
Cybersecurity Today Final Encore Episode - Research, Cybersecurity Awareness and Training
Jan 3, 2026
Michael Joyce, CEO of the Human-Centric Cybersecurity Partnership and PhD candidate, and David Shipley, CEO of Beauceron Security, delve into the intricacies of cybersecurity training. They discuss the decay of vigilance after training, the impact of awareness programs, and the difference between clicking and reporting phishing attempts. Insights include optimal training frequencies, the importance of ongoing feedback, and caution against sensational claims about training efficacy. Their research promotes a blend of technical and behavioral approaches to enhance cybersecurity culture.
AI Snips
Chapters
Transcript
Episode notes
Awareness Month Helps But Can Reduce Reporting
- Cybersecurity Awareness Month changes organizational behaviour but has mixed effects on reporting.
- October sees fewer clicks but also fewer reports, suggesting possible awareness saturation or fatigue.
Use Monthly Simulations And 90-Day Reinforcement
- Run phishing simulations at a frequency that balances learning and fatigue; David Shipley's data shows monthly cadence performs best.
- Pair sims with proactive training interventions every 90 days to sustain vigilance.
Taco Bell 'Alcatraz' Gotcha Training
- David told a viral example of a Taco Bell-themed phishing simulation that led to three hours of punitive training.
- He warns such heavy-handed 'gotcha' approaches are abusive and counterproductive for morale.
