The password rules we were taught are wrong
The ninety-day password change, the mandatory special character, the capital letter forced in for its own sake: these are the rules a generation learn…
Topic · People
Technology alone isn't enough: security is also about people and habits.
The ninety-day password change, the mandatory special character, the capital letter forced in for its own sake: these are the rules a generation learn…
Social engineering remains the most-used way in, and AI has made it cheaper and more convincing: voice cloning can mimic an executive's voice fro…
Social engineering is among the prime threats in the Union according to ENISA, yet the most common reaction stays the worst: blame whoever clicked. Th…
Kimsuky stopped fighting corporate email filters. It simply changed channel: a QR code forces the victim onto a personal phone, outside the IT perimet…
Social engineering remains among the prime threats because it bypasses technical controls by targeting people. But “the user is the problem” is a wrong shortcut: people fail when processes set them up to fail. Cyber culture isn't about blame, it's about giving the tools and habits that make the safe choice also the easy one.
A few practices, repeated: long unique passwords managed by a password manager, multi-factor authentication, wariness of unexpected links and attachments, updates installed. ENISA and CISA's Secure Our World campaign promote exactly these basics, and every October European Cybersecurity Month renews them.
Useful awareness isn't an annual course forgotten the next day: it's recurring practice, phishing simulations built to teach (not to punish), clear and short messages. An organisation that talks about security in an understandable way gets more protection than one that buys yet another tool.