๐ FieldNotes – The hidden HR cost of security awareness training
Reminders, overdue notices and report preparation all take time. Here’s a view on HR workload that belongs in your next awareness renewal.
Reminders, overdue notices and report preparation all take time. Here’s a view on HR workload that belongs in your next awareness renewal.
A Montrachet at an impossible price lands in the inbox of someone who has spent years posting about white Burgundy. Wine phishing scams are not spray and pray. They are built from leaked customer data and public passion, and the wine trade taught attackers everything they know about scarcity and urgency.
The 2026 SANS survey lands on a reassuring finding: a trained, skeptical human is still the best defense against AI-enabled attacks. Sit with the rest of the numbers and a harder pattern shows up. Skepticism runs on time and discomfort, and an AI-shaped attack is built to remove both, on both sides of the firewall.
Excerpt: For two days in July, any Instagram user could pull another person’s public posts into an AI-generated image by @-mentioning them, with the setting enabled for everyone by default. Meta withdrew the option after backlash. The interface disappeared. The assumption underneath it, that a person’s public content is reputation exposure rather than attack material, did not.
Banks are warning employees about spear phishing again. The checklists are familiar: verify the sender, use a second channel, follow approval processes. Good hygiene. But the warning itself encodes an assumption that is quietly wrong, that the threat is still mostly about email, and mostly about obvious manipulation. It is not.
A free malware-as-a-service platform built and traded by teenagers has infected over 116,000 machines through Minecraft mods, with a suggestions page where users vote on adding ransomware. The reflex is to blame the kids. The harder observation is that we mistook a generation’s fluency with technology for judgment about it, and the people who actually hold that judgment are retiring.
NYC Health + Hospitals disclosed a months-long breach exposing biometric, medical, and financial data for 1.8 million people through a third-party vendor. Two-thirds of the dataset can be rotated. The rest cannot. The remediation playbook the industry inherited from the credit-card era does not bend to fit data that is permanent by nature.