I'm seeing a lot of chat re phishing tests on #infosec twitter
I promise you I am one of the people to chat to to feel support for no phishing sims (hit me up I LOVE talking)
Security Awareness & Culture is my job
A 🧵
got laid off in the big @dropbox layoffs today.
if anybody is looking for a staff-level engineer who loves mentoring and who is an expert in web security, email security, TLS/PKI, keys and secrets management, and general defense security stuff, please feel free to hit me up.
let's about talk about my favorite part of the Olympics, one of the things that that originally got me into art and graphic design as a child: pictograms. the first I can remember are from Seoul 88. you might recall these.
At this rate, I am like 95% sure that the only talks at Blackhat 2024 are gonna be purely AI written and delivered by Boston Dynamic robots.
Can't wait.
@19Lv85@Layer8Con Pretty much anything in the behavioural science sphere will help, BJ Fogg is an accessible starting place. Then education/coaching theory - focus on positive reinforcement based training. There's a lot!
Go listen to why all your phishing programs suck. Yes yours. The ones where you trick your staff into clicking things and then yell at them. The ones where you send phishes to your staff. Those ones. They suck
#phishing#infosec
Are you doing phishing testing? Are you doing it badly? On this week's Layer 8 Podcast, @BexMarkwick explains what we do wrong, how it causes harm and how to do them better. https://t.co/kMJpGzlJ2l
Are you doing phishing testing? Are you doing it badly? On this week's Layer 8 Podcast, @BexMarkwick explains what we do wrong, how it causes harm and how to do them better. https://t.co/kMJpGzlJ2l
“Why Phishing Simulations Suck” is this week’s Layer 8 podcast episode with @BexMarkwick. What are we doing wrong, why is it wrong and how can we make it better?
https://t.co/kMJpGzlJ2l
Does your phishing program suck? Maybe it does. On tomorrow’s new Layer 8 podcast episode, @BexMarkwick will explain how we get them wrong and how to do them better.
[private message on work slack]
friend: hey buddy how do i <do thing>, i can't find it in your team's docs and i feel super dumb
me: hey buddy! it doesn't exist. please re-ask this question in our public help channel so whoever is on-call can answer you.
[public help channel]
friend: hi team, our service needs to <do thing> because of <legit reasons>. we're wondering what the right way to do it is. thanks!
me (also the on-call): hello, this is not possible at the moment, but we'll add a ticket for it and prioritize it in our upcoming sprint.
This week, the #Layer8Podcast episode is with @Human_Decoded and talking about @TraceLabs and their search parties.
Next week, we have @BexMarkwick to explain why your phishing program probably sucks.
https://t.co/rxt41IINru
@Infosec_Taylor How America has people do taxes is always mad to me. Glad they are slowly moving to more accessible methods (even if it does seem weird!)
Getting into Security because you think it grants you authority is a solution for idiots. It doesn’t. You only have authority a human mind isn’t incentivized to subvert.
If you want to make change you have to compel a better solution. There’s no debating. There’s just results.
Thrilled to have had my talk accepted for @PancakesCon!
Come along to hear all about semiotics and judging books by their covers
Full schedule of amazing talks here: https://t.co/04K80pVEcF
@pamelacolloff This is ridiculous. His teacher is misguided — banning words in an attempt to get them to write better? We don’t take tools away from learners, we give them more tools
New website is live. It collects the videos of my talks, contact page, my varied thoughts in mini article format, and links to socials. Check it out!
https://t.co/Hf6BsxmkKY