Generated by All in One SEO v5.0.0.1, this is an llms.txt file, used by LLMs to index the site. # Arun Vishwanath, Ph.D., MBA Dr. Vishwanath studies the “people problem” of cybersecurity. ## Sitemaps - [XML Sitemap](https://www.arunvishwanath.us/sitemap.xml): Contains all public & indexable URLs for this website. ## Posts - [Drowning in Security Data, Starving for Human Insight](https://www.arunvishwanath.us/2026/06/01/drowning-in-security-data-starving-for-human-insight/) - Organizations have become exceptionally good at measuring cybersecurity activity—but far less effective at interpreting what it means. Most organizations today are not short on cybersecurity data. They are overwhelmed by it. Phishing simulations, reporting rates, user behavior, threat feeds, audit outputs—signals are everywhere. Dashboards are full. Reports are circulated. Metrics are defended. And yet, ask - [How Security Awareness Has Undermined Real Email Communication](https://www.arunvishwanath.us/2026/02/04/how-security-awareness-has-undermined-real-email-communication/) - Phishing emails are everywhere. You are far more likely to receive phishing and spam messages than legitimate ones. Over the years, I have written about this problem using a term I still find useful: email hygiene. By that, I did not just mean inbox cleanup or filtering rules, but the cognitive-behavioral conditions under which email - [Why Cybersecurity Awareness Training Still Isn’t Working. And What Needs to Change](https://www.arunvishwanath.us/2025/11/18/why-cybersecurity-awareness-training-still-isnt-working-and-what-needs-to-change/) - Each October, organizations around the world dust off their cybersecurity awareness modules, launch another round of phishing tests, and reassure themselves that “training” is making people safer. But a decade’s worth of research—including a recent Cybersecurity Dive feature by Eric Geller, where I was interviewed—shows something uncomfortable: most of these efforts don’t meaningfully change behavior. - [The Death Of Security Awareness Training: Why AI Is Making It Obsolete](https://www.arunvishwanath.us/2025/02/19/the-death-of-security-awareness-training-why-ai-is-making-it-obsolete/) - The Problem: AI-Powered Phishing Is Unstoppable On August 10, 2024, I received an email from Disney+ reminding me to renew my subscription. As a cybersecurity expert, I scrutinized it carefully—checking the sender’s address, domain legitimacy, and authentication records. Everything seemed authentic. Yet, it wasn’t. The email was part of a sophisticated phishing campaign that exploited Post Title: The End of Security Awareness Training? How AI Is Reshaping Cyber Defense Meta Description: Traditional security awareness training is becoming obsolete as AI-driven phishing and deepfake attacks grow more sophisticated. Learn how adaptive security, dynamic policies, and AI-driven trust mechanisms are redefining cybersecurity. #CyberSecurity #AIThreats - [Safeguarding Our Children's Digital Future: A Call to Action](https://www.arunvishwanath.us/2023/12/19/safeguarding-our-childrens-digital-future-a-call-to-action/) - Imagine the shock of receiving communication from a hacker saying that your child's most sensitive information — from passports and birth certificates to profile pictures and classroom locations — will be exposed on the Internet unless their school administrators pay a ransom. This horrifying situation recently occurred in Nevada's Clark County School District (CCSD), the nation's - [How many degrees separate you from a hacker?](https://www.arunvishwanath.us/2023/04/21/it-may-not-matter-how-close-you-are-to-tom-cruise-but-it-matters-how-close-you-are-to-a-hacker/) - Degrees of separation can tell you how likely you are to being hacked. The degrees separating you can reveal your risk of getting hacked. Take this free 8-question quiz and find out how many degrees separate you from a hacker: https://0oxloyflc3p.typeform.com/to/mTc2sV8Q. The answer will instantly reveal your likelihood of being hacked. Degrees imply steps — - [Build Security Around Users: A Human-First Approach to Cyber Resilience [Published in Dark Reading]](https://www.arunvishwanath.us/2023/02/28/build-security-around-users-a-human-first-approach-to-cyber-resilience-published-in-dark-reading/) - Security is more like a seat belt than a technical challenge. It's time for developers to shift away from a product-first mentality and craft defenses that are built around user behaviors. Technology designers begin by building a product and testing it on users. The product comes first; user input is used to confirm its viability - [Time to Change Our Flawed Approach to Security Awareness [Published in Dark Reading]](https://www.arunvishwanath.us/2023/02/28/time-to-change-our-flawed-approach-to-security-awareness-published-in-dark-reading/) - Defend against phishing attacks with more than user training. Measure users' suspicion levels along with cognitive and behavioral factors, then build a risk index and use the information to better protect those who are most vulnerable. As Russian tanks creaked into Ukraine, CEOs and IT managers throughout the United States and much of - [Stopping Russian Cyberattacks at Their Source [Published in Dark Reading]](https://www.arunvishwanath.us/2022/03/28/stopping-russian-cyberattacks-at-their-source/) - In 2016, Lazarus, a notorious hacking group, aimed to steal a billion dollars through the SWIFT interbank communication system. How did the group do it? Social engineering. Using an innocuous email purporting to be from a job applicant, the hackers gained entry into Bangladesh's central bank system almost a year earlier. Once in, they learned - [The end of the beginning of COVID-19 [Published in Medium]](https://www.arunvishwanath.us/2022/01/31/the-end-of-the-beginning-of-covid-19/) - Many are starting to say that pandemic is near its end. That this is the last strain, the final gasp of the virus. But is it the end of the pandemic? Or is it, as Churchill once said, just the end of the beginning. The virus, now in its third year, has infected people in all continents - [The failures that led to the Colonial Pipeline ransomware attack [Published in CNN]](https://www.arunvishwanath.us/2021/05/18/the-failures-that-led-to-the-colonial-pipeline-ransomware-attack/) - An earlier version of this post appeared on CNN By now, we have all heard about last week's Colonial Pipeline ransomware attack that caused a shutdown of the 5,500-mile pipeline responsible for carrying fuel from refineries along the Gulf Coast to New Jersey. The disruption led to stranding gasoline supplies across half the East coast, - [The Colonial Pipeline Hack Was Avoidable](https://www.arunvishwanath.us/2021/05/12/the-colonial-pipeline-hack-was-avoidable/) - The Colonial Pipeline hack is now making the news and many cyber security experts are providing their take on how to recover from it. Of course, while this attack is new, such attacks aren't. The Sony Pictures hack was also ransomware. And in 2016, there were many such attacks occurring. In response to them, I'd written - [Mobile telephony is dying [Published in iPswitch]](https://www.arunvishwanath.us/2020/10/01/mobile-telephony-is-dying/) - Verizon, AT&T, T-Mobile–I hope you are reading this. Mobile telephony, your primary business model of enabling phone calls and text messaging, is dying. Your internal data likely says otherwise. Growth just appears to be everywhere: 5G’s enhanced mobile broadband speeds are coming alive, more people are subscribing with more gadgets, and some 60% of Americans - [Why do we still teach our children ABC? [Published in Medium]](https://www.arunvishwanath.us/2020/09/15/why-do-we-still-teach-our-children-abc/) - “Why do you teach me ABC?” My precocious preschooler pointed to the virtual QWERTY keyboard on the tablet: “Why not ASD?” As someone who studies the diffusion of innovations — how people learn and adopt new ideas and techniques — I wondered why indeed? And not just the ABC sequence. Many preschoolers already know words like Xbox, Yahoo and - [Data Security In The Cloud: Part 2 [Published in iPswitch]](https://www.arunvishwanath.us/2020/09/15/data-security-in-the-cloud-part-2/) - Vulnerabilities in cloud-sharing services stem from the usage of multiple cloud services because of which users need to keep adapting and adjusting their exceptions. In part 1, I discussed some major vulnerabilities using cloud-sharing services caused. This included routine cloud usage leading to users opening emails from unknown addresses; complying with form-emails with no personalized - [How much cyber hygiene do you need? [Published in Medium]](https://www.arunvishwanath.us/2019/10/01/how-much-cyber-hygiene-do-you-need/) - Cyber hygiene: the term that is evoked whenever there is a threat to our infrastructure, a ransomware attack, or any data breach. It appears to be that elusive thing users never seem to have enough. But how does one get this cyber hygiene? Better yet, do we even know what it means? Or how much of it we - [Stop saying “Cyber Hygiene is like personal hygiene” [Published in Medium]](https://www.arunvishwanath.us/2020/02/15/stop-saying-cyber-hygiene-is-like-personal-hygiene-2/) - "Users should use a range of letters, numbers, and special characters on their passwords and change it every 90 days." If you are in IT, you have likely implemented this security policy. And if you are a user, you have likely endured it. The source of this best practice suggestion is a Burr, Dodson, and - [Data Security in the Cloud: Part 1 [Published in iPswitch]](https://www.arunvishwanath.us/2020/09/15/data-security-in-the-cloud-part-1/) - The adoption of public cloud computing makes user data less secure. And it's not for the reasons most in IT realize. In the first part of this series, I explain why; solutions follow in part 2. Most users experience the cloud as online software and operating environments (e.g., Google's App Engine, Chrome OS, Documents); and - [AI will replace trucker, retail workers, journalists–and you and I [Published in CNN]](https://www.arunvishwanath.us/2018/02/08/with-ai-we-may-have-created-ourselves-out-of-existence/) - Amazon Go, the online retailer's first completely automated store, debuted in Seattle last week. Using a bevy of smart cameras, deep machine learning and artificial intelligence (AI) algorithms, the store makes it possible for shoppers to simply pick up the products they like and go, with their accounts being automatically charged for the products -- - [The impact AI will have on democracy [Published in CNN]](https://www.arunvishwanath.us/2018/03/06/when-ai-writes-your-news-what-happens-to-democracy/) - In the not-so-distant future, we will be presented with the version of the news we wish to read -- not the news that some reporter, columnist or editorial board decides we need to read. And it will be entirely written by artificial intelligence (AI). Think this is science fiction? Think again. Many of us probably - [To reward, or not to reward [Published in InfoSecurity Magazine]](https://www.arunvishwanath.us/2018/08/02/to-reward-or-not-to-reward/) - In late 2014, in the aftermath of the Sony Pictures Entertainment breach, I had advocated the development of a cyber breach reporting portal where individuals could report suspected cyber incidents. Such a system, I argued, would work as an early warning system so IT could be made aware of an attack before it become widespread; - [COVID-19's Lessons About Social Engineering [Published in Dark Reading]](https://www.arunvishwanath.us/2020/06/14/covid-19s-lessons-about-social-engineering/) - Unless we do something proactively, social engineering's impact is expected to keep getting worse as people's reliance on technology increases and as more of us are forced to work from home. Contact tracing, superspreaders, flattening the curve — concepts that in the past were the domain of public health experts are now familiar to people - [Spearphishing has become even more dangerous [Published in CNN]](https://www.arunvishwanath.us/2018/09/14/stopping-the-russians-from-influencing-the-midterms/) - The continued prosecution of “All the President’s Men” does little to stop the Russians from attempting to influence America’s upcoming midterm elections. And reports from Missourito Californiasuggest they are already looking for our cyber weaknesses to exploit. Chief among these: spear phishing—emails containing hyperlinks to fake websites—that the Russians used to hack into the DNC - [The troubling implications of weaponizing the Internet [Published in Washington Post]](https://www.arunvishwanath.us/2019/07/13/the-troubling-implications-of-weaponizing-the-internet/) - Cyberwarfare suddenly went public late last month. Multiple media outlets reported that President Trump had authorized U.S. Cyber Command to conduct a cyberstrike on Iran. Obviously, this isn’t the first such attack by a nation, or even by the United States, on another — the Russians, Chinese and North Koreans have their digital fingerprints on - [Why do so many people fall for fake profiles online? [Published in The Conversation]](https://www.arunvishwanath.us/2018/09/21/why-do-so-many-people-fall-for-fake-profiles-online/) - The first step in conducting online propaganda efforts and misinformation campaigns is almost always a fake social media profile. Phony profiles for nonexistent people worm their way into the social networks of real people, where they can spread their falsehoods. But neither social media companies nor technological innovations offer reliable ways to identify and remove - [Why smartphones are more susceptible to social attacks [Published in 2019 Verizon DBIR]](https://www.arunvishwanath.us/2019/05/10/why-smartphones-are-more-susceptible-to-social-attacks/) - Research points to users being significantly more susceptible to social attacks they receive on mobile devices. This is the case for email-based spear phishing, spoofing attacks that attempt to mimic legitimate webpages, as well as attacks via social media. [1], [2], [3] The reasons for this stem from the design of mobile and how users - [Improving Everyone’s Ability to Work from Home After the Pandemic [Published in IPSwitch]](https://www.arunvishwanath.us/2020/05/12/improving-everyones-ability-to-work-from-home-after-the-pandemic/) - Two out of three Americans with jobs are already working from home because of the pandemic. Many will have to continue if pandemic reoccurs. But millions are unable to and are without jobs, because of significant barriers imposed by technology, regulation, and organizational preparedness. One technological barrier is the lack of universal high-speed Internet connectivity. - [It's 2020: Do we need more cyber hygiene? [Published in InfoSecurity Magazine]](https://www.arunvishwanath.us/2020/01/23/its-2020-do-we-need-more-cyber-hygiene/) - This month we learned that a US maritime base had to be taken offline for more than 30 hours because of a ransomware attack that interrupted cameras, doors, and critical monitoring systems. It’s not the first such attack, and it’s most definitely not the last. Following it will be the usual drumbeat: a call for - [Stopping the Dark Triad from impacting our response to COVID-19 [Published in IPSwitch]](https://www.arunvishwanath.us/2020/05/12/stopping-the-dark-triad-from-impacting-our-response-to-covid-19/) - Last week, New York City Mayor Bill de Blasio warned residents of a widespread Twitter and text-message circulated misinformation campaign falsely claiming that Manhattan was under quarantine. Around this time, Attorney General Barr and U.S. Attorneys from various states were also warning residents of spear phishing emails, fake websites, local phone area code or neighbor- - [How to fight cybercrime with smarter habits [Published in The Conversation]](https://www.arunvishwanath.us/2015/01/29/how-to-fight-cybercrime-with-smarter-habits/) - Hackers gain access to computers and networks by exploiting the weaknesses in our cyber behaviors. Many attacks use simple phishing schemes – the hacker sends an email that appears to come from a trusted source, encouraging the recipient to click a seemingly innocuous hyperlink or attachment. Clicking will launch malware and open backdoors that can - [Who is to blame for cyberattacks? [Published in The Conversation]](https://www.arunvishwanath.us/2015/02/26/who-is-to-blame-for-cyberattacks-cnn/) - The theft of 80 million customer records from health insurance company Anthem earlier this month would be more shocking if it were not part of a larger trend. In 2013, the Department of Defense and some US states were receiving 10–20 million cyberattacks per day. By 2014, there was a 27% increase in successful attacks, - [Why the cyber attacks keep coming [Published in CNN]](https://www.arunvishwanath.us/2015/06/08/why-the-cyber-attacks-keep-coming/) - Last week, we learned that hackers allegedly working for the Chinese government breached personal information of some 4 million current and former federal employees. This latest episode is shocking in its scope, but security experts have long known about China's military-level cyberoffensive capabilities, with reports of an entire division of its army being devoted to - [When hackers turn your lights off [Published in CNN]](https://www.arunvishwanath.us/2016/02/11/when-hackers-turn-your-lights-off/) - Cybersecurity was in the news again this week as hackers released contact details of thousands of FBI and Homeland Security employees after claiming to have taken 200 GB of data from Department of Justice computers. But even as such breaches have started to feel almost routine, they are also taking a more troubling turn. Imagine - [When hackers turn your lights off [Published in CNN]](https://www.arunvishwanath.us/2016/02/11/when-hackers-turn-your-lights-off-2/) - Cybersecurity was in the news again this week as hackers released contact details of thousands of FBI and Homeland Security employees after claiming to have taken 200 GB of data from Department of Justice computers. But even as such breaches have started to feel almost routine, they are also taking a more troubling turn. Imagine - [Apple, want to show you really care? Protect us from everyday hacking [Published in CNN]](https://www.arunvishwanath.us/2016/03/02/apple-want-to-show-you-really-care-protect-us-from-everyday-hacking/) - Tuesday at the first congressional hearing on the issue of iPhone encryption, Apple's general counsel argued against the FBI's call for creating a backdoor into the company's technology, a door that could allow the government -- and hackers -- to intrude on our privacy in the future. Apple CEO Tim Cook's position -- supported by - [Is 2016 the year of online extortion?[Published in CNN]](https://www.arunvishwanath.us/2016/03/25/is-2016-the-year-of-online-extortion/) - his week, a hospital in western Kentucky was the latest organization to fall victim to a "ransomware" attack -- a class of malware that encrypts all the files on a computer, only releasing them when a ransom is paid to the hacker holding the encryption key. In this case, the hospital did not pay up. - [Time to rethink apps security [Published in CNN]](https://www.arunvishwanath.us/2016/04/01/time-to-rethink-apps-security/) - Even Steve Jobs could not see the potential of third-party mobile apps: those little software programs that turned our mobile phones into smartphones. Jobs had famously argued against such apps, instead advocating for the use of mobile web pages that could be accessed using iPhone's Safari browser. It reportedly wasn't until users began jail-breaking and - [Why we need a cyber wall [Published in CNN]](https://www.arunvishwanath.us/2016/05/02/why-we-need-a-cyber-wall/) - Donald Trump had the audience at his rally in California on Thursday chanting "build that wall," a reference to his pledge to build one along America's southern border. But while this pledge might not be in the country's best interests, there is actually somewhere that we really could use a wall: cyberspace. After all, this - [Cybersecurity’s weakest link: humans [Published in The Conversation]](https://www.arunvishwanath.us/2016/05/05/cybersecuritys-weakest-link-humans/) - There is a common thread that connects the hack into the sluicegate controllers of the Bowman Avenue dam in Rye, New York; the breach that compromised 20 million federal employee records at the Office of Personnel Management; and the recent spate of “ransomware” attacks that in three months this year have already cost us over - [Cyber security: It's not just about Yahoo [Published in CNN]](https://www.arunvishwanath.us/2016/09/30/cyber-security-its-not-just-about-yahoo/) - It's not surprising that some Yahoo users have decided to sue the company for negligence over a 2014 breach that was only recently discovered and announced. But before we blame Yahoo for this, we need to understand how hackers accomplish such breaches -- and what all of us should be doing better to prevent such - [“Spear-Phishing” Roiled the Presidential Campaign—Here’s How to Protect Yourself [Published in The Conversation]](https://www.arunvishwanath.us/2016/11/07/spear-phishing-roiled-the-presidential-campaign-heres-how-to-protect-yourself/) - Never in American political history have hacked and stolen emails played such a central role in a presidential campaign. But hackers are likely to target you as well—though perhaps with smaller repercussions for the world as a whole. Every one of October’s surprises, from the leaks of Clinton campaign chairman John Podesta’s purported emails to those of the - [How to protect the Internet [Published in CNN]](https://www.arunvishwanath.us/2017/01/11/how-to-protect-the-internet/) - FBI Director James Comey was on Capitol Hill with other intelligence leaders on Tuesday to testify over the various email breaches of Democratic National Committee computers during the election campaign. It is unclear whether the testimony -- or the analysis by 17 civilian and military intelligence agencies that all point to the role of Russia - [You are the key to keeping your computer safe [Published in CNN]](https://www.arunvishwanath.us/2017/06/28/you-are-the-key-to-keeping-your-computer-safe/) - Yet another major cyber extortion campaign is wrecking computer networks all over the world -- and we need to start thinking about cyber safety more comprehensively and include users in solving the problem. This effort must begin with an assessment of user risk, not just technical risk -- because all signs indicate that there is - [Is the new iPhone designed for cybersafety? [Published in The Conversation]](https://www.arunvishwanath.us/2017/09/12/is-the-new-iphone-desined-for-cybersafety/) - As eager customers meet the new iPhone, they’ll explore the latest installment in Apple’s decade-long drive to make sleeker and sexier phones. But to me as a scholar of cybersecurity, these revolutionary innovations have not come without compromises. Early iPhones literally put the “smart” in the smartphone, connecting texting, internet connectivity and telephone capabilities in one intuitive device. - [It's not just fake news, Facebook, or Twitter! It's the Internet's Dark Triad we should be worried about. [Published in CSO Online]](https://www.arunvishwanath.us/2017/11/30/its-not-just-fake-news-it-is-the-internets-dark-triad-we-should-be-worried-about/) - Thanks to the ongoing Senate hearings on election hacking we are learning about how the Russians interfered with our presidential elections by sponsoring numerous fake social media accounts and even placing advertisements on Facebook, YouTube and Google that targeted people with interest on divisive issues. But while policy makers are rightfully angered by these platforms’ - [Where's the outrage over the Sony hack? [Published in CNN]](https://www.arunvishwanath.us/2014/12/07/wheres-the-outrage-over-the-sony-hack/) - - Major crimes usually shake us into action. A London fire that killed five women ultimately led to the creation of 999, a precursor to our own 911 emergency system. The rape and murder of Kitty Genovese, meanwhile, inspired the creation of the neighborhood crime watch system. Yet while the Sony Pictures Entertainment email breach ## Pages - [Arun Vishwanath, Ph.D., MBA](https://www.arunvishwanath.us/) - Leading Expert in Cybersecurity and Human Behavior Arun Vishwanath is a distinguished scholar and practitioner at the forefront of addressing cybersecurity's "people problem." With a dynamic blend of expertise in cognitive-behavioral science and cybersecurity, he delves into how human vulnerabilities can be the linchpin in safeguarding or compromising cyber resilience. An internationally recognized figure, Dr. - [News Coverage](https://www.arunvishwanath.us/news-and-events/) - April 2026 NPR/WUFT: Phishing scams have long targeted Florida’s seniors. AI raises the stakes. March 2026 WKBW/ABC: iPhone privacy report: How to check which apps are tracking you and accessing your data January 2026 WBEN with Tom Bauerle: Arun Vishwanath on Ring Doorbell 'Search Party' feature showcased during the Super Bowl WBEN: Cybersecurity expert Arun - [Conference Papers](https://www.arunvishwanath.us/conference-papers/) - Dr.Arun Vishwanath Confrence paper is all about imparting digital cleanliness among clients and making a culture of digital security. - [Publications](https://www.arunvishwanath.us/publications/) - Heiding, F., Lermen, S., Kao, A., Verdun, C. M., Schneier, B., & Vishwanath, A. (2026). Evaluating Large Language Models’ Ability to Automate Spear Phishing. Expert Systems with Applications, 131546. Vishwanath, A. (2026). The beginning of the end of security awareness training: How AI marks a new era in cybersecurity. In Q. Zhu & C. X. - [About Dr Arun Vishwanath Buffalo](https://www.arunvishwanath.us/about-dr-arun-vishwanath-buffalo/) - Dr. Arun Vishwanath Buffalo is among the foremost experts on the “people problems” of cybersecurity. His research on the science of cybersecurity focuses on the biggest vulnerability in enterprise security - its users. His body of work includes the development of methodologies to quantify human cyber-risk, approaches to diagnose how and why people are at - [Invited Talks](https://www.arunvishwanath.us/invited-talks/) - August 2024: Dueling keynote on the state of security awareness with Perry Carpenter, Chief Security Awareness Evangelist with KnowB4 ConnectCon, Las Vegas. April 2024: Best practices for reviewing research papers in a program committee: NSA symposium on the Science of Security (HotSoS). August 2023: Humans are NOT a blackbox: Our understanding of human cyber risk, - [Unlock Your Cyber Risk Beliefs](https://www.arunvishwanath.us/cyber-risk/) - Unlock Your Cyber Risk Beliefs: Take the Quiz Now! Ever wondered why we fall for online deception? It's because our minds tend to fill in, have, or ignore gaps in what we encounter online. Understanding and measuring these gaps can significantly enhance our efforts in creating targeted and successful security awareness. Introducing Cyber Risk Beliefs - [Strengthening The Weakest Link](https://www.arunvishwanath.us/weakestlink/) - HOW TO DIAGNOSE, DETECT, AND DEFEND USERS FROM PHISHING By Arun Vishwanath From the book's publisher MIT Press: An expert in cybersecurity lays out an evidence-based approach for assessing user cyber risk and achieving organizational cyber resilience. Phishing is the single biggest threat to cybersecurity, persuading even experienced users to click on hyperlinks and attachments - [Your Hacker Connection Quotient](https://www.arunvishwanath.us/hacked/) - How Close Are You To Being Hacked? Uncover Your Connection Quotient Are You Closer to Tom Cruise or a Hacker? Ever wondered how closely you're connected to Hollywood superstar Tom Cruise or, perhaps surprisingly, a potential hacker? Find out in just eight quick questions with this interactive quiz! QUIZ LINK Discover the intriguing concept of - [CyberSecurity Musings](https://www.arunvishwanath.us/cybersecurity/) - Dr. Arun Vishwanath keeps you up-to-date with the latest cybersecurity musings. - [About Dr Arun Vishwanath](https://www.arunvishwanath.us/about-dr-arun-vishwanath/) - Arun Vishwanath is among the foremost experts on the "people problems" of cybersecurity. Dr Vishwanath's research on the science of cybersecurity focuses on the biggest vulnerability in enterprise security: its users. His body of work includes the development of methodologies to quantify human cyber-risk, approaches to diagnose how and why people are at risk through social - [Dr Arun Vishwanath, Buffalo, New York](https://www.arunvishwanath.us/dr-arun-vishwanath-buffalo-new-york/) - Dr. Arun Vishwanath, Buffalo, New York, studies the “people problem” of cyber security. Dr. Arun Vishwanath's research focuses on improving individual, organizational, and national resilience to cyber attacks by focusing on the weakest links in cyber security—all of us Internet users. His particular interest is in understanding why organizational insiders willingly exfiltrate sensitive organizational data; - [Dr Arun Vishwanath](https://www.arunvishwanath.us/bio/) - I am an expert on the “people problem” of cyber security. I have studied the social, cognitive, and behavioral aspects of user deception from a cyber security point of view two decades. Through this time, I have authored close to fifty peer-reviewed articles on social engineering, online deception, and its amelioration. I am an alumnus - [News & Events](https://www.arunvishwanath.us/news-events/) - [Contact](https://www.arunvishwanath.us/contact/) - Contact Dr. Arun Vishwanath from New York for speaking inquires at aruncyber911@gmail.com and for general inquires at arun@arunvishwanath.us - [Cybersecurity Musings](https://www.arunvishwanath.us/blog/) - Recent Posts Drowning in Security Data, Starving for Human Insight June 1, 2026 How Security Awareness Has Undermined Real Email Communication February 4, 2026 Why Cybersecurity Awareness Training Still Isn’t Working. And What Needs to Change November 18, 2025 The Death Of Security Awareness Training: Why AI Is Making It Obsolete February 19, 2025 Safeguarding - [Do We Need More Cyber Hygiene?](https://www.arunvishwanath.us/do-we-need-more-cyber-hygiene/) - Earlier this month we learnt that a US maritime base had to be taken offline for more than 30 hours because of a ransomware attack that interrupted cameras, doors, and critical monitoring systems. It’s not the first such attack. And it’s most definitely not the last. Following it will be the usual drumbeat that in ## Post Grid - [News](https://www.arunvishwanath.us/post_grid/news/) - [Cybersecurity](https://www.arunvishwanath.us/post_grid/cybersecurity/) - [White Papers](https://www.arunvishwanath.us/post_grid/561/) ## Categories - [Cybersecurity](https://www.arunvishwanath.us/category/cybersecurity/) - [White Paper](https://www.arunvishwanath.us/category/white-paper/) ## Tags - [Spear phishing](https://www.arunvishwanath.us/tag/spear-phishing/) - [fake profile](https://www.arunvishwanath.us/tag/fake-profile/) - [misinformation campaigns](https://www.arunvishwanath.us/tag/misinformation-campaigns/) - [midterm elections](https://www.arunvishwanath.us/tag/midterm-elections/) - [Russian influence](https://www.arunvishwanath.us/tag/russian-influence/) - [computer literacy](https://www.arunvishwanath.us/tag/computer-literacy/) - [cyber hygiene](https://www.arunvishwanath.us/tag/cyber-hygiene/) - [teaching and learning](https://www.arunvishwanath.us/tag/teaching-and-learning/) - [mobile telephony](https://www.arunvishwanath.us/tag/mobile-telephony/) - [vishing](https://www.arunvishwanath.us/tag/vishing/) - [smishing](https://www.arunvishwanath.us/tag/smishing/) - [phishing](https://www.arunvishwanath.us/tag/phishing/) - [cyber security](https://www.arunvishwanath.us/tag/cyber-security/) - [robocalling](https://www.arunvishwanath.us/tag/robocalling/) - [#ColonialPipeline](https://www.arunvishwanath.us/tag/colonialpipeline/) - [#ransomware](https://www.arunvishwanath.us/tag/ransomware/) - [#cybersecurity](https://www.arunvishwanath.us/tag/cybersecurity/) - [#usercyberrisk](https://www.arunvishwanath.us/tag/usercyberrisk/) - [#cyberattacks](https://www.arunvishwanath.us/tag/cyberattacks/) - [#cyberresilience](https://www.arunvishwanath.us/tag/cyberresilience/) - [#cyberdefense](https://www.arunvishwanath.us/tag/cyberdefense/) - [#russiancyberattacks](https://www.arunvishwanath.us/tag/russiancyberattacks/) - [AI Security](https://www.arunvishwanath.us/tag/ai-security/) - [Security Awareness Training](https://www.arunvishwanath.us/tag/security-awareness-training/) - [Phishing Defense](https://www.arunvishwanath.us/tag/phishing-defense/) - [Cyber Resilience](https://www.arunvishwanath.us/tag/cyber-resilience/) - [AI in Cybersecurity](https://www.arunvishwanath.us/tag/ai-in-cybersecurity/) - [Generative AI Threats](https://www.arunvishwanath.us/tag/generative-ai-threats/) - [Deepfake Phishing](https://www.arunvishwanath.us/tag/deepfake-phishing/) - [LLMs and Security](https://www.arunvishwanath.us/tag/llms-and-security/) - [AI-Driven Social Engineering](https://www.arunvishwanath.us/tag/ai-driven-social-engineering/) - [Cyber Threat Intelligence](https://www.arunvishwanath.us/tag/cyber-threat-intelligence/) - [Enterprise Security](https://www.arunvishwanath.us/tag/enterprise-security/) - [Security Awareness Programs](https://www.arunvishwanath.us/tag/security-awareness-programs/) - [Adaptive Security Policies](https://www.arunvishwanath.us/tag/adaptive-security-policies/) - [Zero Trust Security](https://www.arunvishwanath.us/tag/zero-trust-security/) - [Cybersecurity Research](https://www.arunvishwanath.us/tag/cybersecurity-research/) - [AI & Cybercrime](https://www.arunvishwanath.us/tag/ai-cybercrime/) - [Large Language Models (LLMs)](https://www.arunvishwanath.us/tag/large-language-models-llms/) - [Digital Identity Protection](https://www.arunvishwanath.us/tag/digital-identity-protection/) - [Future of Cyber Defense](https://www.arunvishwanath.us/tag/future-of-cyber-defense/) - [email hygiene](https://www.arunvishwanath.us/tag/email-hygiene/) - [governance](https://www.arunvishwanath.us/tag/governance/) - [Human Cyber Risk](https://www.arunvishwanath.us/tag/human-cyber-risk/) - [Behavioral Cybersecurity](https://www.arunvishwanath.us/tag/behavioral-cybersecurity/) - [Cyber Risk Management](https://www.arunvishwanath.us/tag/cyber-risk-management/) - [Security Culture](https://www.arunvishwanath.us/tag/security-culture/) - [Digital Trust](https://www.arunvishwanath.us/tag/digital-trust/) - [Cyber Governance](https://www.arunvishwanath.us/tag/cyber-governance/) - [AI Governance](https://www.arunvishwanath.us/tag/ai-governance/)