
September 17, 2026 · 9 min
Early detection of compromised accounts
A compromised account can stay active for weeks. Learn the signals, why per-person risk scoring beats averages, and how to close the window before impact.
Read article →Keeping you informed and secure. The latest in human risk and behavioral cybersecurity: phishing, social engineering, ransomware and more.

September 17, 2026 · 9 min
A compromised account can stay active for weeks. Learn the signals, why per-person risk scoring beats averages, and how to close the window before impact.
Read article →
September 17, 2026 · 8 min
Changing the password is not enough. The first-hours steps to contain a leaked credential before it turns into a bigger incident.
Read article →
September 9, 2026 · 7 min
Closing out an employee's departure is not HR paperwork. It is closing the door an attacker looks for when nobody is watching. A step-by-step guide.
Read article →
September 3, 2026 · 6 min
Phishing simulations are legal in LATAM when you respect data-protection law, disclose the purpose and minimize data. A guide to framing it before you start.
Read article →
September 3, 2026 · 8 min
A good pilot does not prove people finished a course, it proves their behavior changed under pressure. Here is how to design one and how to decide.
Read article →
August 28, 2026 · 7 min
Four steps to shield the help desk MFA reset against social engineering, and how to validate that support actually withstands the deception.
Read article →
August 28, 2026 · 9 min
The three signals behind a human risk score, how to capture the first picture in two weeks, and which baseline to compare against later.
Read article →
August 25, 2026 · 9 min
The second factor is not broken, it is bypassed. The six ways an attacker gets past MFA without cracking anything, and what each reveals about behavior.
Read article →
August 20, 2026 · 8 min
How the attacker's subscription model multiplies email phishing, and why the defense still lives in human behavior rather than in spotting typos.
Read article →
August 20, 2026 · 7 min
Chile became the first country in the region to make human risk management a legal obligation. Here is what that means for companies across LATAM.
Read article →
August 13, 2026 · 7 min
Measuring behavior change is not a slogan: it is a protocol with a window, a category, passing criteria, and a risk floor. Here is how to design each piece.
Read article →
August 11, 2026 · 7 min
An email with no link or attachment, just a number to call. How callback phishing (TOAD) works, why it slips past filters, and what your team can do.
Read article →
August 6, 2026 · 6 min
We gathered the verified 2026 figures on phishing, human factor, breach cost and market, each with its source, to cite without repeating loose numbers.
Read article →
August 5, 2026 · 8 min
The human risk business case is not the cost of the course, it is the cost of the breach that does not happen. What numbers and metrics to show the board.
Read article →
August 4, 2026 · 7 min
A simulation that humiliates teaches people to hide the slip, not report it. Here is how to introduce the practice without the team feeling trapped.
Read article →
August 3, 2026 · 6 min
A generic template everyone spots measures pattern recognition, not behavior under attack. What actually makes a phishing simulation realistic.
Read article →
August 3, 2026 · 7 min
A leaked credential leaves no trace on your network. What dark web monitoring is and how to know if your team is already exposed.
Read article →
July 31, 2026 · 7 min
Authority, urgency, fear, curiosity, reward, trust and the wish to help: the seven human instincts phishing exploits to make a person click.
Read article →
July 28, 2026 · 6 min
Email is still the main door and the other channels add to it, they do not replace it: a map of the seven vectors and the instinct each one exploits.
Read article →
July 27, 2026 · 9 min
If your program can prove people completed the training but not that risk went down, it is a checkbox. These seven signs help you confirm it yourself.
Read article →
July 27, 2026 · 7 min
A social engineering technique convinces an employee to copy a command and run it themselves. Here is how ClickFix and FileFix work.
Read article →
July 24, 2026 · 8 min
Banning ChatGPT does not stop the habit, it hides it. What shadow AI is, how it differs from an AI agent, and what to watch in behavior.
Read article →
July 22, 2026 · 8 min
Sending the same campaign to everyone measures exposure, not change. Personalize the scenario, correct on time, and validate the result with a retest.
Read article →
July 21, 2026 · 6 min
Monthly for everyone, every two weeks for finance, leadership, HR and IT support. Set frequency by role without training people to spot the drill.
Read article →
July 21, 2026 · 7 min
Passing the training module after falling for a phishing email proves nothing. Only putting the person back in the same situation proves the change.
Read article →
July 17, 2026 · 7 min
A new hire already has access, does not know the protocols, and wants to impress. That window lasts weeks, and attackers know it better than HR does.
Read article →
July 16, 2026 · 8 min
The question that matters most is not price or template count. It is how the vendor proves that someone who failed a simulation actually changed.
Read article →
July 15, 2026 · 7 min
Ninety days is enough to go from zero to a program that measures conduct. Order matters more than tooling: start with who is exposed, not with the course.
Read article →
July 14, 2026 · 5 min
It no longer counts who finished the course. It measures whether the person changes how they act against a deception. That is what the framework names.
Read article →
July 14, 2026 · 5 min
The decision is not which modules to buy, it is whether they talk. When the engines stay silent, the leaked credential never steers the next simulation.
Read article →
July 10, 2026 · 5 min
Price per employee tells you little on its own. Here are the criteria that separate a cheap fee from a program that actually reduces human risk.
Read article →
July 8, 2026 · 7 min
Reporting beats falling for it, but warning is not the same as resisting. Only retesting proves the behavior actually changed.
Read article →
July 7, 2026 · 5 min
The text message reaches the personal device, outside the email perimeter. That is where the employee trusts more and the company sees less.
Read article →
July 6, 2026 · 7 min
Why approval-based MFA gives in to repetition and exhaustion, and what separates a real defense from a checked box against this pattern.
Read article →
July 3, 2026 · 5 min
A 2026 guide to the HRM category for companies of 25 to 500 employees in LATAM. Nine platforms compared by what really decides: how they prove change.
Read article →
July 3, 2026 · 5 min
A phone attack no email filter can stop: why the help desk is the target, and how to validate that people actually resist the pretext.
Read article →
July 2, 2026 · 7 min
The native Microsoft 365 simulator is a solid starting point, not a human risk program. A scope comparison and the checklist a CISO should demand.
Read article →
July 2, 2026 · 5 min
A frequently asked questions bank for security leaders in LATAM evaluating a human risk management program at midsize companies.
Read article →
June 30, 2026 · 5 min
Finishing a course does not prove anyone stopped falling for a scam. The metric that shows change is retesting the behavior weeks later.
Read article →
June 30, 2026 · 6 min
Generative emails, synthetic voice and fake video raise the quality of deception. Why filters fall short and how to prepare your teams.
Read article →
June 30, 2026 · 6 min
The market is racing to police autonomous agents, but validating how people behave under a real attack is the problem almost no one is measuring.
Read article →
June 30, 2026 · 5 min
The right KnowBe4 alternative is not the one with the biggest catalog: it is the one that proves an employee who fell for a trick is no longer vulnerable.
Read article →
June 27, 2026 · 5 min
A QR code hides the link and moves the attack to the phone, past your filters. Prioritize by person, simulate real quishing and validate with a retest.
Read article →
June 6, 2026 · 8 min
Artificial intelligence democratized sophisticated attacks, boards woke up to human risk, and cyber insurance became a catalyst. Three converging forces that change everything.
Read article →
December 28, 2025 · 6 min
A market that keeps growing while peer reviewed evidence shows that completing training does not predict fewer real failures.
Read article →
December 18, 2025 · 7 min
Security spending keeps growing while the human layer stays underfunded. A look at where the imbalance comes from and how to close it.
Read article →Book a 30-minute demo and see it with simulated data from your industry.
Not just theoretical training. We test real behavior with personalized attacks adapted to each employee and develop specific competencies so your team meets human security standards.
We assess susceptibility to contextual phishing tailored to each employee's role, industry, and personal context
We monitor dark web exposure and train immediate response when corporate or personal credentials are compromised
We identify individual vulnerabilities (urgency, authority, family context) and train defense against the exact vector that deceives each person
We simulate urgency scenarios calibrated to each employee's position to develop identity verification in critical moments
We measure response time to simulated attacks and build the habit of immediate reporting to the security team
We generate risk scores per employee and executive reports that demonstrate documented monthly preparedness to insurers and regulators