human risk management

Payroll Pirates Reveal Canada’s Human Risk Gap

On April 9, 2026, Microsoft’s security researchers published their investigation into Storm-2755, a financially motivated threat actor running what they are calling “payroll pirate” attacks against Canadian employees. The campaign does not rely on malware, ransomware, or headline-grabbing intrusions. It relies on two things that are already inside your organization: a staff member who Googled […]

Payroll Pirates Reveal Canada’s Human Risk Gap Read More »

Why Contextual Security Awareness Training Works Better

A new integration announced this week between Dashlane and KnowBe4 points to a fundamental shift in how effective contextual security awareness training actually works. Rather than delivering training on a quarterly schedule, the two companies have built a system that triggers learning the moment a credential risk is detected in the browser. The announcement offers

Why Contextual Security Awareness Training Works Better Read More »

Human Risk Management: Beyond Security Awareness Training

Nearly 70% of organizations believe their employees lack fundamental cybersecurity awareness, even at organizations that already run formal training programs. That finding, from Fortinet’s 2024 Security Awareness and Training Global Research Report, captures a frustration that many security leaders recognize immediately: completing a course is not the same as being prepared. In 2026, the industry’s

Human Risk Management: Beyond Security Awareness Training Read More »

Why Phishing Simulations Are Failing Your Team in 2026

Most organizations run phishing simulations a few times a year and feel reassured when pass rates look good. But new research from ISACA and findings from Gartner’s March 2026 Security and Risk Management Summit in Sydney paint a more troubling picture: the simulations themselves may be the problem. Outdated templates, unrealistic scenarios, and a compliance-first

Why Phishing Simulations Are Failing Your Team in 2026 Read More »

When the Boss Calls: AI Voice Scams Target Employees

AI voice scam employee training is no longer a future concern for Canadian organizations. On March 9, 2026, Canada’s Competition Bureau issued a public alert warning that scammers are using artificial intelligence to impersonate government officials, politicians, and other trusted figures with a level of realism that makes these calls remarkably difficult to detect. The

When the Boss Calls: AI Voice Scams Target Employees Read More »

Retail Data Breach: Phishing Awareness Training Gap

Retail Data Breach: Phishing Awareness Training Gap By POPP3R Cybersecurity | March 20, 2026 Table of Contents What Happened at Loblaw Why Exposed PII Fuels Phishing Campaigns Retail Data Breach Phishing Awareness Training: The Missing Layer Key Steps for Canadian Retailers What Happened at Loblaw On March 10, 2026, Loblaw Companies Limited confirmed that a

Retail Data Breach: Phishing Awareness Training Gap Read More »