Compass IT Compliance Blog / Security Awareness Training

Security Awareness Training for SOC 2: What Your Auditor Expects

Security Awareness Training for SOC 2: What Your Auditor Expects

On March 15, 2026, the Chittenden Solid Waste District of Vermont lost $3 million to a single phishing attack. That was not a rounding error in someone’s budget; it was a significant portion of the district’s annual funding, gone in the span of a few fraudulent emails.

Read Story

How Human Error Causes Cybersecurity Breaches

How Human Error Leads to Cybersecurity Concerns

Most organizations invest in firewalls, encryption, and sophisticated security tools. Yet despite these technological defenses, humans remain the weakest link in the cybersecurity chain. A single misplaced click, a reused password, or a moment of distraction can unravel even the most …

Read Story

What Is the Best Way to Train Employees on Cybersecurity Awareness?

What Is the Best Way to Train Employees on Cybersecurity Awareness

In today’s connected world, cybersecurity is not just the responsibility of the IT department. Every employee plays a role in protecting company data and systems from threats. With human error contributing to the majority of security incidents, organizations that invest in effective c …

Read Story

Cybersecurity Culture + Technology: Why You Need Both

How Culture & Technology Work Together to Strengthen Cybersecurity

In cybersecurity, it is easy to get caught up in the excitement of new technology. Every year, new tools promise sharper visibility, faster detection, and tighter control over threats. Organizations invest heavily in endpoint protection, firewalls, SIEM platforms, and automation syste …

Read Story

What Are the Best Ways to Prevent Social Engineering Attacks?

Best Ways to Prevent Social Engineering

When I give speeches or training sessions on social engineering, I always start with a simple mantra: V & V—Verification and Validation. It's not flashy, but it's foundational. My bet is that if you verify and validate everything, no social engineering (SE) attack can succeed. I'v …

Read Story

Why Is Social Engineering a Threat to Businesses?

Social Engineering Dangers

When most people think of cybersecurity threats, they picture viruses, ransomware, or brute-force attacks hammering away at firewalls. But some of the most effective attacks don’t need advanced code or malware. They just need a willing person to pick up the phone, click a link, or tru …

Read Story

Subscribe by email