Make it realistic
Controlled phishing and social-engineering scenarios that look like the kind of messages people actually receive.
A geek-built cybersecurity awareness platform for the people who don't live in a SOC — but still have an inbox, a smartphone, a browser and someone trying to scam them.
$ cyberfamily start --target "my-family" [+] Loading scenario engine... [+] Selecting realistic attack simulation... [+] Generating unique sender / domain / landing page... [+] Delivering controlled phishing exercise... [+] Waiting for human interaction... [!] User clicked the link. [+] Training triggered. [+] Explain the indicators. [+] Turn the mistake into a skill. $ cyberfamily report --human-friendly Risk: understood Awareness: improved Panic: 0% Blame: 0%
Your family doesn't need another 45-minute cybersecurity presentation. They need to recognize the trap when the trap actually lands in their inbox.
Controlled phishing and social-engineering scenarios that look like the kind of messages people actually receive.
No boring quiz first. Give users a realistic situation and let them decide what to do.
When something goes wrong, show the clues: sender, domain, URL, urgency, context and the social-engineering trick.
PRINCIPLE_01 = "Train people, don't blame them." PRINCIPLE_02 = "Realistic beats theoretical." PRINCIPLE_03 = "A mistake is a learning opportunity." PRINCIPLE_04 = "Explain the attack, not just the answer." PRINCIPLE_05 = "Security awareness should be accessible." PRINCIPLE_06 = "Build it like an attacker. Defend like a human."
CyberFamily is built for the people who already know how this works:
the sysadmins, CISOs, security engineers and IT folks who have tried
— sometimes unsuccessfully — to explain to their friends and family
why paypal-security-login.example is probably not PayPal.
Instead of saying "be careful", give them a safe place to practice.