We are starting to arrive at the conclusion that it is the people who make our organisations insecure. Unpatched humanoid-operating-systems [HoS] are the very beings which can make wrong decisions, at the wrong time. The real inherent danger of the unpatched HoS is, it also has the ability to cover its own tracks, and hide its woeful actions. So, recognising that this conventional methodologies alone of delivering security education dont always work, maybe we need to look elsewhere.”]
Source: https://informationsecuritybuzz.com/articles/curly-hair-dont-work-for-security-awareness/