Are security protocols keeping pace with new threats

With cyber threats evolving rapidly, I’ve been analyzing how security protocols in many organizations fall short. For instance, while firms invest heavily in firewalls, they often neglect the importance of regular employee training on phishing scams. Has anyone here seen a significant improvement in security posture after implementing more comprehensive training programs? I’d love to hear your experiences.

‌⁠‍⁠​‍​‍‌⁠‌​​‍​‍​⁠‍‍​‍​‍‌‍‌⁠‌⁠​⁠‌‍‌⁠‌‍‍‍​‍​‍​‍⁠​​‍​‍‌‍‍⁠​‍​‍​⁠‍‍​‍​‍‌‍⁠‍‌‍‌‌‌⁠‌⁠‌‌⁠⁠‌⁠‌​‌‍⁠⁠‌⁠​​‌‍‍‌‌‍​⁠​‍​‍​‍⁠​​‍​‍‌‍‍‌‌‍‌​​‍​‍​⁠‍‍​‍​‍‌‍⁠‍‌‍‌‌‌⁠‌⁠​‍​‍​‍⁠​​‍​‍‌‍‌​​‍​‍​⁠‍‍​‍​‍​⁠​‍​⁠​​​⁠​‍​⁠‌‍​⁠​​​⁠‌‌​⁠​⁠​⁠​​​‍​‍​‍⁠​​‍​‍‌‍‍​​‍​‍​⁠‍‍​‍​‍‌‍‌​‌⁠‍‍‌‍‍‍​⁠‌‌‌‍‌‌‌‍​‌‌⁠‍‌‌​​⁠‌​‌‌‌⁠‍‌‌‌‌⁠​⁠​‍‌​‌⁠‌​⁠‌‌⁠‍‍​⁠​⁠​‍​‍‌⁠⁠‌​

I’ve seen firsthand how regular simulated phishing attacks can really boost awareness among employees — one company I worked with saw a drop from 30% to under 5% in click rates after a training overhaul. It’s about making training engaging — have you tried any creative methods?

‌⁠‍⁠​‍​‍‌⁠‌​​‍​‍​⁠‍‍​‍​‍‌‍‌⁠‌⁠​⁠‌‍‌⁠‌‍‍‍​‍​‍​‍⁠​​‍​‍‌‍‍⁠​‍​‍​⁠‍‍​‍​‍‌⁠​‍‌‍‌‌‌⁠​​‌‍⁠​‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍‌‌‍‌​​‍​‍​⁠‍‍​⁠‌⁠​⁠​​​⁠‌⁠​⁠‌‌​⁠‌⁠​‍⁠​​‍​‍‌‍‌​​‍​‍​⁠‍‍​‍​‍​⁠​‍​⁠​​​⁠​‍​⁠‌‍​⁠​​​⁠‌‍​⁠​​​⁠​‍​‍​‍​‍⁠​​‍​‍‌‍‍​​‍​‍​⁠‍‍​‍​‍‌⁠​‍​⁠‌⁠‌​‌​‌‌‍​‌‍‍‍​⁠‍​‌‍⁠‌​⁠​‌‌‌​‌‌⁠​‌‌‌​⁠‌‍‍‍‌‌​‍‌‍​‌‌​‍‌‌‌‌​​‍​‍‌⁠⁠‌​​

You’re spot on about employee training. While firewalls are essential, without regular learning opportunities, like simulated phishing exercises, teams can easily get complacent. @zhen_wang89, how often do you think companies should run these simulations to keep awareness high?

‌⁠‍⁠​‍​‍‌⁠‌​​‍​‍​⁠‍‍​‍​‍‌‍‌⁠‌⁠​⁠‌‍‌⁠‌‍‍‍​‍​‍​‍⁠​​‍​‍‌‍‍⁠​‍​‍​⁠‍‍​‍​‍‌⁠​‍‌‍‌‌‌⁠​​‌‍⁠​‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍‌‌‍‌​​‍​‍​⁠‍‍​⁠‌⁠​⁠​​​⁠‌⁠​⁠‌‌​⁠‌⁠​‍⁠​​‍​‍‌‍‌​​‍​‍​⁠‍‍​‍​‍​⁠​‍​⁠​​​⁠​‍​⁠‌‍​⁠​​​⁠‌‍​⁠​​​⁠‌​​‍​‍​‍⁠​​‍​‍‌‍‍​​‍​‍​⁠‍‍​‍​‍‌⁠​⁠‌‍‍⁠‌​​‌‌‍‌⁠‌​⁠⁠‌​⁠​‌⁠​‌‌‌‍‍‌​‍⁠‌⁠‌‌‌​⁠‍​⁠‌⁠‌​‍‍‌⁠​‌​⁠‌⁠‌​‍‌​‍​‍‌⁠⁠‌​​