
Hosted by Voice+Code
Cybersecurity is complex. Its user experience doesn’t have to be. Heidi Trost interviews information security experts about how we can make it easier for people - and their organizations - to stay secure.
59 episodes · publishes fortnightly · latest 2025-08-25 · ~39 min/episode
Rank
#314
Substance
78.6
/ 100
Breakdown
Scored 2026-07
Updated monthly
Across the index
#314 of 6182
Substance
Top 5%
outscores 95% of the index
Human-Centered Security ranks #314 on The B2B Podcast Index with a substance score of 78.6 out of 100, scored across 5 recent episodes. It scores highest on guest caliber and insight density. Ariana Mirian is a strong guest: PhD researcher from UC San Diego with direct involvement in enterprise security measurement research, currently a Senior Security Researcher at Censys. She has credibility as a practitioner-researcher with real institutional collaboration (UCSD Health, UCSD IT). She brings domain expertise and has published peer-reviewed work. However, she is primarily an academic researcher rather than an operator who has built or run security operations at massive scale in a commercial context.
Averaged across 5 recently scored episodes, with cited evidence.
The episode delivers solid empirical findings (2% average reduction, 20% reduction for interactive training users, 1-30% failure rate variance by lure type) with thoughtful measurement discussion. However, significant portions are consumed by banter, background-setting, and conversational padding. The core insights - that standard phishing training has minimal real-world effect because users don't engage with it, and that lure type matters more than training modality - are valuable but could be extracted more densely.
“the majority spent less than like 10 seconds or 30 seconds on it”
“there was about a 2% difference in average failure rate than folks who didn't get training...is all of this effort, all of this energy, all of this money worth a 2% reduction”
The work is original in execution (rigorous randomized controlled trial with real enterprise data, pre/post measurement of engagement), but the core finding - that security training has limited efficacy - is not new. The paper cites Lane et al. reaching similar conclusions. The framing around measurement rigor and the specific finding about engagement rates are novel, but the fundamental insight (training doesn't work well) is somewhat established in the literature.
“we were able to embed some metrics into the training that allowed us to see how long people were spending on the training”
“Lane et. al., was one of the ones that came before our paper. And they found, you know, very similar results, which is that phishing training has little to limited effect”
Ariana Mirian is a strong guest: PhD researcher from UC San Diego with direct involvement in enterprise security measurement research, currently a Senior Security Researcher at Censys. She has credibility as a practitioner-researcher with real institutional collaboration (UCSD Health, UCSD IT). She brings domain expertise and has published peer-reviewed work. However, she is primarily an academic researcher rather than an operator who has built or run security operations at massive scale in a commercial context.
“I currently work as a senior security researcher over at Censys, which is like the internet map of all devices and things on the world”
“we were very fortunate...to have a very close-knit relationship with like both the UCSD IT folks, and also the folks over at UCSD Health”
The episode provides concrete metrics: 2% average failure rate difference, ~19-20% reduction for interactive training engagers, 1-30% variance by lure type, majority spending under 10-30 seconds on training, 8 months of data, ~20,000 employees, specific training modalities (static generic, static contextual, interactive variants), and named lure examples (vacation policy, traffic violation, password reset). However, exact statistical significance thresholds, confidence intervals, and the specific phishing lures deployed are not all detailed in the conversation.
“there was about a 2% difference in average failure rate”
“interactive training, right, can reduce the likelihood of clicking on subsequent phishing emails by something like 20%...the actual number is 19”
Heidi asks relevant follow-up questions (research questions, dataset composition, why reporting wasn't tracked, recommendations) and shows genuine curiosity. However, much conversation is filler (background stories, tangents about moms, TikTok dancing, parking tickets, the Friday vibe, 'Phish Hoover' riffing) that delays substantive discussion. There are few probing disagreements or sharp pushes on findings; the host is warm but doesn't deeply challenge claims or drill into limitations of the measurement approach.
“One thing I wanted to ask you about...you, one of the things that you did not track was how many folks reported the phishing email, right?”
“if we pooled all of the money that we've spent/wasted on, on these, these trainings, could we have just built a better system?”
First period on the Index - history builds from here.
7 scored on substance · 59 tracked in total.
No Threat Intel Team? No Problem. Let’s Pretend You Do! with Mike Kosak
2025-08-25 · 50 min
We Regret to Inform You: Your Phishing Training Did Nothing with Ariana Mirian
2025-07-16 · 47 min
XDR, EDR, SIEM, SOAR…Snooze: Cybersecurity Marketing Real Talk with Gianna Whitver
2025-05-29 · 34 min
Human-Centered Security In the Wild: Jordan Girman and Mike Kosak On Security and Product Team Collaboration at Lastpass
2025-04-07 · 40 min
From Tools to Teammates: (Dis)Trust in AI for Cybersecurity with Neele Roch
2025-01-02 · 37 min
Introducing Human-Centered Security: The Book
2024-12-11 · 32 min
Threat Actors Leverage Behavioral Science; Security Teams Should, Too with Matt Wallaert
2024-12-05 · 39 min
Add this badge to your site - it links back here and updates automatically as you rank.
<a href="https://index.fame.so/show/human-centered-security" target="_blank" rel="noopener">
<img src="https://index.fame.so/badge/human-centered-security/badge.svg" alt="Ranked #41 on The B2B Podcast Index" width="360" height="136" />
</a>Track Human-Centered Security's rank
Get an email whenever this show moves up or down the Index. Monthly at most, no spam.
The themes that come up most across this show's episodes.
Podcasts that dig into the same topics.