
Cybersecurity Today Final Encore Episode - Research, Cybersecurity Awareness and Training
Jan 3, 2026
Michael Joyce, CEO of the Human-Centric Cybersecurity Partnership and PhD candidate, and David Shipley, CEO of Beauceron Security, delve into the intricacies of cybersecurity training. They discuss the decay of vigilance after training, the impact of awareness programs, and the difference between clicking and reporting phishing attempts. Insights include optimal training frequencies, the importance of ongoing feedback, and caution against sensational claims about training efficacy. Their research promotes a blend of technical and behavioral approaches to enhance cybersecurity culture.
AI Snips
Chapters
Transcript
Episode notes
Taco Bell 'Alcatraz' Gotcha Training
- David told a viral example of a Taco Bell-themed phishing simulation that led to three hours of punitive training.
- He warns such heavy-handed 'gotcha' approaches are abusive and counterproductive for morale.
Reporting And Clicking Follow Different Curves
- Reporting and clicking are different behaviours with different decay curves and motivations.
- Michael Joyce shows reporting probability falls over months while clicking risk increases on a separate timeline.
Always Close The Feedback Loop
- Close the feedback loop when employees report suspected phishing so reporting feels valuable to them.
- Automated responses and contextual feedback dramatically increase reporting rates and sustain motivation.
