Skip to content

Topic: awareness

productWhy the University of Osnabrück is our Awareness Customer of the Year

Our internal selection committee quickly reached consensus on who should receive this award: the University of Osnabrück. It receives the “Awareness Customer of the Year 2026” award for the exemplary implementation of CYBERDISE in an on-premise configuration.

awarenessWhy Security Awareness Will Always Work – If You Build and Measure the Right Thing

A Wall Street Journal article drawing on the study “Understanding the Efficacy of Phishing Training in Practice” questions whether phishing simulations and awareness training lead to meaningful risk reduction. A growing body of empirical research shows that well-designed awareness programs do improve real-world cyber risk behavior; what often fails is a narrow interpretation of what awareness is, how it should be embedded and how success should be measured.

comparisonWhat CUSTOMERS DO WRONG when starting Cybersecurity Awareness Programs

Like any other project, a cybersecurity awareness program can get off to a very bumpy start when it begins with an inappropriate mindset and management fails to recognize the value of awareness. We examined the mistakes and false expectations documented in a USENIX study and compared them with our own experience.

comparisonRisk Attitude vs Risk Behavior: Are You Training the Wrong Thing?

Despite comprehensive security awareness training, many organizations still have cybersecurity breaches resulting from human error. This article is about the gap between risk attitude (knowing what is risky) and risk behavior (actually acting securely).

threat-landscapeThe biggest cyber heists in history: The bybit, MGM and Sony hacks - similarities, effects, damage and awareness potentials

In our irregular series on the biggest cyber heists in history, this post analyzes the Bybit, MGM and Sony hacks: what happened, how it happened, who noticed it, what damage was done and what the consequences were. At the end, we compare the cases and consider what could have been done better, also from a cybersecurity awareness perspective.

awarenessGDPR vs NIS2 vs ISO 27001: Is There Any Difference?

Compliance is a cornerstone of trust, security and resilience, yet telling GDPR, NIS2 and ISO 27001 apart can feel like solving a puzzle. Here is what each framework requires, what non-compliance risks and how the three interconnect.