Positive Reinforcement & Gamified Security Awareness | Interview with Craig Taylor

Dejan Kosutic:

Welcome to Secure and Simple Podcast. In this podcast, we demystify cybersecurity governance compliance with various standards and regulations and other topics that are of interest for consultants, CISOs and other cybersecurity professionals. Hello, I'm Dejan Kosutic, the CEO at Advisera and the host of Secure and Simple Podcast. Today my guest is Craig Taylor, and he's the CEO and co founder at CyberHoots, a cybersecurity awareness training company, and they have more than a 100,000 users on their platform. And Craig actually has both a CISSP and a psychology degree, so he takes care to actually put all of these things together when he creates cybersecurity training programs.

Dejan Kosutic:

So in today's podcast, you'll learn about what are the best practices when companies go for cybersecurity awareness. Welcome to the show, Craig.

Craig Taylor:

Thanks for having me, Dejan. It's great to be here. Really appreciate the opportunity.

Dejan Kosutic:

Great to have you here. So tell me, from your experience, what what are the biggest myths that companies have or cybersecurity professionals have around cybersecurity awareness?

Craig Taylor:

I think the first and biggest myth is that the way to stop clicks from people clicking on links in emails or clicking on things on their desktop that they shouldn't or on website links, this sort of thing. The way to stop that is to punish it and to make it a public offense where users are hauled up in front of HR or their managers and they're told you failed this test, the one our IT team sent, or you clicked on a link, you shouldn't have, how dare you. And for for twenty five years, I think the cybersecurity industry has mis aligned with bigger punishments, more effective punishments, public shame, and public embarrassment of employees with these fake email phishing tests to the inbox, that has to be the biggest mistake of the entire industry for the simple fact that psychology, and remember my degree is in that, has never once proven that punished behaviors are eliminated. People stop performing things because they've been punished for it. What is true and what has always been true from a psychology perspective is that positive reinforcement of a behavior, rewarding a behavior, tends to increase its performance.

Craig Taylor:

It gets repeated over time and it has a very complicated thing that is basically the simplest explanation is punishment is an external focus, and the user says, I might not get punished if I click, or this is really appealing if I click, and I don't have to change my behaviors because I might not get caught. When it's a reward, you think about rewards like a slot machine. Oh, if I pull this arm a couple more times on a slot machine, I might get the reward. I'm gonna keep playing until I do or poker or gambling or what have you. Those are powerful, powerful.

Craig Taylor:

They create addictions, in fact, where people continue to perform behaviors because there's this reward expectation down the road. So when you build a cybersecurity program, the biggest myth is punishing behaviors is what you could you need to do to stop the clicks when, in fact, rewarding understanding and educating oneself on the rubric of what phishing is and what the indicators of a phishing email are. Teaching that, rewarding that will internalize so people continue to do those things.

Dejan Kosutic:

I guess a lot of people wouldn't agree with you, but anyway, let's dig into this a little bit deeper. So what are these, let's say, rewarding things that you think are actually driving positive behavior?

Craig Taylor:

So the things that are driving positive behavior are creating an experience that is not deception based. Right? We all agree as cybersecurity professionals, maybe you do as well, that teaching people how phishing works will be the key to avoiding people clicking on phishing links. Right? If if you teach someone how phishing works with urgency, authority, emotionality to get people to react to something without clearly thinking through the problem, that is one of the key differences between someone that clicks on a link and doesn't.

Craig Taylor:

If they understand, oh, if I get something as urgent, emotional, or authority based, I don't immediately do anything. I have to pause and assess and report. PAR is a little acronym, P A R, pause, assess, report. That helps people understand what they need to do and maybe learn a little bit more about the motivations and the methodologies of hackers. If instead what you're doing is you're sending these fake phishing emails by your IT department or your MSP or your MSSP to the end user, And it's, I've seen five or six of these on Reddit threads recently where people are up in arms.

Craig Taylor:

They are very upset. One was I clicked on the link that said we got a day off in my company. Everyone's overworked. We're all tired. AI is overwhelming us, and we all wanted this day off.

Craig Taylor:

So we all clicked on it, and it was a phishing email. And our disappointment was palpable. We were so upset. And everyone had to then get assigned a thirty minute video. Black Hat briefing last year said the average person will watch that thirty minute video for ten seconds before they walk away from their desk in disgust, in frustration, in anger over the deception based email that tricked them in their inbox.

Craig Taylor:

Another was a change in dress code. Another was a Christmas bonus. You could go down the list of phishing emails that have gone so far off the deep end and are so egregious as to have people quit the company. I don't wanna be in a culture where I have to be fearful of every email my IT department sends me and and that sort of thing because I don't know how to determine whether an email is safe or not. I'm just told click on nothing.

Craig Taylor:

And that is a that is a basically a blinders approach where we're not any how about the people that do URL obfuscation? We're gonna not share the actual URL in our emails that get sent to the inbox. We're hiding them from our end users because we don't trust them. Well, that just dumbs it down even further. Right?

Craig Taylor:

Those things have been proven not to work. In fact, they've been proven to lead to more clicks, not fewer clicks. There was a study out of the University of Zurich in 2020, 10,000 people, they clicked more often on real phishing attacks than less often after training. And the 2025 black hat study was the ten seconds and a 1.7% difference from a baseline group of people who had no training with the fake messages. And all the ones that did have training, there was a 1.7% difference between the two.

Craig Taylor:

It has no effect. So if you don't believe my statements about it, then believe the science.

Dejan Kosutic:

But let's go back to this email, to this example of this email for a free day off. Why do you think that these kind of emails are wrong?

Craig Taylor:

Well, they don't teach anything. They alienate the end users, so the end users get very upset about the experience of a deception based email, meaning they're in a state of mind where training them at that moment or even in close proximity does not work. They abandon the training. And it doesn't teach anything about the rubrics you need to know to learn fishing. All it does was is measure what you know already.

Craig Taylor:

It does not teach what you don't know, and it puts you into a non teachable state.

Dejan Kosutic:

Don't you think that hackers would actually try to think about these kind of emails, which are, let's say, very highly likely for someone to click on them?

Craig Taylor:

Yes, I do agree. The examples that we're using are designed. So the IT person, right? How can I convince my users that they have to be more careful? I can send these really fake, really believable fake messages because I know a hacker will send it.

Craig Taylor:

And in some cases, they take a phishing email that was sent to some person and they recreate it for their other users to experience. Everyone has the right intentions in their heart where they wanna protect the company and they wanna teach the end user. But these are not teaching exercises, Dejan. They're measurements of what people already know or do not know. When you send that message, you have to be certain that the users have been properly trained in a positive reinforcement way with gamification to encourage friendly competition within the company so that everyone wants to do it with leader the C suite, the leaders of the company see, oh, we're falling way down at the bottom of the list because we haven't been doing our training.

Craig Taylor:

And that kicks in their competitive juices. And so the leadership of a company starts doing the exercises that phishing, teach them exactly how phishing works, not the videos necessarily, not the fake messages sent to the inbox. Those are measurements. Right? Those things have to happen first before you run a test, which is your free day off.

Craig Taylor:

And people who have been properly trained will not get disgusted and upset. They will know exactly how to tell that this is a fake message and they'll report it. So it's it's it's like this. Let me put you in another scenario for a moment. All you people listening to this, you might be just out of school or you've been to university or have you at least had high school.

Craig Taylor:

When you get into a class, let's say it's a year long class on genetics, does the professor start you off with, hey, folks, open your books, put your put your textbook away, open your, your, your quiz, the the the spot final exam that I've put on your desk. We're gonna measure how much of information you don't know about genetics because this is our first baseline test. We wanna know just how little you know. And then at the end, we're gonna have another final exam and we'll see how much you've learned. That's how most organizations run fake email phish testing.

Craig Taylor:

They send out a baseline when they adopt a new product to see how many people they can trick and click and get high, high click rates. And then they justify the purchase by reducing those click rates over time, but it's still not teaching people the correct information. It's a it's a dumbed down domain name, which you can't in you can't send a microsoft.com email from Microsoft about a password reset because they'll sue you as a vendor. We know we've been sued three times by the IRS and Facebook and and Meta and, and one other Zoom for impersonating their domain names in these fake email messages.

Dejan Kosutic:

So what What you're saying is that basically these these kind of emails, you could send them, but you have to teach people first what what is a good or bad behavior, and then you can actually start sending these kind of testing emails. Is this what you're saying?

Craig Taylor:

I'm saying that to an extent, but you have to still consider it a final exam. In other words, you need to train, train, train, train, train for six, seven months at a time, and then send a test, a midterm or a final exam. Then you continue to memorize and rote practice these phishing exercises. We have something called Hootfish that runs you through seven points of an email, and it says the sender, the subject, the greeting, the spelling, the language quality, the links, the attachments. And this teaches a rubric, and it's not a deception based in the inbox of an email client.

Craig Taylor:

It's in a browser window where we tell you this is your examination. This is your practice. It's like going to the gym three times a week for six months before you go to the weight lifting competition to show off your muscles. It's all the practice and the repetition that prepares you for the final exam. You don't run a final exam every single week for months on an end and then pair it with failed videos.

Craig Taylor:

When you fail the test, you take a video. Because when people fail, Dejan, they are not willing to learn in that moment and they tend to disengage.

Dejan Kosutic:

Okay, understood. So you mentioned a couple of interesting concepts there, and I'd like to kind of visit all of them. So one of the things that you mentioned is that you're saying that companies should teach their employees how phishing works. Are you basically explaining, I mean, showing them exactly the whole process of how hackers are actually creating these phishing messages, or what actually are you showing there?

Craig Taylor:

So I think it's not a view Let's take a step back and talk about cybersecurity in an aggregate level. There's a lot of scams out there. There's financial scams, there's phishing emails, and there's pushing QR code scams. There's SMS scams. We've all gotten that text that said our toll violation is up, and you're gonna get fined.

Craig Taylor:

All of these things are different flavors of the same thing. Social engineering to get you to do something. And so we have to go back to basics with our employees. We have to create a culture where it's safe and it's, culturally the norm to raise your hand and ask questions, to report things maybe by mistake where it's a legitimate request, but you thought it was a phish and get feedback. Those positive experiences alongside exercises, and we do this in the browser in in the positive reinforcement kind of way.

Craig Taylor:

Just like in a classroom, you get teachers who engage the students, spark the interest, get these positive little wins along the way before they send out the final exam. All of those things are meant designed to get engagement, to get learning of the rote the the base skill set before you test because it makes no sense to test or to punish people when they haven't properly been trained. Another analogy might help here. You can train a dog with a shock collar, Dejan, and you can train a dog with treats. Which would you prefer if you're the dog, and which would you prefer if you're the owner of the dog?

Craig Taylor:

Both are the treats. The dog will bring you the leash to say, let's go do some fun things at the dog park when they're treat based, and they'll go to a corner and curl up and hide when it's shock based. We are focused too heavily on shocking our employees when they make mistakes, and it creates a culture of disengagement, of I give up. In fact, I talked to a PhD gentleman not too long ago, and he said, Craig, I've been cited twice in my company for clicking on the fake messages my IT department sent me. I'm a PhD.

Craig Taylor:

I'm smart. I'm a sharp guy, and I do care about making mistakes, but I don't feel I've been properly trained. So what I do now is I forward everything to IT. I've given up trying to learn and avoid these things. I just forward it all to IT.

Craig Taylor:

I abdicate responsibility. I want IT to solve this. This is an IT problem, isn't it, Craig? I'm like, it's actually not that complicated. I'll say his name is John.

Craig Taylor:

And John, it's not that complicated. You just need to learn this little rubric that we teach. And if you learn these things, you should be able to spot 90% of the phishing. There's about 10% that are business email compromise where the tips are not the same.

Dejan Kosutic:

Okay, Craig, but let's try to be concrete here. So you're speaking about this positive approach and positive reinforcement. So does this come down only to learning about what they need to actually understand about phishing, or is this also something else? So what exactly does this positive reinforcement come down to?

Craig Taylor:

Well, creates a safe environment for learning where people are not afraid to engage, to ask questions, to report things correctly, incorrectly. We had an event just on Friday of last week, Dejan, where an employee at one of the companies receiving positive reinforcement stuff, they clicked on a link from a Zoom meeting, or it was a Teams meeting actually. They've been talking to a party for tax completion. They're a CPA firm for a number of weeks, two or three weeks, and they finally said, let's meet to figure this out. And the other party who was the hacking person or individual couldn't join the Zoom meeting that the company the CPA firm sent out, and so offered up a Teams meeting at the last possible moment.

Craig Taylor:

And the CPA person said, okay. Well, you can't get on my Zoom. Let's try your Teams. It makes sense. Came in as teams.microsoft.com, but it was hiding a rippling link.

Craig Taylor:

Rippling is a remote management tool that helps deploy software to company environments. And the CPA person clicked on the link, made a mistake. He shouldn't have. He had, unfortunately, the administrative rights on his local workstation to install the remote access tool that Rippling pushed down, which was another version of ConnectWise. There was a couple of other tools pushed in.

Craig Taylor:

And the employee recognizing from his training, maybe I shouldn't have clicked the link because he clicked it four different times and it didn't work. He escalated it. He reported it. At the same time, the monitoring systems of choice were alerting that something was being blocked. An incident was called.

Craig Taylor:

This happened at about 02:00 on a Friday afternoon. Because the individual is not afraid of the repercussions, what we do see on companies where there is a lot of shame and punishment about mistakes made on links and you have to go through remedial training and three clicks and failures and you're fired and all the negativity that goes with that, the bigger and stronger punishments, people are more reticent to report their mistakes. They just hope it will go away. Right? Nothing happened at the moment, so I'll just be quiet.

Craig Taylor:

He did not. He reported it. We had an incident. We saw this install happen. We'd started an incident.

Craig Taylor:

And we were able to contain and recover and revise from that very, very quickly. So the experience is when you have a culture where it's safe to report, it is not a punishment for failure. It is a reward for doing the right thing where there's gamification, positive reinforcement of educational experiences that are not deception based in the inbox as much as they're more, educational based in a browser window, through an analysis of various emails that have been identified and walking through them. And then practice, practice, practice, you get this muscle memory like, I made a mistake. I gotta let them know.

Craig Taylor:

Let's see what happened. And and it gets reported. So you have better culture. You have a better experience, a better experience for the end users. I I can tell you in those five other cases in Reddit threads that I've read, people are ready to quit over the fake messages and the punishment and the devious schemes that they've been receiving.

Craig Taylor:

You can go and there's hundreds of those threats, not just five, but literally hundreds.

Dejan Kosutic:

And how do you actually make a change in, let's say, companies' processes and in companies' culture to actually be open to reporting these kind of incidents and not actually punishing their employees? It's not only, I would say, one person's decision, it's much more than that, right?

Craig Taylor:

Yeah, it is. It starts from the, it is both grassroots and also top down. You have to recognize the science behind this, right? When you look at psychology education, these have done a great job of researching and reporting on behavior changes in humans. If you want to look at psychology, they've they've done multiple studies that say rewarding behaviors repeats them, that gamification added to rewarding behaviors makes people engage more.

Craig Taylor:

So you have higher percentages of employees participating in these trainings. Because let's face it, everyone is overwhelmed with things to do. Everyone is busy. But when you see yourself at position 16 out of 16 employees or 445 out of 500 employees, and you're a leader at that company, and your way to getting up that leaderboard, which might be anonymous, we don't recommend it being a public leaderboard because that's shameful, But a private leaderboard, I can tell you from firsthand experience that when we introduced leaderboards at my company within their learning management platform, the senior level employees who were always at the bottom started doing their assignments because they could not be last at anything. And they started to climb the leaderboards even though they were anonymous.

Craig Taylor:

So when you build the proper psychology, gamification, reward structure into play. And then there's little subtle things that you can do that are very easy. Right? You can have HR or you can have different divisions compete with each other to see who could get the highest compliance between sales, marketing, support, development, and and maybe throw a pizza party for the highest ranking, highest highest compliance teams because you're rewarding the behaviors that you want to see more of. I forget if it was the Oracle of Omaha, who said, show me the incentives and I'll tell you what the behaviors will be.

Craig Taylor:

Isn't that a fair statement? Right? If you incentivize people to engage and to get high compliance and to complete these educational assignments, you're going to get better understanding, better reporting, better compliance, better culture. It's a win, win, win, win for the employee, for the division, for the business, for whatever that company produces, their clients will benefit from fewer breaches, fewer downtime. And be careful with what the incentives are.

Craig Taylor:

You can take this in some of the wrong directions, right? Because when you send out fake emails, you can reward reporting and everyone will just start reporting more and more and more, and your IT team will be overwhelmed with emails to look at, no, this isn't a fish. Why did you say so? No, that and if so you can go too far in different directions. You have to be careful.

Dejan Kosutic:

And your this gamification that you mentioned is is very interesting. So does the gamification come down to these leaderboards or is there anything else to gamification?

Craig Taylor:

Great question. I love that. Have you played any video games or computer games where you rank up over time? You get to level one, then to level two, then level three. And there's a gamification there where the higher levels give you more resources.

Craig Taylor:

They give you better character, blah, blah, blah. We've built gamification into our platform. And I think this has to be built into any learning management system where the individuals at the beginning are given an avatar, let's say, a baby owl in a nest. And as they complete assignments, they graduate to another level, and that owl looks more mature. And eventually the owl might get armor.

Craig Taylor:

Maybe they get a sword or a staff. Maybe they get a fancy helm on top of it as they climb the ranks. So there's this gamification idea within any training or learning management system where you create levels and you have people who are higher ranked because they've completed more assignments at a quicker pace with better outcomes. Maybe on time versus late, you get points, same as in school. When you look at the education system, there's a lot of things you can learn.

Craig Taylor:

If you turn in an assignment at university late, you get a doc, 5% penalty, 10% penalty. The same can be built into your gamification system. And so when you have those leaderboards and a friendly social aspect, we have the ability for you to add, like, five different people to your group of financial officers, and you can see their ranks as compared to you. That creates a little healthy, friendly competition inside that division that has everybody doing it the moment it launches because they get more points. So you get better uptake.

Craig Taylor:

Those are all just psychological phenomenons that lead to this becomes a bigger priority than answering the seventy seventh email in your inbox today because this one gets me higher rankings. This gets me rewards. This gets me positive recognition at the company all hands meeting. You can call out the perfect performers. You can give gift cards to the winners of the drawing, the random drawing, that sort of thing.

Craig Taylor:

Maybe you get a day off. I mean, honestly, take that negative story about a fake day off and give everyone that's at a 100% compliance in your learning management system a free day off in the year. What a low cost, amazing, way to turn a bad story into a good story.

Dejan Kosutic:

When creating these cybersecurity awareness programs, should this all come down to some kind of an online, let's say, learning through videos, through gamification and everything else? Or should there be also some live events or some other methods to actually teach people what they can and what they cannot do? I think it's all additive. Benefits, right? It's like if you

Craig Taylor:

go to the gym two times a week, you're gonna get in pretty good shape after the course of six, nine, twelve months. But if you do three times a week, you'll be in better shape a little quicker, right? But if you do six times a week, you're gonna hurt yourself and you're gonna be set back and you won't go to the gym because you'll give up. Right? Or here's the other big analogy.

Craig Taylor:

I love the gym analogy because many companies come to me and say, we took all of our employees to the gym on January 15 and we put them there for twelve hours of workout, and that was our annual training on cybersecurity. Right? Like, that's gonna be enough. No one's gonna get hurt. They're all gonna be super smart about all the cyber things, and they're gonna remember for twelve months.

Craig Taylor:

It doesn't work that way. No different than if on January 1, get a gym membership, you go for four hours, and you pull every muscle in your body, and you quit. That's what happens.

Craig Taylor:

So it has to be practiced. And you raise a really good point. This accounting firm that I talked about with this one targeted employee who had multiple phone calls with a hacker and then got on a Zoom, which wasn't a Zoom. It was a it was a Teams that wasn't as Teams. It was, you know, downloading malware.

Craig Taylor:

That story needs to be told in the next team meeting at that company. We had a targeted attack here, gentlemen and ladies. This person had three conversations over three weeks about coming on board our company as a new client. And then there was this subtle switcheroo of vendor Teams meetings from our Zoom meeting. And in the heat of getting onto a call that we were ten minutes late, we didn't look at the link properly, this is a story we all need to know.

Craig Taylor:

So you share that story with people. And so that's very important. And then you also encourage the reporting of events and that there's no negative outcomes if you make a mistake reporting because we want you to tell if you see something, say something. That's a military thing, but it works in businesses as well.

Dejan Kosutic:

Yep. And from your experience and experience working with clients, how often what's, let's say, the the best timing for showing these learning programs to learning materials to

Craig Taylor:

That's great. The Well, the state of the art, which is what we talked about earlier about trying to share with your employees is what we know is people's attention spans have gone from hours to minutes to almost seconds. So you cannot do even one hour training videos, thirty minute training videos, we just stay way away from that. We see the best engagement, memorization, or really understanding at about the two to three minute mark for videos, nothing longer. Because people will cheat.

Craig Taylor:

I swear to God, they will sit down and start a five minute video and go get a coffee in the morning. And when they come back, they'll try to answer the questions. If you make it two minutes and you make it fun, entertaining, not doom and gloom, then people actually look forward to watching these videos. There's a vendor, not us, who got a famous person. I don't know if it's Richie Fallon, Jimmy Fallon, or some other famous comedian to do videos for them.

Craig Taylor:

I'm like, that's brilliant. People wanna hear a famous person talking about cybersecurity even though it sounds bad. Like if they can make it entertaining and fun, people will pay attention. And then they'll remember in the moment, oh, Jimmy Jimmy Fallon said, don't click that link, right, because of the remember how funny that was? So those are all kind of the key things around its repetition.

Craig Taylor:

It's very short. It's monthly, if not more than that. Like, I would do we do once a month video, once a month hoot fish, which is the phishing simulation in the browser where people think through the five or six or seven parts of an email, and they have to choose safe or unsafe. And then they pass the test. It's open book if you don't remember what it's about.

Craig Taylor:

You just keep doing that once a month, once a month, once a month. We have very, very good outcomes where the companies in the platform versus the companies not in the platform at some MSPs we've measured are much lower risk of breach, much lower risk of incidents, right?

Dejan Kosutic:

Yeah, and it's actually a very interesting question. What kind of KPIs should companies measure? And actually the example that you're doing, actually having two test groups, right? And then you actually measure the difference. You can actually show the ROI there.

Craig Taylor:

Yeah, was a study someone else did at the Black Hat Conference in 2025. They measured a health care provider in The United States that had 10,000 employees, and they put a control group aside, say, 100 employees who got no training. And then they put multiple other groups, control group, BCD, and they delivered multiple variable. How often they do the fake email phishing test paired with videos, fake email phishing test, no videos, videos only, and then they measured outcomes. And they said that basically, because of the lack of and there's another thing that I haven't seen a study on, to be perfectly frank, but watching a video and translating it to steps in the inbox of checking a sender and this the translation is to reading, and those two mediums don't always translate very well.

Craig Taylor:

People watch things and they miss they're watching a wheel on a bus that should be turning, not turning in the video, not the words or the message that's audibly just you know, hearing it and then doing it. So I I think videos have a place, but they're not as good as looking at an actual email on a on a browser window and looking through the indicators and choosing and thinking through the problem each time when you know it's not a time based test, it's not a pressure cooker of 75 other things to do, that's much better. So I think those are some of the best practices there is to do the training in a multimodal fashion. Positive reinforcement, short repetition is key with multiple like in person sharing stories, storytelling is amazing. That's some of it.

Craig Taylor:

I'm sorry, I may have got off topic with you.

Dejan Kosutic:

Okay. But going back to measurement and metrics, do you see as the best practices for metrics related to security awareness?

Craig Taylor:

Well, when you have a positive reinforcement program and it's based on gamification, those sorts of things, One of the metrics is compliance. Are you doing your assignments and are you doing them on time? And are you getting high enough scoring? Like, don't require perfect scores to pass the test. Some of our companies have asked us to set it set the bar at perfection.

Craig Taylor:

We don't think that's wise. We think that's got a little bit of a negativity to it because a person might not understand the experience, and they in our tool, you have to go through it again if you don't pass the passing score. So if you get through three, four, five, six, seven times you failed it, something else is wrong. You're not understanding the test measurement. So we want to make sure people have help when they get to that scenario.

Craig Taylor:

But compliance is number one. We also have a reporting button. Many of the tools on the market have a report phish button, which goes to the IT team and they say, in our case, it's automatically measured against the fake message. Because our test our tooling, at our company and almost every tool out there has the ability to send these fake messages as a final exam kind of measurement. So reporting a legitimate fake email is another measurement. Just don't make it the focus of all measurements. Then you could also do an employee survey like, do you feel well prepared while trained to spot and avoid phishing attacks? You could get some employee feedback on how is this training doing in your perspective as an end user. I don't think there's enough of that done, to be honest.

Craig Taylor:

Seeing because I I my heart of hearts, I I've been doing this a long time, thirty years. My heart of hearts says if people's affect, how they feel about the training they're getting, is it effective? Is it helpful? Is it knowledge given? Is it short?

Craig Taylor:

Is it know, all of these different measurements that are sort of soft measurements are positive, then that person will take those messages and internalize them with an intrinsic locus of control, meaning I have control over this situation because I understand it. You've taught me how to fish, feeding me for a lifetime of secure, confident, efficient email processing because I understand and know how phishing works. The alternative is to feed you a fish today to hope you don't click today. Maybe you'll click tomorrow, but we'll feed you a fish tomorrow, and then hopefully you don't click tomorrow. And it's all a negative there's a negative feedback loop, but you're still hungry every day because you're not learning how it works.

Craig Taylor:

That's another thing. So I guess level of competency with the gamification as you climb the leaderboards and climb the status boards, you're proving over time that you've done well on your assignments. There's another measurement. Measurement. Outside of that, you can run a final exam once a year because you need to tell your staff, hey, you better pay attention and do all your assignments because we will have a final exam.

Craig Taylor:

Every student knows that final exam is coming. If I skip too many classes, I'm not going to be prepared for the final exam. So you should run once a year phishing tests of the attack kind. I call it attack phish phish because you're attacking your end users from a trusted party. That erodes a little bit of trust unless you've prepared them properly for it.

Craig Taylor:

Right? Then it's okay. So there is a click rate measurement that you can add to it as well.

Dejan Kosutic:

But use it spare. Yep, definitely. Okay. How do you see that security awareness will look like in, let's say, three years, five years from now?

Craig Taylor:

Wow. Last week there was a Five Eyes advisory from five governments, The US, Canada, UK, New Zealand, Australia. They all got together because they've seen what the frontier AI models can do from a penetration perspective. There's new frontier models that haven't been released like Mythos, Claude Mythos, Microsoft Emdash, that can be pointed at just about any software on the market and find zero days in it, exploit it, and or get the person into that software and that environment. So the five I said, listen, you have months, not years, to protect yourself, to prepare yourself.

Craig Taylor:

And so we we have a consulting business as well. We put together a readiness assessment. And I say what what the world will look like in a year, I couldn't tell you. From an AI development perspective, it's getting so accelerated at improving itself through iterating on the like, they've just thrown so much power and practice to the AI models that they're accelerating their advancement. So things are gonna change quite rapidly.

Craig Taylor:

I mean, I could throw some crazy Jetson like things at you. Nobody on this will know if you're not 50 what Jetsons are. So there's you know, there might be robots in every home in five years that are doing the laundry and cooking and stuff like that. It's possible. But from a security perspective, we have a bit of a storm in front of us, and then we should have relative calm because we have all this tech debt where we've produced software with bugs in it so for so long.

Craig Taylor:

We have to find all those bugs and fix them with the AI tools that are coming onto the market. And during that time, we'll have more breaches. But after we find the bugs and we start releasing code that is much better prepared for the world with very much fewer bugs in it, very, very many fewer zero days because we're using the same AI models to text test the software before it's released to public. That's the calm after the storm. So we have this little three month or four month window before a storm hits where we're gonna see a lot more breaches, a lot more outages.

Craig Taylor:

We could have infrastructure outages. We could have banking breaches. Gosh forbid. God forbid that happens. Hopefully, it doesn't.

Craig Taylor:

We have some major upheaval. But I think after that big storm, which we all we will get through. No problem. No question in my mind. We'll get through it.

Craig Taylor:

Might take us eighteen months. Might take us twelve or sixteen or, you know, who knows, two years. Then it will be relatively calm, and things will return to a better normal baseline than ever before. Outside of that, I I don't I can't I can't tell you. A human you know, what I what I do know is this, that the human mistakes will still then become the biggest, problem we all face after the storm is over and we're releasing much more secure code.

Craig Taylor:

We'll have to go back to the basics, which is convincing you to let me in through a trick. Right? Social engineering with a phishing email or an SMS text or some other means because the zero days will go away again largely.

Dejan Kosutic:

Yeah. This is very insightful about the next twenty four months. It's going to be very, very exciting and very different from what we have now. Okay. To wrap up the discussion, what are your, let's say, top suggestions for companies when they build their awareness programs?

Craig Taylor:

Stop punishing your users. You know, I don't think punishing a child when they make mistakes or have a temper tantrum stops the temper tantrums. Punishing a dog doesn't make them wanna learn more tricks. Use treats for children, for dogs, for employees. Make the employee want to participate by adding gamification in.

Craig Taylor:

That takes engagement with a positive re system of, you know, not deception based testing initially. Save that for the last test. But build positive reinforcement in, rewards, and then gamification takes it up another lot notch. Leaderboards gets all the people that you want participating participating. All of these positive things are happening, then call them out publicly with a Give managers the flexibility to give out, you know, a free lunch or a gift card or something positive to publicly reward the high performers who are at high compliance and whose, avatars have advanced the most in the game, right, so that there's an incentive for everyone to do well at this cyber literacy stuff.

Craig Taylor:

Because the alternative, which we're all trying to avoid, is a breach on a Friday afternoon of a long weekend and ransomware and twenty five years of your legal files being released to the Internet contacting those people in recovery, finding twenty five years of companies, good luck. You won't be able to find them to tell them their data was stolen. The alternatives are just not very nice, and I see it on both sides every day.

Dejan Kosutic:

Okay. Great. Thanks for for these insights, Craig. It's it's been a pleasure talking to you.

Craig Taylor:

You too. It was my pleasure to be here. Thank you so much for, being able to hopefully move cybersecurity off of its punishment and shame and in a better direction.

Dejan Kosutic:

Thanks again and thank you everyone for listening or watching this podcast and see you again in two weeks time in our new episode of Secure and Simple Podcast. Thanks for making it this far in today's episode of Secure and Simple Podcast. Here's some useful info for consultants and other professionals who do cybersecurity governance and compliance for a living. On Advisera website, can check out various tools that can help your business. For example, Conformia software enables you to streamline and scale ISO 27,001 implementation and maintenance for your clients.

Dejan Kosutic:

White label documentation toolkits for NIS2, DORA, ISO 27,001 and other ISO standards enable you to create all the required documents for your clients. Accredited Lead Auditor and Lead Implementer courses for various standards and frameworks enable you to show your expertise to potential clients. And a learning management system called Company Training Academy with numerous videos for NIS2, DORA, ISO 27,001 and other frameworks enable you to organize training and awareness programs for your clients workforce. Check out the links in the description below for more information. If you like this podcast, please give it a thumbs up, it helps us with better ranking and I would also appreciate if you share it with your colleagues.

Dejan Kosutic:

That's it for today, stay safe!

Creators and Guests

person
Host
Dejan Kosutic
CEO at Advisera & Cybersecurity governance expert
Positive Reinforcement & Gamified Security Awareness | Interview with Craig Taylor
Broadcast by