## What the 18-Year-Old Who Hacked Uber Knew About Your Employees

Security training should prepare people for the moments attackers actually create, across every channel they use. The wrong starting point is treating employees as a risk to be mitigated. Preparing them as the last line of defense, and actually equipping them for that role, is a different task entirely.

[Learn more](/content/insights/what-the-18-year-old-who-hacked-uber-knew-about-your-employees/index.html)

##### Insights

[**What the 18-Year-Old Who Hacked Uber Knew About Your Employees**  
Security training should prepare people for the moments attackers actually create, across every channel they use. The wrong starting point is treating employees as a risk to be mitigated. Preparing them as the last line of defense, and actually equipping them for that role, is a different task entirely.  
May 19, 2026](/content/insights/what-the-18-year-old-who-hacked-uber-knew-about-your-employees/index.html)

**Why Smart People Still Fall for Phishing**  
When someone clicks a phishing link, the response inside most organizations follows the same pattern. There's the incident report. There's the remedial training. And underneath all of it, there's an assumption that rarely gets questioned: that a smarter, more careful person would have caught it. That assumption is wrong, and it's expensive.  
May 7, 2026](/content/insights/why-smart-people-still-fall-for-phishing/index.html)

**Your Finance Team and Engineering Team Should Not Get the Same Security Training**  
Most security awareness platforms were built with compliance in mind, not learning. The goal was to get everyone through the content and generate a completion report. Role-specific delivery was an afterthought, if it was a thought at all. That made sense when attacks were more uniform and when the tooling didn't exist to do anything more sophisticated. It doesn't make sense now.  
Apr 23, 2026](/content/insights/your-finance-team-and-engineering-team-should-not-get-the-same-security-training/index.html)

**What Most Security Training Still Fails to Measure**  
You start the module. You realize it’s going to take a while. You half-pay attention for a minute, move it to the second monitor, click through the quiz, and get back to work. Whether any of it changed anything is a different question. That disconnect is why we need to start thinking about security awareness metrics differently -- because so much of this category is built around proving the training happened, not proving it did anything.  
Apr 19, 2026](/content/insights/what-most-security-training-still-fails-to-measure/index.html)

**Everyone's an Engineer Now. Your Security Program Wasn't Built for That**  
Claude Code, Codex, Copilot, and a growing pile of no-code tools have democratized software creation. An employee can have something functional running in minutes lunch. Something that handles critical data, sits on the internet, and makes decisions about permissions and access that used to belong to people who understood what those decisions meant. What does that mean for your security program?  
Apr 14, 2026](/content/insights/everyone-s-an-engineer-now.-your-security-program-wasn-t-built-for-that/index.html)

**The Problem Was Never Just Email**  
As the MGM breach demonstrated, traditional security awareness training has failed to keep pace with modern attackers. They now use hyper-personalized emails, phone calls, and AI-generated messages to bypass the red flags employees were taught to spot. The industry needs to evolve.  
Mar 19, 2026](/content/insights/the-problem-was-never-just-email/index.html)

## Security training that actually sticks.
