Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

Personalized Security Awareness Training & Human Risk

SoSafe
05/26/2026
0
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


TL;DR

  • Traditional one-size-fits-all security awareness training fails because employees have vastly different risk levels, job roles, work contexts, and skill levels that generic programs cannot address effectively
  • SoSafe's personalized approach uses context surveys and role-based learning paths to deliver relevant training, while adaptive phishing simulations adjust difficulty based on individual click rates to build competency progressively
  • Sophie AI provides real-time feedback on suspicious emails, creating immediate learning moments while reducing manual triage work for security teams who previously reviewed every reported message
  • Success measurement should focus on behavioral indicators like click rates and department-level vulnerabilities rather than just training completion percentages, with continuous training needed to maintain threat recognition skills
  • Organizations can track security culture maturity through attitude surveys, the ratio of security events to actual incidents, and the volume of proactive security consultations from business units

The Human Risk Problem and One-Size-Fits-All Limitations

This HuFiCon 2024 session addresses the fundamental challenge that 68% of security breaches involve human error, with projections suggesting this will reach 90% in coming years. SoSafe product experts Tommy Courtney and Dr. Gundula Zerbes argue that traditional security awareness training oversimplifies human risk by treating all employees identically. They demonstrate how workforce diversity—spanning risk levels, departmental roles, work contexts, and individual skill levels—demands a more sophisticated approach. The session establishes that employees working from home face different vulnerabilities than office-based staff, while new hires require different training than tenured employees, yet most organizations still deploy uniform training programs that fail to account for these critical differences.

Personalized Learning Paths and Adaptive Simulations

The presentation introduces SoSafe's approach to individualized security training through role-based learning paths, context surveys, and behavior-based phishing simulations. Using a sales leader named Alex as a case study, the speakers demonstrate how the platform builds contextual understanding of each employee's role, travel patterns, and device usage to deliver relevant training content. The adaptive simulation engine adjusts phishing difficulty based on individual click rates—sending easier templates to users with low awareness and progressively harder scenarios as competency improves. This personalization extends to smishing simulations for mobile users and eliminates irrelevant training modules, addressing the common complaint that employees lack time for generic security content that doesn't apply to their actual work environment.

Real-Time Feedback with Sophie AI and Success Measurement

SoSafe's Sophie AI assistant provides immediate feedback when employees report suspicious emails, offering instant analysis of whether a message is malicious and explaining the specific threat indicators. This real-time learning moment occurs when employees are most engaged and receptive, while simultaneously reducing the manual triage burden on security teams who traditionally review every reported email. The session emphasizes measuring success through behavioral metrics like click rates rather than just training completion percentages, with recommendations to track department-level vulnerabilities and continuously train employees to maintain their threat recognition capabilities. The Q&A portion addresses measuring security culture maturity through attitude surveys and tracking the ratio of security events to actual incidents as indicators of program effectiveness.

Chapters

0:00 - Introduction and Speaker Backgrounds
2:00 - The Human Factor in Today's Threat Landscape
4:30 - Why One-Size-Fits-All Training Fails
7:30 - Risk Levels and Contextual Learning Needs
10:30 - Personalized Learning and Motivation Science
13:30 - Role-Based Learning Paths and Adaptive Simulations
17:00 - Behavioral Phishing Simulations
20:30 - Smishing and Real-World Relevance
23:30 - Sophie AI and Real-Time Security Feedback
27:30 - Measuring Success Beyond Completion Rates
33:00 - Audience Q&A on Maturity KPIs

Key Quotes

1:34 "... 80% of security professionals, so people in this room, believe this is the most complex time we've had in the last five years ..."
1:41 "One in two of us in our organizations in the last three years have been successfully hit by an attack ..."
3:44 "... 68% of breaches involve us. They involve a human just making one mistake ..."
5:36 "What we see in practice then is that this doesn't really work. Why won't that really work? Well, that's because humans are a little bit more complex than that ..."
13:54 "If you're really crap at spotting phishing emails, there's no point in you receiving really, really difficult ones because you're too far away from your actual knowledge ..."
18:32 "What we always recommend to people is to, wherever possible, look at metrics that reflect the real world risk behavior as closely as possible ..."

Categories:
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Security Operations
  • AI & Machine Learning
  • Best Practices
  • Webinar
  • Getting Started
  • Security Awareness Training
  • Human Risk Management
  • Personalized Learning
  • Phishing Simulations
  • Behavioral Science
  • AI-Powered Security Feedback
  • Security Culture Measurement
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Personalized Security Awareness Training & Human Risk

              Upcoming Webinar Calendar

              • 05/27/2026
                10:00 AM
                05/27/2026
                Adopting AI: From Illusion to Intentional Control
                https://www.truthinit.com/index.php/channel/1924/harnessing-ai-transforming-illusion-into-purposeful-mastery/
              • 05/28/2026
                01:00 PM
                05/28/2026
                Harnessing AI for Smaller Teams: Strategies for Secure Implementation
                https://www.truthinit.com/index.php/channel/1951/harnessing-ai-for-smaller-teams-strategies-for-secure-implementation/
              • 06/02/2026
                01:00 PM
                06/02/2026
                Spring of Satori: Delving into Recent Findings and 2026's Threat Landscape
                https://www.truthinit.com/index.php/channel/1930/spring-of-satori-delving-into-recent-findings-and-2026s-threat-landscape/
              • 06/10/2026
                12:00 PM
                06/10/2026
                Deciding Between Purchasing and Developing Solutions
                https://www.truthinit.com/index.php/channel/1983/deciding-between-purchasing-and-developing-solutions/
              • 06/10/2026
                02:00 PM
                06/10/2026
                Deciding Between Building or Buying Data Classification: Understanding DIY Costs
                https://www.truthinit.com/index.php/channel/1985/deciding-between-building-or-buying-data-classification-understanding-diy-costs/
              • 06/16/2026
                07:00 AM
                06/16/2026
                Prioritizing Solutions: Transforming Data Risk into Actionable Steps
                https://www.truthinit.com/index.php/channel/1952/prioritizing-solutions-transforming-data-risk-into-actionable-steps/

              Upcoming Events

              • May
                27

                Adopting AI: From Illusion to Intentional Control

                05/27/202610:00 AM ET
                • May
                  28

                  Harnessing AI for Smaller Teams: Strategies for Secure Implementation

                  05/28/202601:00 PM ET
                  • Jun
                    02

                    Spring of Satori: Delving into Recent Findings and 2026's Threat Landscape

                    06/02/202601:00 PM ET
                    • Jun
                      10

                      Deciding Between Purchasing and Developing Solutions

                      06/10/202612:00 PM ET
                      • Jun
                        10

                        Deciding Between Building or Buying Data Classification: Understanding DIY Costs

                        06/10/202602:00 PM ET
                        More events
                        Truth in IT
                        • Sponsor
                        • About Us
                        • Terms of Service
                        • Privacy Policy
                        • Contact Us
                        • Preference Management
                        Desktop version
                        Standard version