Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Wednesday, 24 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Security Training Needs Google Maps, Not Christopher Columbus

The threat landscape is always changing and security training must continually change as well

by The Gurus
June 24, 2026
in News, Uncategorized
Security Training Needs Google Maps, Not Christopher Columbus
Share on FacebookShare on Twitter

If you’re around my age, then you know the joy of using an old paper map. Not real joy, obviously. More the sort of joy normally associated with trying to keep track of 3 pages, getting told off for not holding it the right way up, or for giving instructions too late, and discovering that the road you were confidently following was replaced by a retail park sometime during the Blair years.

A paper map is only useful for as long as the world stays still. The moment roads change, roundabouts vanish, diversions appear, or somebody decides to turn half the town into a one-way system designed by a sadist, that map becomes less a guide and more a historical artefact. Lovely if you are Christopher Columbus. Less useful if you are trying to get to Leeds for a 10am meeting.

That, in essence, is how most security awareness training still works; like a paper map. Printed at a moment in time and handed out at scale. The content may well be fine. The design may be polished. But none of that changes the basic problem. It is static. The threat landscape is not.

Threats do not stand politely still while your annual training cycle catches up. Attackers change tactics constantly because they are trying to succeed, not preserve the integrity of your procurement process. Phishing lures are now shaped by AI, tuned to context, tailored to the individual, and adjusted faster than most organisations can update a slide deck. By the time next year’s awareness module rolls round, the threat it was designed to address has already had several costume changes and a passport renewal.

It’s also worth bearing in mind that people change too, not just the threats. The person who looked low risk six months ago may now be drowning in a new role, dealing with unfamiliar suppliers, handling pressure they did not have before, and are one rushed Friday away from making a regrettable decision. A static programme cannot see that. It cannot reroute. It cannot say there is trouble ahead, avoid this road, try this instead. It just sits there, insisting this field used to be the A41.

This is why custom training needs to look like something much closer to Google Maps. It needs to be responsive and personal. Aware of what is happening now, not what was true when the training content was commissioned and everyone still thought fax machines had a future. If there is a pile-up ahead, it should know. If one route is riskier than another, it should adjust. If someone is driving, cycling, walking, or taking public transport, it should understand that different people need different guidance depending on the context they are in.

Security awareness should work the same way. The new joiner does not need the same intervention as the finance director. The person who just failed a sophisticated phishing simulation does not need a generic reminder that phishing exists, in the same way a driver stuck behind a motorway collision does not need a note explaining that roads can sometimes be busy. They need timely guidance, based on what is happening around them, that helps them make a better decision in that moment.

That is what dynamic training does. It meets people where they are. It takes account of behaviour, context, pressure, patterns, and changes over time. It understands that behaviour change is not achieved by showing everyone the same video once a year and hoping muscle memory somehow forms out of corporate obligation.

Google Maps is also useful because it lets people contribute back. Spot an accident, a speed trap, a closed lane, and you can report it so others benefit. Security culture should have the same quality. If an employee spots something suspicious, reporting it should be easy, encouraged, and actually useful to everyone else. A phish alert button is not just a feature. It is your equivalent of warning the drivers behind you that there is a flaming bin lorry overturned in lane two. Shared visibility matters.

Then there is personalisation. Avoid toll roads. Avoid motorways. Take public transport. Walk instead. The route changes depending on what is sensible for you. Security training should be no different. Some users need more help. Some need less. Some are repeatedly targeted. Some are consistently resilient. Some need coaching in the moment. Some need reinforcement over time. Treating all of them the same is like telling a cyclist and an HGV driver to follow the identical route and then acting surprised when somebody ends up in a canal.

A decent security awareness programme should not behave like a souvenir map from the age of sail. It should behave like a living navigation system. It should reflect current threats, current users, current pressures, and current behaviours. It should help people avoid danger before they fall into it. It should learn. It should adapt. It should reroute.

Because if your training cannot tell the difference between the road as it was and the road as it is, then it is not guiding anyone anywhere. It is just nostalgia with branding.

Tags: Cybercybersecuritysecurity trainingtechTechnology
ShareTweet
Previous Post

Trump Sets Post-Quantum Security Deadlines as White House Warns of Advanced Cryptographic Threats

Recent News

Security Training Needs Google Maps, Not Christopher Columbus

Security Training Needs Google Maps, Not Christopher Columbus

June 24, 2026
Quantum computing: The data security conundrum

Trump Sets Post-Quantum Security Deadlines as White House Warns of Advanced Cryptographic Threats

June 23, 2026

Experts Warn: Passwords Still Winning Despite Passwordless Push

June 23, 2026
How Do Online Gaming Sites Keep Players and Their Data Safe?

KnowBe4 awarded in the email security industry

June 23, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol