European Cyber Security Month - Feedback loops @channel Last week, we talked about the importance of a full Communications Plan for your Security Awareness Month. After all, security programmes are built to push messages out - training, education, policy updates. What we may not be so good at is listening 🙉. That imbalance sits at the centre of security culture work: we measure click rates and completion percentages and call it engagement, but true engagement isn't one-directional 🔃. If we want people to believe security is done with them, not to them, we have to value listening as much as broadcasting. Consider the difference between two scenarios:
A mandatory module is pushed to all staff telling them about a new process or policy;
A question is issued to all staff - “what gets in your way when you try to report a security concern?”
Only the second suggests their experience matters enough to shape what happens next. Employees don't conclude “security cares about us” because of a well-produced campaign; they conclude it because, at some point, they said something was broken and we fixed it ✅. Without that loop, even the best-designed awareness content reads as friction from someone who doesn't care 🤷♂️. The trouble is, one channel can't do this job. 👩💼Executives rarely respond to a survey - listening to them means being in the room; 🧑🏭 Operational staff live with legacy technologies that resist changes, so we need to walk the floor, not just email a policy; and 🧑💼Office workers leave a trail in help desk tickets and everyday grumbling about workplace process frictions that quietly drive workarounds. Treating all three as one audience is how we lose the connection, and the trust, we're trying to build. Collecting feedback is the easy part. What changes behaviour and creates culture is visibly acting on it. A control adjusted because the factory floor flagged it as unworkable, or a reporting process simplified because people kept giving up halfway through - these are the moments that convert feedback into evidence of care. A feedback loop that goes nowhere is worse than none at all ⏯️- it teaches people not to bother. If users don't get a valid, personalised response to every suspicious email they report, they'll simply stop. Security culture isn't something a campaign announces into existence. It accumulates as the residue of hundreds of small moments where the organisation either responded to what people told it, or didn't. The key question isn't how to communicate security better - it's how well we listen, and what we're prepared to change because of what we hear 👂. So, during Security Awareness Month, capture the voices, feedback and complaints from each person, and record who said what. Investigate, and circle back with personalised responses and explanations. We may not fix everything, but if people understand how, why and when, that's the basis for trust 🫶.
Thanks for comments Lars S. Sabrina H.. My recommendation is definitely to switch from 'data points' to 'indicators' to 'trends and stories' as you go up the hierarchy. Going into a Boardroom with lots of data is asking for trouble, they'll select an outlier point and quiz you on it until you can't answer, then they'll disregard the whole lot. Choosing 'what matters' is always a challenge - but you know your business and what matters. Is it uptime, safety, product design, price, reputation etc? Find the key aspects and then see how you can relate your metrics to those. I did a speech to the SoSafe Virtual Academy a few weeks ago which touched on this topic, and included some examples. I'll be posting that in the community in the first weeks of October.
Signal Watch | Operational Security Metrics @channel Metrics are one of the most challenging aspects of the security management role and trying to think of what to measure, that truly adds value, can be a real problem. I stumbled across this list today and thought it may help people with that process.
European Cyber Security Month - Planning The Delivery @channel October is nearly here! It’s the pinnacle moment in many of our programmes, when we get permission to push our message harder than ever across Security Awareness Month. Over the next 3 weeks, I’ll pop in with tips, reminders and tools to help you be as prepared as you can be for the coming month. In this first episode, I want to focus on three things:
📉 Before you start this journey, it’s important that you’ve assessed your cultural maturity and the risks it points to. Decide which behaviours need to change, what ‘better’ looks like, and which teams need the most attention. If you haven’t done this already, loop back and do it NOW to give yourself a foundation for what comes next.
🎯 SoSafe has already built a set of content for you: sosafe-awareness.com/ecsm-2026. It has four weeks of awareness content covering Phishing, Voice Scams, Shadow AI and Deepfakes. If these topics overlap with your key messages, feel free to use this content.
📣 Free content is great, but it’s only half the solution – you need a solid communications plan to drive your messaging and interactions. Following on from last week’s ‘Off The Hook’ PPT, I’ve created a Communications Plan template, pre-populated with some example content.
The plan will drive clarity about what you are trying to achieve. Most of the columns are self-explanatory but a few deserve some explanation:
BJ Fogg Focus - Highlights the specific behaviour-change lever that you are using in that scenario – try to ensure you cover all three for each topic!
Mouthpiece - Separates content from delivery - we know that other voices often carry more credibility than the CISO, so choose deliberately for maximum impact
Associated policy - Gives you a place to record which policy covers this message, aiding in any subsequent Q&A with staff.
Tests - Freeform column to record ideas for metrics that validate scope and impact of your communication. Useful to prove value when we get to November.
Take the template and adapt it to your needs. I’d love to know which columns work for you, which don’t, and what you add. One thing’s certain: don’t head into October without a clear plan for every communication activity.
Off the Hook – Phone addiction and Meta’s legal settlement @channel As our summer breaks start to end, many of us have had a front-row seat to something that’s been hard to ignore: our family’s, and our own, relationship with social media/phones 📱. The unstructured days of the school holidays 🏖️ strip away routines that normally keep phone use in check, and for many households the result has been a summer of near-constant scrolling, gaming, and notification-chasing. Whether it was watching a teenager disappear into TikTok for hours, or catching yourself reaching for your phone when there's a lull in conversation, the pattern is familiar: apps engineered to be irresistible, delivering just enough reward to keep us coming back 📲. Interestingly, this isn't simply a matter of willpower. This same topic has been the subject of serious legal scrutiny in the US. You may know that Meta ♾️ recently agreed a landmark settlement worth around $18 billion, resolving claims that it knowingly designed Facebook and Instagram to be addictive, and that they misrepresented the harm this caused to children's mental health. As part of the deal, Meta committed to daily usage limits and "nighttime blocks" for teenage users, stronger age-verification measures, and new tools to help parents manage their children's use of its platforms. Although they deny any wrongdoing, these changes are an acknowledgment that social media products need guardrails & regulation, not just goodwill & best endeavours. This is a useful reminder for us all: if the platforms themselves are being required to build in friction and limits, there's a strong case for doing the same at home*. If this is a topic you think your user base could be interested in, I have good news 🥳! This week, I’ve created a handout that you can use to within your own organisations. The handout, ‘Off the Hook’, sets out six practical steps to help you and your family regain control over phone habits as the new school year begins. The goal isn't to demonise technology, but to try to break the automatic reflexes, and to do it as a household, with everyone's buy-in. Feel free to brand, revise and utilise this handout if you think it could be of value, either in parallel to communication about the Meta court case, or as part of your plans for October’s awareness month. * interestingly, in ‘Careless People’ (a book written about Meta by an internal whistleblower) it was highlighted that senior members of the Meta leadership team were very strict about their own children having no, or very limited, access to social media platforms… make of that what you will…🤨
Signal Watch | MSFT Exchange Vulnerability - GERMAN USERS PLEASE READ @channel For those us us still running MSFT Exchange servers (and there's a LOT in Germany!), it's important to note that a recent vulnerability now has exploit code available that will allow attackers to take over the mailboxes of all users, send emails, read emails, & download attachments. 🔑 Germany's Federal Office for Information Security (BSI) warned that around 85% of all on-premise Exchange servers in Germany are still vulnerable to this vulnerability 😬 Please take note of this and chase your IT department to patch these issues ASAP! bleepingcomputer.com/news/security/nearly-22-000-microsoft-exchange-servers-vulnerable-to-hijack-attacks
Integrity is a great point. We HAVE to be seen to be playing by the same rules we apply to others. I once had an IT team leader say that he thought I was a risk as I made policy exceptions that he didn't agree with - so I put 'myself' on the risk register, did a risk assessment and got it signed off by the CEO. I wasn't going to give myself a pass just because I could, I was trying for that visible integrity you highlight. Measuring trust is sooo difficult. You are right that you feel it way before you can count it. I think that a questionnaire where you simply ask the obvious question ('how much do you trust the security teams advice?') is possibly the best initial way - although the adoption rate of your recommendations is a clear signal of the true levels of trust.
Trust Me, I'm From IT! @channel In preparation for my session at SoSafe Academy earlier this week, I was creating content about how to establish trust between the CISO and the Board. It made me ponder the benefits of trust on a wider scale. It’s an awkward truth, but the IT team is often the least trusted voice in the building👨💻. They show up uninvited, tell people they're doing it wrong, disrupt working flow, and then vanish leaving staff confused and irritated. That’s an issue in itself, but what’s worse is that Security is often perceived as just another part of IT! Is it any wonder therefore, that our messages struggle to get through? 🙉 Trust is a mental shortcut our brains use to decide who's worth listening to under pressure, and who’s opinions have value. We judge advice by how we feel about the messenger, not simply the merits of the message. This technique is used by attackers all the time - look at the 2023 MGM Resorts breach for example. Attackers didn't crack any encryption - they simply rang the IT help desk, sounded confident, and asked for a password reset. The help desk trusted the caller's tone and basic authentication over any advanced verification process. That's authority bias, social proof & years of training a ‘help desk’ to help, working exactly as evolution intended, just weaponised against us. If attackers can build trust in five minutes on the phone, we can surely build genuine trust with our own colleagues. So how can we build trust with our user base instead? Three behavioural levers:
🔄 Reciprocity - always be looking to help. I used to tell my team that the answer to any user request was always “Yes”, we just needed to figure out how to say yes safely. Look for opportunities to add value and make the users life easier. Once you are perceived to be ‘on their side’, things will get much easier.
📶 Consistency - as German (& British!) rail commuters know, it’s difficult to trust a service that is inconsistent. By always having the same helpful response, by showing up every time, by always being calm, regardless of cause, you will become much more approachable to staff. Which leads onto…
🆘 Psychological safety - remove the risk, blame and finger pointing from any engagement. Reward the person who reports "I think I clicked something," fast, publicly, and warmly. That single cultural signal does more for security than any awareness poster you can print.
Trust isn't earned through authority; it's earned through repeated, low-stakes proof that we're on the user’s side. It will spread slowly, user by user, as each one encounters a reason to trust you, so be the colleague who always helps, not the department that judges — and watch engagement follow. Talking Points 1. Do you have any metric tracking trust levels? If so, what does that look like? 2. What’s the one thing your department has done that made the biggest difference to how much the user base trust the Security function?
Welcome! Great to have you in the community - hope you find some value in the conversations and posts. I tend to post something every two weeks or so. Please do let me know if there are any topics you'd like the community to discuss!
The Summer Security Paradox: Why Fewer Attacks Still Means More Vulnerability @channel As I was drafting this article, I found something I didn’t expect - ransomware attacks decline by 18% during summer ! Now although that may sound like great news, it comes with some significant caveats. 🏖️ Summer's Hidden Attack Vectors While ransomware declines, travel-related phishing can spike. Kaspersky blocked 26% more phishing attempts in 2024, noting a surge in summer, targeting travellers with holiday themed phishing scams – e.g. last-minute holiday bargains; fake airline/hotel updates; travel insurance alerts. Then there's your out-of-office auto-reply. It’s a low-risk way for attackers to assess your organisation - they can scope out an understanding of who’s away, for how long and who covers their work. This information can map out decision-making chains and enable more competent & informed social engineering. ⤵️ The Resilience Collapse Of key concern is that summer staffing levels can break controls. One individual covering multiple roles means segregation of duty fails; the office ‘expert’ may be absent so escalations are avoided; or the sheer volume of work means tasks are put to one side, or corners are cut to hit deadlines. This may mean that your understaffed SOC doesn’t detect the attack; a junior Finance clerk pays that urgent high value invoice; or your internet facing systems don’t get the latest patch – either way, you’ll be increasing your vulnerability exactly when attackers know you’ll be running depleted teams. 👍 Addressing The Risk Although it seems that the attackers may take a summer vacation too, it’s not a time to become complacent 🍹. The controls you’ve created across the rest of the year are stretched thin, & defences are less effective, so when an attack does happen you are less able to detect and respond. Consider these pre-holiday steps:
Travel related phishing - Run a pre-holiday phishing simulation that is holiday themed, supported by a communication plan to remind people about contextually-correct lure emails!
Out-of-office auto-reply - Educate staff on information leakage and the importance of external out-of-office responses that don't broadcast key information.
Summer staffing - Ask line managers to remind their staff about the need to adhere to process regardless of the summer break, even if that impacts deadlines. Ensure playbooks (who's on-call, decision thresholds, out-of-band communication for critical incidents) are up to date before people leave, and specifically call out which systems can have updates deferred.
Talking Points 1. What risks do you see over summer? Untrained contract staff filling roles, skill depletion etc? 2. How do you educate people on summer risks without triggering them?
