Cut Cybersecurity Training and You Triple Your Risk in 18 Months.
Another week, another headline, another breach!
Cut Cybersecurity Training and You Triple Your Risk in 18 Months.
Another week, another headline, another breach!
This time it is, Fake CAPTCHA IRSF Scam and 120 Keitaro Campaigns Drive Global SMS, Crypto Fraud: https://thehackernews.com/2026/04/fake-captcha-irsf-scam-and-120-keitaro.html

The usual disclosure
The reporting will focus on scale, impact, and cost. Millions of records exposed. Operations disrupted. Regulatory scrutiny. Reputational damage.
What is rare?
What you rarely see is a clear breakdown of how it actually started. Not the final payload. The first mistake.
Across most breaches, the pattern is consistent. The firewall is configured. The SIEM is ingesting logs. Endpoint protection is active. Controls are in place and, in many cases, working as designed.
Where are the failures coming from?
The failure sits elsewhere!
It sits in a moment where a person makes a decision without the context or training to recognise risk.
That moment may be small. A user approves a login request they did not initiate. A developer pushes code with a hardcoded credential. An analyst dismisses an alert because it looks similar to previous noise. A system administrator delays patching because of operational pressure.
Individually, these actions seem low impact. In sequence, they form an attack path.
I have worked with teams across finance, government, and private sector organisations across the world over the past 40 years. The gap is not effort. The gap is capability under real conditions and lack of training.
Most professionals understand basic security concepts. They know what phishing is. They know passwords should be strong. They know systems should be patched. They are trained to a certain extent and then it stops and they are left to deal with the chaos. All that knowledge (albeit not enough) does not always translate into action.
What is the big issue?
Real environments are noisy. Alerts compete for attention. Deadlines take priority and are sometimes unrealistic. People rely on habit. Attackers understand this and design campaigns that blend into normal workflow. This is where most organisations underestimate risk.
They invest heavily in technology. They measure coverage. They report on tool deployment. They assume that presence of controls equals effective defence.
It does not!
Where defence fails?
Effective defence depends on how well people are trained to understand and interpret signals, make decisions, and respond under pressure.
If those skills are not trained and reinforced, the organisation remains exposed regardless of how advanced the tooling is.
Security awareness programmes often fail because they are treated as compliance exercises. Annual modules. Generic content. No context. No measurement of real capability.
That approach creates a false sense of security.
What is effective defence?
What works is structured, role-based training that reflects actual attack scenarios. Analysts need to practise triage and escalation decisions. Developers need to understand how vulnerabilities are introduced in real code. Executives need to recognise business-level risk signals and response priorities.
Training must be continuous. Threats evolve. Tactics change. Skills degrade without use. Training courses and certifications such as CEH, CHFI, ECIH, CPENT, CISSP, CISA, CISM are just the start. Also they should be repeated by professionals because time changes all and Instructors (if they are in the field as cyber security professionals) bring more to the table than just training. They bring industry experience not found in courses and books.
A practical benchmark is simple. If your team has not had structured, scenario-based cyber security training in the last 12–18 months, your exposure is increasing and could be ten-fold in the next 12 months. This is your baseline!
This is not about blame. It is about ownership and accountability.
Leadership sets priorities. Budgets follow priorities. If training is not funded and scheduled, it does not happen. When it does not happen, the organisation relies on assumption rather than capability.
Recently in the past 18 months I have seen a reduction in training. This I have felt personally. However due to companies either sending people on training less frequently or none at all, the number of attacks have almost trippled.
Attackers do not rely on assumption. They test, iterate, and adapt and they train and learn all the time. Defenders need to do the same. So why are companies not do the same?
Every breach is a case study in decision failure. Not because people are careless, but because they were not prepared for the exact situation they faced.
That is the gap to close. Training your staff is paramount!
What is the biggest skills gap you have seen in your organisation?
CyberSecurity #SecurityAwareness #DataBreach #InfoSec #Training #CEH #CHFI #Training #Courses
메타데이터
- post_id
- be5309e98585
- slug
- cut-cybersecurity-training-and-you-triple-your-risk-in-18-months-be5309e98585
- url
- https://medium.com/@creative_40249/cut-cybersecurity-training-and-you-triple-your-risk-in-18-months-be5309e98585
- canonical_url
- https://medium.com/@creative_40249/cut-cybersecurity-training-and-you-triple-your-risk-in-18-months-be5309e98585
- author_url
- https://medium.com/@creative_40249
- status
- ok
- fetched_at
- 2026-06-12 18:14:10