Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Endpoint

Why Most Security Awareness Training Fails (And What To Do About It)

100%
0%

BLACK HAT USA 2017 -- Arun Vishwanath, associate professor at the University at Buffalo and faculty associate at Harvard University's Berkman Klein Center, visits the Dark Reading News Desk to discuss the need for better cybersecurity awareness "diagnostics." Vishwanath says training often tries to apply the same cure to every ailment then blames the patient when the treatment doesn't work.

Watch the full, two-day Dark Reading News Desk show and all 45 interviews at DarkReading.com/DRNewsDesk.

Learn from the industry’s most knowledgeable CISOs and IT security experts in a setting that is conducive to interaction and conversation. Click for more info and to register.

Comment  | 
Print  | 
Comments
Newest First  |  Oldest First  |  Threaded View
Joe Stanganelli
50%
50%
Joe Stanganelli,
User Rank: Ninja
8/27/2017 | 9:40:11 AM
Re: First and last line of defense ..... and yet
Fear is another motivator. It doesn't have to be a refund invoice. It could be a bill or a warning or some such thing. It could also be an updated HR policy. Something that would hold just enough interest rather than something that stands out as extraordinary.

After all, for many checking their email, anything that's not obvious spam is going to stand out as extraordinary.
REISEN1955
50%
50%
REISEN1955,
User Rank: Ninja
8/25/2017 | 2:58:47 PM
First and last line of defense ..... and yet
People still open up a jpg file or a pdf invoice partly because they are curious to see what it does.  If this simple rule of email was really observed, infections would go way down.  Human nature however, is a very powerful thing indeed.  Greed too.  That refund invoice for $375 from the Liberty Wine company.  That is far less obvious that the emails about $7,203,230 from a late relative now held in the Bank of Nigeria.  

We're human after all.
COVID-19: Latest Security News & Commentary
Dark Reading Staff 8/3/2020
Pen Testers Who Got Arrested Doing Their Jobs Tell All
Kelly Jackson Higgins, Executive Editor at Dark Reading,  8/5/2020
New 'Nanodegree' Program Provides Hands-On Cybersecurity Training
Nicole Ferraro, Contributing Writer,  8/3/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
Special Report: Computing's New Normal, a Dark Reading Perspective
This special report examines how IT security organizations have adapted to the "new normal" of computing and what the long-term effects will be. Read it and get a unique set of perspectives on issues ranging from new threats & vulnerabilities as a result of remote working to how enterprise security strategy will be affected long term.
Flash Poll
The Changing Face of Threat Intelligence
The Changing Face of Threat Intelligence
This special report takes a look at how enterprises are using threat intelligence, as well as emerging best practices for integrating threat intel into security operations and incident response. Download it today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-15479
PUBLISHED: 2020-08-07
An issue was discovered in PassMark BurnInTest through 9.1, OSForensics through 7.1, and PerformanceTest through 10. The driver's IOCTL request handler attempts to copy the input buffer onto the stack without checking its size and can cause a buffer overflow. This could lead to arbitrary Ring-0 code...
CVE-2020-15480
PUBLISHED: 2020-08-07
An issue was discovered in PassMark BurnInTest through 9.1, OSForensics through 7.1, and PerformanceTest through 10. The kernel driver exposes IOCTL functionality that allows low-privilege users to map arbitrary physical memory into the address space of the calling process. This could lead to arbitr...
CVE-2020-5412
PUBLISHED: 2020-08-07
Spring Cloud Netflix, versions 2.2.x prior to 2.2.4, versions 2.1.x prior to 2.1.6, and older unsupported versions allow applications to use the Hystrix Dashboard proxy.stream endpoint to make requests to any server reachable by the server hosting the dashboard. A malicious user, or attacker, can se...
CVE-2020-13376
PUBLISHED: 2020-08-07
SecurEnvoy SecurMail 9.3.503 allows attackers to upload executable files and achieve OS command execution via a crafted SecurEnvoyReply cookie.
CVE-2020-15907
PUBLISHED: 2020-08-07
In Mahara 19.04 before 19.04.6, 19.10 before 19.10.4, and 20.04 before 20.04.1, certain places could execute file or folder names containing JavaScript.