Cybersecurity Today

Final Encore Episode - Research, Cybersecurity Awareness and Training

Jan 3, 2026
Michael Joyce, CEO of the Human-Centric Cybersecurity Partnership and PhD candidate, and David Shipley, CEO of Beauceron Security, delve into the intricacies of cybersecurity training. They discuss the decay of vigilance after training, the impact of awareness programs, and the difference between clicking and reporting phishing attempts. Insights include optimal training frequencies, the importance of ongoing feedback, and caution against sensational claims about training efficacy. Their research promotes a blend of technical and behavioral approaches to enhance cybersecurity culture.
Ask episode
AI Snips
Chapters
Transcript
Episode notes
ANECDOTE

Taco Bell 'Alcatraz' Gotcha Training

  • David told a viral example of a Taco Bell-themed phishing simulation that led to three hours of punitive training.
  • He warns such heavy-handed 'gotcha' approaches are abusive and counterproductive for morale.
INSIGHT

Reporting And Clicking Follow Different Curves

  • Reporting and clicking are different behaviours with different decay curves and motivations.
  • Michael Joyce shows reporting probability falls over months while clicking risk increases on a separate timeline.
ADVICE

Always Close The Feedback Loop

  • Close the feedback loop when employees report suspected phishing so reporting feels valuable to them.
  • Automated responses and contextual feedback dramatically increase reporting rates and sustain motivation.
Get the Snipd Podcast app to discover more snips from this episode
Get the app