🔎 Stay up to date with the latest announcements from the SoSafe Community Team.
🗞️ Share and discuss the latest industry news, trends, and updates in cybersecurity.
Just joined? Say hello and introduce yourself! Connect with fellow newcomers and start building meaningful connections in the community. 💛
Share your knowledge and learn from others! Exchange valuable security best practices to stay informed and improve cybersecurity tactics. 🤝
📆 Stay informed about the latest community meetups and webinars, and share relevant industry events with your peers.
🎟️ Community hub for Signal 2026: connect with fellow attendees, join the conversations around the event, and share real-time community moments. More info: https://signal.sosafe-awareness.com/
Signal Watch | French tax authority (DGFiP) breach: ANSSI's post-mortem >> @channel Good luck with ECSM tomorrow, and because it always helps to have a recent story about cyber risk...
What happened: ANSSI (France's national cybersecurity agency) published its incident report on 29 Sept 2026 analysing the breach at the French Tax Authority earlier in the year. Over three months, the attacker collected the logins and passwords of several dozen tax agents, probably stolen by infostealers. ANSSI suspects that was via devices the DGFiP doesn't control, notably agents' personal computers.
Impact: Data from the E-Contact application covering nearly 353,000 individuals and 252,000 businesses, plus land registry data, was taken. Around 14 GB left over three months without the tax office or ANSSI raising the alarm.
Interesting detail: A session stayed open roughly sixteen hours after the password was reset. Also, in 2026, two tax portals with access to sensitive data still relied on just a username and password.
Lessons:
BYOD and personal-device hygiene is your risk to manage, even though it’s outside your perimeter. This is where awareness and education can make the difference.
IT Service desks need to remember to revoke sessions as well as resetting passwords.
Least privilege matters: ordinary agent accounts with no special rights gave access to large volumes of sensitive data.
Get a First Look at What’s Coming to Signal 2026
@channel Less than two months to go until we meet in Cologne on November 18 and there’s already a first taste of what’s waiting for us.
The official Signal 2026 trailer is out, giving us a glimpse of the people, conversations and ideas coming together this year.
From AI and cyber resilience to security culture, human behaviour and the realities of leading security teams, Signal 2026 brings together voices from across the security landscape for a full day of ideas, conversations and practical insights.
We’re already getting things started here in the Community, with more opportunities to connect, exchange and get ready for Signal together.
🎬 Watch the trailer below and get a first glimpse of Signal 2026.
And psst… we’ll be sharing something Community-exclusive right here in the upcoming days! 👀 Stay tuned. There’s more to come.
📢 European Cyber Security Month Is One Week Away @channel Every October, European Cyber Security Month (ECSM) puts security awareness front and center across organisations – a great moment to sharpen employees’ instincts against the threats that matter most right now. And the threat landscape is evolving fast. Attackers increasingly use the same AI tools we do, making scams more convincing and harder to spot. That’s why we’ve built a ready-to-use 4-week campaign kit to help you run a focused ECSM programme with your teams, covering phishing, voice scams, Shadow AI and deepfakes. 🗓️ The four weeks at a glance:
Week 1 – Phishing: spotting AI-generated phishing attempts
Week 2 – Voice Scams: recognising AI voice cloning and vishing
Week 3 – Shadow AI: safe use of AI tools at work
Week 4 – Deepfakes: identifying manipulated video/audio content
Each week includes a Scene Inspector challenge, a short game, and one practical rule employees can apply immediately. 🎮
What's included in the kit:
Ready-to-use assets for all 4 weeks
Email templates for weekly comms
Reporting template to track engagement
Recognition template to celebrate participation ⭐
📚 Want to go deeper? Our community ambassador Andrew R. put together a great 3-part series on running ECSM effectively:
💬 Your turn: How are you kicking off Cyber Security Month? Drop a comment and tell us what you've got planned, or share a creative idea you've already rolled out.
European Cyber Security Month - Measuring Success @channel It’s my final instalment of things to consider ahead of Security Awareness Month, so let’s tackle something meaningful - metrics. This month gives us some rare things: budget, attention, and a captive audience for four weeks, and the hard part isn't producing the content (we've done that for you here - sosafe-awareness.com/ecsm-2026) - it's proving it worked. Many of us finish the month with ticked communication objectives and an ‘engagement’ figure, but still can't answer the key question: did behaviour change 🤷? The challenges
💬 Engagement is not action. Page views, stand visits, and quiz completions tell you people were exposed to content, not that they did anything differently afterwards.
⌛ The measurement window is short. A month of content won't produce a month of measurable behaviour change - culture shifts show up over a longer horizon, well after the campaign team has moved on.
🤔 Self-reported confidence is unreliable. It’s helpful to have a post-campaign survey asking “do you feel more confident reporting a security concern?”, but it’s measuring sentiment, not action.
👉 Attribution is challenging. If reporting rates rise in October, was it the campaign, a recent ‘near miss’, or a manager reminding their team?
Solutions worth trying
💥 Pick the key behaviours before the month starts. As mentioned in my first ECSM post, run a cultural maturity assessment to decide which behaviours need to change and which teams need most attention. Then select some associated metrics - for a ‘Safe Data Handling’ theme, that might be DLP blocks and overrides, or the percentage of documents classified on creation.
📈 Baseline first. Pull three months of the metric before the campaign launches, so later numbers have something real to sit against.
⏰ Extend measurement past the month itself. Behaviour changes that fade within two weeks aren't culture change - they're a reaction resetting to baseline. Re-check the same metric at 30 and 90 days.
👀 Widen your view. In the Communications Plan, we had a column just for measurement - review those ideas, e.g. how many reminder (‘trigger’) stickers are still on phones after 90 days.
📶 Trend analysis. As part of the feedback loops we discussed last week, record every comment, complaint and question from staff to follow up and build trust. Analysis can reveal the problem areas needing attention, and an appetite to revisit issues you though were done.
💬 Engagement still matters. Exposure doesn't strongly correlate with behaviour change, but tracking interactions can indicate which channels are most successful.
🔄 Follow up. Pair behavioural metrics with something qualitative - speak to line managers or run a short survey in later months to confirm that message landed, and stuck. If behaviours changed, ask why.
None of this needs to be complicated. It needs to be decided before the campaign launches, tied to a few specific behaviours, and checked again after the noise has died down. Focus on creating metrics that tell leadership something important about how the organisation actually behaves and where the risks still lie. That’s all on ECSM for now, but we are planning something for November – hopefully where we can all review what happened, what worked and we’ll avoid next time. Best of luck everyone 🫡!
European Cyber Security Month - Feedback loops @channel Last week, we talked about the importance of a full Communications Plan for your Security Awareness Month. After all, security programmes are built to push messages out - training, education, policy updates. What we may not be so good at is listening 🙉. That imbalance sits at the centre of security culture work: we measure click rates and completion percentages and call it engagement, but true engagement isn't one-directional 🔃. If we want people to believe security is done with them, not to them, we have to value listening as much as broadcasting. Consider the difference between two scenarios:
A mandatory module is pushed to all staff telling them about a new process or policy;
A question is issued to all staff - “what gets in your way when you try to report a security concern?”
Only the second suggests their experience matters enough to shape what happens next. Employees don't conclude “security cares about us” because of a well-produced campaign; they conclude it because, at some point, they said something was broken and we fixed it ✅. Without that loop, even the best-designed awareness content reads as friction from someone who doesn't care 🤷♂️. The trouble is, one channel can't do this job. 👩💼Executives rarely respond to a survey - listening to them means being in the room; 🧑🏭 Operational staff live with legacy technologies that resist changes, so we need to walk the floor, not just email a policy; and 🧑💼Office workers leave a trail in help desk tickets and everyday grumbling about workplace process frictions that quietly drive workarounds. Treating all three as one audience is how we lose the connection, and the trust, we're trying to build. Collecting feedback is the easy part. What changes behaviour and creates culture is visibly acting on it. A control adjusted because the factory floor flagged it as unworkable, or a reporting process simplified because people kept giving up halfway through - these are the moments that convert feedback into evidence of care. A feedback loop that goes nowhere is worse than none at all ⏯️- it teaches people not to bother. If users don't get a valid, personalised response to every suspicious email they report, they'll simply stop. Security culture isn't something a campaign announces into existence. It accumulates as the residue of hundreds of small moments where the organisation either responded to what people told it, or didn't. The key question isn't how to communicate security better - it's how well we listen, and what we're prepared to change because of what we hear 👂. So, during Security Awareness Month, capture the voices, feedback and complaints from each person, and record who said what. Investigate, and circle back with personalised responses and explanations. We may not fix everything, but if people understand how, why and when, that's the basis for trust 🫶.
Thanks for comments Lars S. Sabrina H.. My recommendation is definitely to switch from 'data points' to 'indicators' to 'trends and stories' as you go up the hierarchy. Going into a Boardroom with lots of data is asking for trouble, they'll select an outlier point and quiz you on it until you can't answer, then they'll disregard the whole lot. Choosing 'what matters' is always a challenge - but you know your business and what matters. Is it uptime, safety, product design, price, reputation etc? Find the key aspects and then see how you can relate your metrics to those. I did a speech to the SoSafe Virtual Academy a few weeks ago which touched on this topic, and included some examples. I'll be posting that in the community in the first weeks of October.
Thanks Andrew R. choosing the right KPIs for different levels is an art in itself that depends highly on the art of Stakeholder Management or even the standing that you have in an organisation. As a Cybersecurity Professional you see so clear and you also understand what level the Management may understand. Still the main challenge is to get all parties involved to a common understanding on what really makes sense.
Hey thanks Andrew R. for sharing, this definitely helps. I think I mentioned it in another post, but KPI/RPI implementation is one of my biggest struggles. The hard part is figuring out which metrics actually matter and provide real value to management when making decisions. There are a few good ones on this list that I'll definitely take a closer look at.
Signal Watch | Operational Security Metrics @channel Metrics are one of the most challenging aspects of the security management role and trying to think of what to measure, that truly adds value, can be a real problem. I stumbled across this list today and thought it may help people with that process.
