias: How It Can Compromise the C-Suite's Cybersecurity

Learn how AI-driven and AI-customized training programs can help organizations mitigate the impact of ego bias in the C-Suite, fostering a proactive security culture and safeguarding cybersecurity.
JOSHUA CRUMBAUGH
JOSHUA CRUMBAUGH
April 18, 2024
Understanding Social Engineering: Staying Safe from Human-activated Threats
Educational

Understanding Social Engineering: Staying Safe from Human-activated Threats

Learn about different types of social engineering attacks and practical tips for improving awareness and protection!
JOSHUA CRUMBAUGH
JOSHUA CRUMBAUGH
April 18, 2024
Unleash Your Inner Superheroes: The Power of the Heroic Imagination in Cybersecurity
Educational

Unleash Your Inner Superheroes: The Power of the Heroic Imagination in Cybersecurity

Discover the concept of the heroic imagination and its relevance to cybersecurity, exploring tips for empowering employees as digital superheroes while addressing potential pitfalls and challenges.
JOSHUA CRUMBAUGH
JOSHUA CRUMBAUGH
April 18, 2024
What is a Phishing Simulation and How do I Simulate Phishing Tests?
Educational

What is a Phishing Simulation and How do I Simulate Phishing Tests?

Improve your organization's cybersecurity posture by incorporating PhishFirewall's comprehensive phishing simulation and security awareness training solutions, designed to stop over 99% of phish clicks within six months.
JOSHUA CRUMBAUGH
JOSHUA CRUMBAUGH
April 18, 2024
Leveraging AI-Powered Solutions for Smarter Security Awareness Training
Educational

Leveraging AI-Powered Solutions for Smarter Security Awareness Training

Discover how artificial intelligence (AI) can revolutionize security awareness training by making it more adaptive, engaging, and effective in today's evolving cybersecurity landscape.
JOSHUA CRUMBAUGH
JOSHUA CRUMBAUGH
April 18, 2024
Building Your Digital Immunity: Why Security Awareness Training is Crucial
Educational

Building Your Digital Immunity: Why Security Awareness Training is Crucial

Learn why security awareness training is crucial for building your digital immunity, protecting against cyber threats, and fostering a culture of security within your organization.
CRYSTAL FONTAINE
CRYSTAL FONTAINE
April 18, 2024
The Sneaky Mind Tricks Behind Social Engineering: Cognitive Biases & How To Prevent Them
Educational

The Sneaky Mind Tricks Behind Social Engineering: Cognitive Biases & How To Prevent Them

A fun deep dive into the top cognitive biases that social engineers love to exploit, complete with examples and tips on how to outsmart them. So buckle up, and let's uncover the secrets of the social engineering world!
JOSHUA CRUMBAUGH
JOSHUA CRUMBAUGH
April 18, 2024
 The Perils of AI-Driven Phishing: Understanding, Detecting, and Defending
Educational

The Perils of AI-Driven Phishing: Understanding, Detecting, and Defending

Learn about the various types of phishing attacks, the role of AI in enhancing their effectiveness, and valuable tips for detecting and defending against these advanced cyberthreats in our comprehensive guide. Stay informed and protect your sensitive information from AI-driven phishing attacks.
JOSHUA CRUMBAUGH
JOSHUA CRUMBAUGH
April 18, 2024
How Do Phishing Simulations Contribute to Enterprise Security?
Educational

How Do Phishing Simulations Contribute to Enterprise Security?

Learn how phishing simulations serve as an effective training tool to increase employee awareness, reduce human error, and strengthen your organization's overall cybersecurity posture against growing phishing threats.
JOSHUA CRUMBAUGH
JOSHUA CRUMBAUGH
April 18, 2024
The Top 10 Secrets to Effective Phishing Simulations
Educational

The Top 10 Secrets to Effective Phishing Simulations

Phishing simulations play a crucial role in helping companies defend against cyber attacks by providing a safe environment for employees to learn how to identify and respond to phishing attempts. In this comprehensive guide, we explore the top 10 strategies for effective phishing simulations, including focusing on education, communicating the purpose, customizing simulations, praising non-clickers, monitoring progress, offering immediate feedback, encouraging reporting, conducting frequent simulations, using realistic simulations, and analyzing trends. By implementing these tactics, organizations can significantly improve their cybersecurity posture and better protect themselves from potential attacks. With PhishFirewall's fully autonomous AI-driven platform, companies can take their phishing and security awareness training to the next level, ensuring their employees are well-equipped to handle the ever-evolving landscape of cyber threats.
JOSHUA CRUMBAUGH
JOSHUA CRUMBAUGH
April 18, 2024
How Gamified Security Training Empowers Employees to Outsmart Cybercriminals
Educational

How Gamified Security Training Empowers Employees to Outsmart Cybercriminals

Explore the importance of security awareness training in the digital age and discover how gamified security training, like PhishFirewall, can effectively engage employees, improve knowledge retention, and strengthen an organization's cybersecurity posture.
JOSHUA CRUMBAUGH
JOSHUA CRUMBAUGH
April 18, 2024
Why the 'You Can't Patch Stupid' Mindset is a Cybersecurity Hazard
Educational

Why the 'You Can't Patch Stupid' Mindset is a Cybersecurity Hazard

The "you can't patch stupid" mindset in cybersecurity is a dangerous and false belief that human error is unpreventable. This article debunks this myth and highlights the importance of continuous education, awareness, and a positive security culture in mitigating cyber threats.
JOSHUA CRUMBAUGH
JOSHUA CRUMBAUGH
April 18, 2024
Unzipping a New Era of Cybersecurity Threats: The '.zip' Domain
Educational

Unzipping a New Era of Cybersecurity Threats: The '.zip' Domain

This comprehensive article explores phishing and deceptive URL use in cybercrime, with a spotlight on Google's newly introduced .zip and .mov domains. It includes analysis of domain registration data, potential misuse of new domains, and offers phishing prevention best practices. The piece is a critical read for anyone seeking to understand the evolving landscape of cybersecurity threats.
JOSHUA CRUMBAUGH
JOSHUA CRUMBAUGH
April 18, 2024
Kindness as a Strategy: A New Approach to Security Awareness
Educational

Kindness as a Strategy: A New Approach to Security Awareness

It's time to revolutionize security awareness programs by embracing the Carrot-First approach, which focuses on positive reinforcement, empathy, and respect. This methodology fosters collaboration, shared responsibility, and a culture of security that nurtures learning and behavior change. By ditching punitive methods and prioritizing kindness in cybersecurity training, organizations can create a more effective and resilient security culture.
JOSHUA CRUMBAUGH
JOSHUA CRUMBAUGH
April 18, 2024
Revolutionizing Digital Learning: NoLMS AI Driven Methodology Explained
Educational

Revolutionizing Digital Learning: NoLMS AI Driven Methodology Explained

The landscape of education and training is ripe for change, and NoLMS, with its AI-driven, personalized, and engaging approach to learning, is poised to lead this revolution.
JOSHUA CRUMBAUGH
JOSHUA CRUMBAUGH
April 18, 2024
Question Everything: Redefining Cybersecurity Training with Wendy Nather and Joshua Crumbaugh
Cyber News

Question Everything: Redefining Cybersecurity Training with Wendy Nather and Joshua Crumbaugh

Wendy Nather, a cybersecurity leader, joins PhishFirewall CEO Joshua Crumbaugh to tackle some of the biggest gaps in security awareness. They examine why traditional training often fails, the transformative impact of role-based and AI-driven training, and why users should be viewed as assets rather than weak links. Wendy shares insights from research showing that organizations with targeted, role-specific training see far better outcomes. They also discuss the importance of creating an open environment where employees feel empowered to report security concerns.
JOSHUA CRUMBAUGH
October 30, 2024
Adapting to AI-Driven Threats: Dr. Joshua Scarpino’s Take on Cybersecurity
Cyber News

Adapting to AI-Driven Threats: Dr. Joshua Scarpino’s Take on Cybersecurity

In this episode of Phishing for Answers, Dr. Joshua Scarpino, CISO of TrustEngine, discusses the future of security awareness training. He highlights the importance of personalized, bite-sized training sessions and adapting to AI-driven cyber threats. Dr. Scarpino emphasizes the need for ongoing, relevant training that ties both to employees’ roles and personal lives to create a lasting culture of security. Learn how TrustEngine’s approach mirrors the key strategies that PhishFirewall brings to the table, ensuring your team is always one step ahead of evolving threats.
JOSHUA CRUMBAUGH
October 24, 2024
I Swear I’m Your CFO (Send That Dough)
Cyber News

I Swear I’m Your CFO (Send That Dough)

In a world full of phishing scams and fake requests, “I Swear I’m Your CFO” brings some much-needed humor to an all-too-common scam: the fake boss asking for gift cards. This hilarious and catchy tune teaches listeners a critical cybersecurity lesson—if your CFO is asking for gift cards, it’s definitely NOT your CFO!
JOSHUA CRUMBAUGH
October 19, 2024
The Human Firewall: Building a Culture of Cyber Vigilance
Cyber News

The Human Firewall: Building a Culture of Cyber Vigilance

In this episode of Phishing for Answers, Joshua Crumbaugh interviews Marcos Marrero, CISO of H.I.G. Capital, to discuss the unique security challenges in private equity and how his team has developed a culture of vigilance. Marrero shares a story about a sophisticated fake data room scam targeting their firm, emphasizing the importance of continuous security awareness and employee empowerment. Key takeaways include turning employees into “human firewalls,” fostering a “see something, say something” culture, and simplifying security communication for non-technical stakeholders. PhishFirewall’s AI cyber coach aligns with these principles by providing continuous, role-based training and phishing simulations to strengthen security both in the workplace and in employees’ personal lives.
JOSHUA CRUMBAUGH
October 17, 2024
Building a Proactive Security Culture with James Phillips
Cyber News

Building a Proactive Security Culture with James Phillips

In this episode, James Phillips, Principal Consultant at SAPCG, delves into the importance of role-based training and how AI automation is transforming cybersecurity awareness. He discusses the growing sophistication of phishing attacks and how PhishFirewall’s zero-campaign management and AI-driven cyber coach provide a customized and friendly training experience. With micro-training sessions that are less than a minute long, PhishFirewall is the TikTok of cybersecurity awareness, ensuring that employees stay engaged and protected with minimal disruption to their workflow.
JOSHUA CRUMBAUGH
October 11, 2024
The Evolution of Phishing: Personalized Attacks on Your Business Units
Cyber News

The Evolution of Phishing: Personalized Attacks on Your Business Units

In this episode, Christopher Russell, CISO of tZERO Group, explains how attackers are shifting from mass phishing attempts to highly targeted, personalized attacks that mimic normal business communications. Russell emphasizes the importance of role-based training, fostering a supportive security culture, and using phishing simulations to build trust within organizations. Discover how to protect your teams from this new wave of phishing threats and keep your business secure.
JOSHUA CRUMBAUGH
October 10, 2024
Strengthening Security Culture with Steve Cobb, CISO of Security Scorecard
Cyber News

Strengthening Security Culture with Steve Cobb, CISO of Security Scorecard

Join us as Steve Cobb, CISO of Security Scorecard, shares insights on the human side of cybersecurity, building a strong security culture, and tackling insider threats. Don’t miss his expert take on fostering engagement and resilience in today’s evolving threat landscape. #Cybersecurity #InsiderThreats #SecurityCulture #PhishFirewall
JOSHUA CRUMBAUGH
October 9, 2024
The Importance of Empathy in Security Awareness: Insights from Tim Dzierzek, CISO of Aya Healthcare
Cyber News

The Importance of Empathy in Security Awareness: Insights from Tim Dzierzek, CISO of Aya Healthcare

Tim Dzierzek, CISO of Aya Healthcare, shares why employees are the real assets in your defense, how empathy drives better phishing simulations, and why AI-powered, role-specific training is the future of security awareness. Listen to this episode of Phishing for Answers for practical insights on building a human-centered security culture.
JOSHUA CRUMBAUGH
October 9, 2024
If We're Laughing, We're Learning: Mike Crandall’s Unconventional Approach to Cybersecurity
Cyber News

If We're Laughing, We're Learning: Mike Crandall’s Unconventional Approach to Cybersecurity

In this episode of Phishing for Answers, Mike Crandall shares his journey from military service to leading cybersecurity initiatives for small to mid-sized businesses. Mike reveals some of the most interesting phishing tests he’s run, including one where a city employee clicked a link three times a day for a week, trying to claim a gift card! With a background in building secure networks for the Department of Defense, Mike discusses the challenges of building a security culture in organizations, the role of phishing simulations, and the importance of role-based training. He emphasizes the need to change the way we treat users, turning them from the “weak link” into the first line of defense. Whether you’re looking to improve your security awareness programs or better understand how to engage employees in cybersecurity, this episode is packed with practical advice and real-world stories.
JOSHUA CRUMBAUGH
October 3, 2024
Social Engineering and the Human Factor: Why Cybersecurity Must Evolve
Cyber News

Social Engineering and the Human Factor: Why Cybersecurity Must Evolve

In this episode of "Phishing for Answers," Kip James, a cybersecurity expert at the Bureau of Reclamation, shares his journey from the early days of technology as a hobbyist to becoming a seasoned CISO. With over four decades of experience, Kip provides valuable insights on building a culture of security, the human element in cybersecurity, the evolving role of AI, and effective strategies for phishing awareness and employee training.
JOSHUA CRUMBAUGH
October 2, 2024
Elevating Cybersecurity Awareness Training: Insights from Bob Fabien and Joshua Crumbaugh
Cyber News

Elevating Cybersecurity Awareness Training: Insights from Bob Fabien and Joshua Crumbaugh

This blog post recaps the conversation between Bob Fabien and Joshua Crumbaugh, focusing on the importance of human-centric training in cybersecurity. They discuss how behavioral science, micro-training, and simulations can effectively reduce phishing attacks and strengthen organizational defenses.
JOSHUA CRUMBAUGH
October 2, 2024
CMMC Level 2 Contractors: Protect CUI with These Critical Role-Based Training Tips
Cyber News

CMMC Level 2 Contractors: Protect CUI with These Critical Role-Based Training Tips

CMMC Level 2 compliance demands more than generic cybersecurity training—it requires role-specific training to tackle unique risks across your organization. Each department, from Helpdesk to Developers, faces distinct threats based on the data they handle. In this blog, we break down why role-based training is critical for CMMC compliance, focusing on key roles like SOC Analysts, Network Engineers, and HR personnel. We offer practical tips to ensure these roles are prepared to safeguard CUI and meet stringent security standards.
JOSHUA CRUMBAUGH
August 20, 2024
The Shocking Truth About Phishing: Why Good Employees Keep Falling for Scams
Cyber News

The Shocking Truth About Phishing: Why Good Employees Keep Falling for Scams

This blog post explores the concept of learned helplessness in phishing susceptibility, using the story of Mike, a diligent accountant, to illustrate how repetitive, unfair phishing training without feedback can lead even cautious employees to feel powerless and give up. The post argues that “gotcha” phishing simulations set employees up to fail, fostering disengagement rather than improving security awareness. The solution? Just-in-time training and gamification, which provide real-time, constructive feedback and make training both fair and engaging. This shift from punitive tactics to educational, empowering methods breaks the cycle of learned helplessness and strengthens employees’ phishing defenses. The post concludes with a call to action to adopt PhishFirewall’s innovative, automated approach to phishing training.
JOSHUA CRUMBAUGH
August 20, 2024
Understanding Darcula: The New Phishing-as-a-Service Threat
Cyber News

Understanding Darcula: The New Phishing-as-a-Service Threat

Discover how Darcula, a new phishing-as-a-service platform, is revolutionizing cybercrime with easy-to-use phishing kits and sophisticated tactics. Learn why businesses must enhance their security measures to combat this emerging threat and protect their sensitive data.
JOSHUA CRUMBAUGH
May 29, 2024
How AI is Transforming Cybersecurity – And Why You Can’t Afford to Ignore It
Cyber News

How AI is Transforming Cybersecurity – And Why You Can’t Afford to Ignore It

AI is revolutionizing cybersecurity, but it’s also empowering cybercriminals. This post explores how AI advancements by Apple and Microsoft highlight the urgent need for AI-driven defenses. Discover how PhishFirewall’s AI training prepares your team to stop sophisticated phishing attacks and stay ahead of AI-driven threats. Don’t wait—integrate AI into your cybersecurity strategy today!
JOSHUA CRUMBAUGH
May 22, 2024
Judgment Day for Government Agencies: AI-Powered Phishing Attacks on the Rise
Cyber News

Judgment Day for Government Agencies: AI-Powered Phishing Attacks on the Rise

🚨 URGENT ALERT 🚨 PhishFirewall has uncovered a massive surge in AI-powered Adobe Sign phishing attacks targeting state and local government agencies and law enforcement! 😱 These sneaky attackers are using advanced techniques like consent phishing to bypass MFA and gain access to sensitive data. 🕵️‍♂️ Don't let your organization fall victim to these convincing scams! 🛡️ Read our latest blog post to learn how PhishFirewall's can help you stay one step ahead of the bad guys. 💪 #PhishFirewall #AdobeSignPhishing #ConsentPhishing
JOSHUA CRUMBAUGH
May 10, 2024
The Phishing Scam That's Costing Companies Millions: Is Your Business Next?
Cyber News

The Phishing Scam That's Costing Companies Millions: Is Your Business Next?

🚨 New phishing threat alert! 🚨 Fake email chain attacks are costing companies millions, using perfectly spoofed emails that look like real conversations between executives and trusted partners. 😨 These attacks often rely on successful BEC attacks to lend credibility to their schemes, putting your organization at risk. 🕵️‍♂️ Learn more about this evolving threat and how to protect your business in our latest blog post, "The Dangerous Evolution of Phishing: How Fake Email Chains Are Tricking Employees and Stealing Millions." 📚 Don't wait until it's too late – read now and stay informed! 💡 #phishing #cybersecurity #securityawareness
JOSHUA CRUMBAUGH
May 3, 2024
The Surprising Connection Between Consent Phishing and Corporate Deep Fake Scams
Cyber News

The Surprising Connection Between Consent Phishing and Corporate Deep Fake Scams

🚨 Deep fakes are the new frontier of cybercrime, and your business could be next. 🚨 In our latest blog post, we reveal the shocking tactics scammers are using to impersonate CEOs and steal millions. 💰 Plus, we share expert strategies for spotting these sophisticated scams before they strike. 🕵️‍♂️ Don't wait – read "Deep Fakes: The New Frontier of Cybercrime and How to Spot Them" now and arm your employees with the knowledge they need to protect your organization. 🛡️ #deepfakes #cybersecurity #cybercrime
JOSHUA CRUMBAUGH
May 1, 2024
Okta Breach Reveals: It's Time to Hack the Human Psyche, Not Just Systems
Cyber News

Okta Breach Reveals: It's Time to Hack the Human Psyche, Not Just Systems

The recent Okta breach is a stark reminder that the battleground for cybersecurity is not just in the servers, but in the synapses of every employee's brain. 'You can't patch stupid' is a defeatist adage that our industry clings to, yet this breach shows the fallacy of such thinking. Our latest post delves into why a mindset shift is imperative, from outsmarting hackers to outsmarting our own behavioral pitfalls. We argue that the only real fix to the phishing scourge is a revolutionary change in organizational culture, powered by behavioral science. Join us as we explore how ethical hacking and culture change are the duo that can reclaim cybersecurity's future.
JOSHUA CRUMBAUGH
November 7, 2023
New York's Cybersecurity Law: A Deep Dive into Its Strengths and Shortcomings
Cyber News

New York's Cybersecurity Law: A Deep Dive into Its Strengths and Shortcomings

New York's financial sector is now governed by the Second Amendment to 23 NYCRR 500, a set of cybersecurity regulations. While the amendment introduces robust technical and procedural requirements, it notably overlooks the human element of cybersecurity. Behavioral science principles, such as cognitive load theory and spaced learning, emphasize the need for digestible, continuous training. Over 90% of breaches start with human error, yet regulations like this one sideline the human element. For cybersecurity measures to be truly effective, continuous security awareness training must be prioritized, ensuring that every individual is empowered with the knowledge and skills to combat cyber threats.
JOSHUA CRUMBAUGH
November 3, 2023
Consent Phishing: The Wolf in Sheep's Clothing
Cyber News

Consent Phishing: The Wolf in Sheep's Clothing

Consent phishing is a sneaky tactic where hackers pretend to be trustworthy apps or services to trick people into giving them permissions. Once they have these permissions, they can get into real cloud services and steal sensitive data. This post will explain what consent phishing is, how it works, and how to protect against it, with a focus on the innovative solutions provided by PhishFirewall.
JOSHUA CRUMBAUGH
November 2, 2023
Navigating the New NIST Training Guidelines: What You Need to Know
Cyber News

Navigating the New NIST Training Guidelines: What You Need to Know

Unpacking the NIST Cybersecurity Framework 2.0 Public Draft is like unboxing a new gadget—it’s the same but better. The proposed changes in the training requirements are subtle but pinpointed for clarity, trimming any room for misinterpretation. While most vendors miss the mark on role-based training, the new draft illuminates these gaps. Dive in to understand how these changes might be more significant than you think.
JOSHUA CRUMBAUGH
October 27, 2023
wormgpt: Combating AI-Driven BEC Attacks with AI-Powered Cybersecurity Solutions
Cyber News

wormgpt: Combating AI-Driven BEC Attacks with AI-Powered Cybersecurity Solutions

🚨 AI-driven BEC attacks are on the rise, with cybercriminals exploiting advanced tools like WormGPT to craft highly convincing phishing emails. Traditional security measures just won't cut it anymore. It's time to embrace PhishFirewall's innovative noLMS approach, gamified training, and AI cyber coaching to empower employees and stay ahead of these evolving threats. Let's redefine #cybersecurity training together! 💪 #PhishFirewall #BECattacks #AIDrivenCybersecurity
JOSHUA CRUMBAUGH
July 19, 2023
The Ch@ngeme! Conundrum: Strengthening Cybersecurity in Schools and Beyond
Cyber News

The Ch@ngeme! Conundrum: Strengthening Cybersecurity in Schools and Beyond

🚨 The Ch@ngeme! incident at a Michigan high school highlights the importance of cybersecurity awareness in schools & service providers. Top 5 best practices: 1️⃣ Strong password policies 2️⃣ Cybersecurity education for students & staff 3️⃣ Clear communication channels 4️⃣ Regular security assessments 5️⃣ Fostering a culture of security awareness
JOSHUA CRUMBAUGH
July 19, 2023
Pioneering Role-Based, Micro-Sized Cybersecurity Training for the Modern Workplace
Cyber News

Pioneering Role-Based, Micro-Sized Cybersecurity Training for the Modern Workplace

Discover PhishFirewall, the revolutionary cybersecurity training solution offering role-specific, time-efficient microlearning modules. Transform your team's cybersecurity awareness with our personalized, AI-enhanced approach. Make the switch to PhishFirewall. Redefine cybersecurity education in your organization.
CRYSTAL FONTAINE
June 15, 2023
Cybersecurity: Guardian or Tyrant? The Hidden Icebergs in Corporate Waters
Cyber News

Cybersecurity: Guardian or Tyrant? The Hidden Icebergs in Corporate Waters

Unchecked authority given to cybersecurity teams is a hidden iceberg posing potential threats to corporate harmony and functionality. Practices like punitive phishing simulations, imposing the 'my way or the highway' approach, fostering a superiority complex, and exploiting user trust can cause more harm than good. To foster a productive, respectful, and safe digital environment, organizations must balance their approach, allowing cybersecurity teams to serve as a collaborative force rather than an autocratic entity. PhishFirewall challenges these traditional practices, providing a non-punitive, gamified platform to create an atmosphere of continuous learning and mutual respect in the cyber realm, turning cybersecurity from a liability into an asset.
JOSHUA CRUMBAUGH
June 15, 2023
The AI Revolution: Transforming Customer Success in 2023
Cyber News

The AI Revolution: Transforming Customer Success in 2023

Explore the transformative role of AI in customer success in 2023. Learn how AI is reshaping business strategies and enhancing customer experience by predicting behavior, automating tasks, and extracting actionable insights from data.
CRYSTAL FONTAINE
June 7, 2023
Cybercrime Explosion: Navigating the PaaS Tsunami and the Lifeline of Security Training
Cyber News

Cybercrime Explosion: Navigating the PaaS Tsunami and the Lifeline of Security Training

Explore the challenges of rising cyber threats such as Phishing-as-a-Service and access brokers in our digital age. Discover the critical role of security awareness training and proactive defensive measures in combating these threats and ensuring a safe, secure digital ecosystem.
CRYSTAL FONTAINE
June 2, 2023
Photo Representing how secure Huntsville is

Huntsville: A Beacon for Cybersecurity

Huntsville is a hub of technology and innovation, making it a lucrative target for cybersecurity threats. Learn How Phishfirewall Helps!
Read post
Joshua's interview with Business Insight

Cyber Security Executive 2022 | Joshua Crumbaugh, PhishFirewall | Business Insight Group

Phishfirewall's CEO Joshua discusses current phishing trends with the Business Insight Group!
Watch Now
Photo of Phishing Attack

How AI and Machine Learning are Changing the Phishing Game

Joshua discusses how AI and machine learning are redefining how the industry looks at phishing.
Read post

Learn Why World Leading Advisory Firm, Frost & Sullivan, Recommends Phishfirewall!

Strengthen your Security Awareness Training with Frost & Sullivan's white paper! Gain insights on why training is more effective when you employ an AI-powered SAT program to protect your business. Download this essential resource today!
We care about your data, learn more in our privacy policy.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.