Deny by Default

Click, Fail, Repeat

28 min · 13. März 2026
Episode Click, Fail, Repeat Cover

Beschreibung

Security Awareness Training and phishing simulations are some of the most debated controls in modern cybersecurity programs. Some CISOs argue they don't work, claiming users will always click and that organizations should rely entirely on technology to stop attacks. Others believe the human element remains one of the most critical layers of defense. In this episode of Deny by Default, Scott Gombar explores the controversy around Security Awareness Training (SAT) and phishing simulations. Are they just compliance checkboxes, or do they still play an essential role in protecting organizations from modern cyber threats? Scott breaks down why attackers continue to target people through phishing, social engineering, and business email compromise—and why ignoring the human layer of security may actually increase risk.

Kommentare

0

Sei die erste Person, die kommentiert

Melde dich jetzt an und werde Teil der Deny by Default-Community!

Loslegen

2 Monate für 1 €

Dann 4,99 € / Monat · Jederzeit kündbar.

  • Podcasts nur bei Podimo
  • 20 Stunden Hörbücher / Monat
  • Alle kostenlosen Podcasts

Alle Folgen

4 Folgen

Episode How One Click Cost a Business $187,000 Cover

How One Click Cost a Business $187,000

One employee. One email. One click. $187,000 gone. It started with an email that looked exactly like it came from the CEO. A routine wire transfer request, sent at the right time, to the right person, with the right tone. The employee didn't think twice. Within hours, $187,000 had been wired to an overseas account — and it was never coming back. In this episode, we break down a real-world business email compromise (BEC) attack step by step. We look at how the attacker gathered intel, crafted the perfect message, and exploited trust and urgency to bypass every security tool in place. We also cover the warning signs that were missed, why traditional email filters didn't catch it, and the critical controls — like multi-person authorization for wire transfers, out-of-band verification, and employee awareness training — that could have stopped this attack cold. If your business moves money by email, this episode is required listening.

3. Apr. 202622 min
Episode To Small to Hack? That's Cute! Cover

To Small to Hack? That's Cute!

In this episode of Deny by Default, host Scott Gombar breaks down one of the most dangerous myths in cybersecurity: that small businesses are too insignificant to be targeted. The reality is the opposite. Attackers do not go after size, they go after opportunity. Using a real-world ransomware attack on a small city as a backdrop, Scott explains how modern cyber threats rely on automation, weak controls, and human trust, not Hollywood-style hacking. From business email compromise to shared passwords and lack of multi-factor authentication, this episode highlights how everyday gaps create easy entry points for attackers. You will learn why small and mid-sized businesses are prime targets, how attacks actually happen, and what security leaders see that most organizations miss. Most importantly, this episode provides practical, actionable steps you can take immediately to reduce risk without needing an enterprise budget. If you think your business is too small to be hacked, this episode will change your perspective and your security posture.

27. März 202623 min
Episode Click, Fail, Repeat Cover

Click, Fail, Repeat

Security Awareness Training and phishing simulations are some of the most debated controls in modern cybersecurity programs. Some CISOs argue they don't work, claiming users will always click and that organizations should rely entirely on technology to stop attacks. Others believe the human element remains one of the most critical layers of defense. In this episode of Deny by Default, Scott Gombar explores the controversy around Security Awareness Training (SAT) and phishing simulations. Are they just compliance checkboxes, or do they still play an essential role in protecting organizations from modern cyber threats? Scott breaks down why attackers continue to target people through phishing, social engineering, and business email compromise—and why ignoring the human layer of security may actually increase risk.

13. März 202628 min