Blog

Insights on Human Risk and Enterprise Security

Expert analysis, emerging trends, and the latest product, feature, and company innovations from the team redefining how enterprises think about user risk.

Founder POV
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Cybersecurity Training Gets Personal: The Dune Approach

Dune Security CEO David DellaPelle joins Wharton Tech Talks to discuss how AI and behavior-based intelligence are reshaping the future of enterprise cyber defense.

Minutes to listen:
34 min listen
Featured Podcasts

Deepfakes, DMs, and Deception: Dune Security on Human Cyber Risk

Dune Security’s CEO and SHI’s field CISO discuss how AI, multi-channel attacks, and user risk are transforming cybersecurity and how to adapt defenses effectively.

Minutes to listen:
16 min listen
Featured Podcasts
A glitched portrait illustrating the human vulnerability in cybersecurity and how social engineering targets users inside enterprises.

How Social Engineering Exploits Human Behavior in Enterprises

Learn how social engineering weaponizes human behavior and organizational trust, turning routine business processes into costly avenues for enterprise compromise.

Minutes to listen:
Blog

Finance worker pays out $25 million after video call with deepfake ‘chief financial officer’

A finance worker at a multinational firm was tricked into paying out $25 million to fraudsters using deepfake technology to pose as the company’s chief financial officer in a video conference call, according to Hong Kong police.

Minutes to listen:
Industry News

Closing Out Cybersecurity Awareness Month: 5 Key Takeaways in the Fight for User Resilience

October may be over, but the fight for user resilience continues – see how Dune helped turn awareness into action this Cybersecurity Awareness Month.

Minutes to listen:
Blog

Gmail Passwords Confirmed As Part Of 183 Million Account Data Leak

Earlier this year, I reported on a data leak that included a whopping 184,162,718 passwords and logins impacting the likes of Apple, Facebook and Instagram users.

Minutes to listen:
Industry News
Graphic promoting Cyber Happy Hour & Panel: Deepfakes + Synthetic Media hosted by Dune Security and Reality Defender at Cooley LLP.

Dune Security and Reality Defender Team Up at Cooley LLP to Tackle the Rise of Deepfake and Synthetic Media Threats

Deepfakes have emerged as one of the most pressing enterprise threats, capable of eroding trust and triggering costly decisions in seconds. Dune Security and Reality Defender gathered industry leaders at Cooley LLP to explore how organizations can keep up with today’s most advanced threats at scale.

Minutes to listen:
Blog

Legacy Security Awareness Training Doesn’t Reduce User Risk

As cyber threats grow more sophisticated, fueled by AI and targeting human behavior, traditional security awareness training is no longer enough. Organizations need a smarter, user-focused approach that not only identifies individual risk but actively reduces it in real time.

Minutes to listen:
Industry News
Cybercriminals connected to a recent string of ransomware attacks on major British retailers said on Friday they had stolen almost 1 billion records from cloud technology giant Salesforce, opens new tab by focusing on companies that use its software.

Almost 1 billion Salesforce records stolen, hacker group claims

Cybercriminals connected to a recent string of ransomware attacks on major British retailers said on Friday they had stolen almost 1 billion records from cloud technology giant Salesforce, opens new tab by focusing on companies that use its software.

Minutes to listen:
Industry News
Image of a face illuminated by light, symbolizing vigilance and building user resilience this Cybersecurity Awareness Month.

Dune Security Launches Resource Calendar to Help Teams Fight Back This Cybersecurity Awareness Month

Cybercriminals are training every day – but this October, we’re hitting back harder. Our new Resource Calendar helps security teams meaningfully engage employees, strengthen culture, and build resilience all month long.

Minutes to listen:
Blog
Dune Security announces new partnership with the National Cybersecurity Alliance (NCA) to support Cybersecurity Awareness Month and promote user risk reduction.

Dune Security Joins the National Cybersecurity Alliance to Champion Cybersecurity Awareness Month

Dune Security has joined forces with the National Cybersecurity Alliance to champion Cybersecurity Awareness Month. Together, we’re working to strengthen the human layer of cybersecurity and equip employees to stay safe online against modern threats.

Minutes to listen:
Blog

CyberVault Podcast: Why Security Awareness Training Fails with David DellaPelle

David DellaPelle, Co-Founder and CEO of Dune Security, joined The CyberVault Podcast to discuss why most security awareness programs fall short and what it takes to build a true human-first security culture.

Minutes to listen:
21 minutes
Featured Podcasts

Insecure Agents Podcast: Weaponizing AI with Kyle Ryan

Kyle Ryan, Head of Artificial Intelligence at Dune Security, joined the Insecure Agents podcast to discuss how advanced threat actors are weaponizing AI and the human vulnerabilities they exploit.

Minutes to listen:
21 minutes
Featured Podcasts

Tech Optimist Podcast: User Error in Cybersecurity

David DellaPelle, Co-Founder and CEO of Dune Security, joined Alumni Ventures CEO Mike Collins to discuss how Dune is tackling one of the most common causes of cybersecurity breaches: employee error.

Minutes to listen:
66 minutes
Featured Podcasts

The Hustle Daily Show: The Billion-Dollar Value of Cybersecurity Startups

David DellaPelle, CEO of Dune Security, joined The Hustle Daily Show to discuss the billion-dollar value of cybersecurity startups, why the industry is booming, and how to break into it.

Minutes to listen:
22 minutes
Featured Podcasts

Cyber Security Matters Podcast: Tackling Social Engineering Prevention

David DellaPelle, Co-Founder and CEO of Dune Security, joined the Cyber Security Matters Podcast to discuss defending against social engineering, the rise of deepfakes, and his journey as a cybersecurity entrepreneur.

Minutes to listen:
34 minutes
Featured Podcasts

The Security Sessions Podcast: Deepfakes & AI with Kyle Ryan

Kyle Ryan, Head of AI Engineering at Dune Security, joined The Security Sessions Podcast to discuss how hackers are weaponizing AI and deepfakes to target organizations, and what can be done to stop them.

Minutes to listen:
33 minutes
Featured Podcasts

The ITSM Practice Podcast: Future-Proofing Cybersecurity

Kyle Ryan, Head of AI and Backend Engineering at Dune Security, joined The ITSM Practice Podcast to discuss the rise of AI-enhanced phishing and how data-driven, behavior-based defenses are helping security teams stay ahead.

Minutes to listen:
10 minutes
Featured Podcasts

Security Architecture Podcast: Securing Tomorrow

David DellaPelle, Co-Founder and CEO of Dune Security, joined the Security Architecture Podcast to discuss Dune’s mission to reduce attack surfaces, counter AI-powered social engineering, and build resilient security cultures.

Minutes to listen:
25 minutes
Featured Podcasts

The ITSM Practice Podcast: Exploring Scattered Spider Cloud Attacks

Tarun Ramesh, Senior Backend Engineer at Dune Security, joined The ITSM Practice Podcast to discuss how Scattered Spider and similar threat groups exploit cloud environments using advanced social engineering and defense strategies.

Minutes to listen:
8 minutes
Featured Podcasts

Inside the Round Podcast: Building Dune Security with David DellaPelle

Dune Security Co-Founder and CEO David DellaPelle joined the Inside the Round Podcast to share how Dune is tackling user risk and what it takes to build a modern cybersecurity company from the ground up.

Minutes to listen:
37 minutes
Featured Podcasts
The Dune Security team standing in front of a six-story Times Square billboard showcasing the company’s mission to prevent insider threats, reduce user risk, and protect enterprises from social engineering attacks and AI risks.

Dune Security Takes Over Times Square

In less than three years, Dune Security has grown from an idea into a platform trusted by Fortune 1,000 enterprises. Our Times Square milestone celebrates that journey and our mission to stop insider threats and social engineering at scale.

Minutes to listen:
Blog

AI in Action Podcast: Fighting Cyber Threats with AI

Kyle Ryan, Senior Manager of Engineering and AI at Dune Security, joined the AI in Action Podcast to discuss how generative AI is fueling hyper-personalized phishing and multi-channel social engineering, and how Dune is replicating these threats to lower user risk and strengthen enterprise defenses.

Minutes to listen:
21 minutes
Featured Podcasts
Glitched digital portrait symbolizing AI manipulation and deepfake exploitation, representing the Dune Security and Reality Defender partnership to fight synthetic media fraud with behavioral risk intelligence and AI-driven user protection.

Reality Defender, Dune Security partner to tackle fraud from two angles

Technical blocks and employee training combine to protect the user layer

Minutes to listen:
Industry News

US Investment in Spyware Is Skyrocketing

A new report warns that the number of US investors in powerful commercial spyware rose sharply in 2024 and names new countries linked to the dangerous technology.

Minutes to listen:
Industry News

CISOs, stop chasing vulnerabilities and start managing human risk

Breaches continue to grow in scale and speed, yet the weakest point remains unchanged: people.

Minutes to listen:
Industry News

How Effective Is Corporate Cybersecurity Training? Not Very, It Seems

A new study suggests that employees fall for phishing scams at about the same rate, whether they’ve had legacy training or not

Minutes to listen:
Industry News

Dune Security Is Now Available on AWS Marketplace

Dune Security is now available on AWS Marketplace, allowing enterprises to deploy User Adaptive Risk Management through AWS for faster protection against social engineering and insider threats.

Minutes to listen:
Blog

Innovator Spotlight: Dune Security

Cyber Defense Magazine spotlights Dune Security for redefining user security through multi-channel simulations, adaptive training, and real-time risk scoring that deliver measurable results.

Minutes to listen:
Industry News
Modern glass skyscrapers representing interconnected enterprise infrastructure, highlighting lateral movement risks in cybersecurity and the need for user layer threat detection.

Lateral Movement: How Attackers Expand Access After Initial Compromise

Lateral movement turns a single compromise into an enterprise-wide breach. Learn how attackers spread, why it evades detection, and how CISOs can contain it.

Minutes to listen:
Blog
Dune Security and Reality Defender announce new cybersecurity partnership to stop deepfake attacks and AI-generated media threats targeting employees.

Dune Security and Reality Defender Partner to Stop AI-Generated Media Threats Targeting Enterprises

Deepfakes and AI-generated attacks are targeting employees faster than legacy tools can keep up. Dune Security and Reality Defender are partnering to deliver layered protection against these threats, combining real-time detection with user layer intelligence.

Minutes to listen:
Blog

Cybercriminals Use AI to Create Fake Websites That Look Just Like the Real Thing

As scammers expand their targets beyond large companies, cybersecurity experts urge consumers to study web addresses carefully.

Minutes to listen:
Industry News
Businessman on mobile phone, illustrating how vishing attacks use voice-based social engineering to impersonate trusted contacts and bypass enterprise security.

What Is Vishing? How Voice Phishing Works and How to Stop It

Vishing attacks use voice-based social engineering to bypass traditional defenses. Learn how attackers exploit urgency, trust, and AI-generated audio to trigger breaches – and what enterprises must do to stop them.

Minutes to listen:
Blog

FBI Sounds Alarm As Airline Cyber Threats Escalate

The FBI confirmed that Scattered Spider, one of the most dangerous and sophisticated cybercrime gangs operating today, is now targeting the airline industry.

Minutes to listen:
Industry News

Third-Party Access Is the New Insider Threat

Third-party breaches now drive 30% of incidents. Learn how attackers use valid vendor credentials to move undetected, escalate access, and operate like insiders inside your network.

Minutes to listen:
Blog

16 billion passwords exposed in record-breaking data breach: what does it mean for you?

Several collections of login credentials reveal one of the largest data breaches in history, totaling a humongous 16 billion exposed login credentials. The data most likely originates from various infostealers.

Minutes to listen:
Industry News

Scattered Spider Behind Cyberattacks on M&S and Co-op, Causing Up to $592M in Damages

The April 2025 cyber attacks targeting U.K. retailers Marks & Spencer and Co-op have been classified as a "single combined cyber event."

Minutes to listen:
Industry News

How Hackers Are Turning Tech Support Into a Threat

Attacks on call centers lead to hundreds of millions of dollars in crypto thefts and disrupt retail sales.

Minutes to listen:
Industry News

Customer data possibly leaked in Aflac cyberattack, the third insurance hack this month

The Aflac breach potentially impacted files with customers’ Social Security numbers and health details.

Minutes to listen:
Industry News

‘Anthony from Staten Island’ said he developed a chat tool for Meta. His entire identity was fake.

A provider of identity verification and fraud tools was recently targeted by what appear to be multiple North Korean IT workers managing dozens of personas.

Minutes to listen:
Industry News

Financial aid fraud is on the rise. Here’s how scammers are stealing funds

As fake enrollments for online courses surge, some professors discover that no one in their classes is real.

Minutes to listen:
Industry News

Accenture: What we learned when our CEO got deepfaked

Rather than a mere advance in social engineering, deepfakes represent ‘a paradigm shift in the attack vector,’ says security lead Flick March

Minutes to listen:
Industry News

The Age of Realtime Deepfake Fraud Is Here

Fraudsters are able to change their race, facial hair, voice, and more during live video calls with very little effort. Scammers are already fooling the elderly and verification systems.

Minutes to listen:
Industry News

Former FBI agent thought he had seen it all in cybercrime. Then he became a corporate executive in charge of information security

For cybersecurity workers, 2021 was intense. There was the Russian-based ransomware attack on Colonial Pipeline, a key transit system for U.S. oil, that set off panic-buying at the gas pumps. Meanwhile, major U.S. meat packer JBS was shut down by yet another attack. And then there was the U.S. federal government, which suffered one of its worst cyber espionage breaches ever, due to aftershocks created by the hacking of software maker SolarWinds.

Minutes to listen:
Industry News

Fake job seekers are flooding U.S. companies that are hiring for remote positions, tech CEOs say

Companies are facing a new threat: Job seekers who aren’t who they say they are, using AI tools to fabricate photo IDs, generate employment histories and provide answers during interviews.

Minutes to listen:
Industry News
Stylized glowing email icon surrounded by digital debris, symbolizing the spread of phishing emails and Business Email Compromise attacks in corporate environments.

BEC Has Already Cost $55 Billion and AI Is Making It Worse

Business Email Compromise has already caused over $55 billion in losses. Now AI is scaling these attacks with deepfakes, voice clones, and urgent pretexts. Learn how modern BEC works and what CISOs can do to stop it.

Minutes to listen:
Blog

How Ghost Students Are Exploiting College Enrollment Systems to Steal Federal Aid

Criminal fraud rings are targeting college aid systems with fake student identities. These scams use automation, identity theft, and AI to steal financial aid, lock out real students, and overwhelm public institutions. Here’s how it works and what security leaders in higher ed need to know.

Minutes to listen:
Blog

How Employee Fatigue Drives Human Error in Cybersecurity

Employee fatigue fuels human error and cybersecurity breaches by creating behavioral blind spots attackers exploit through social engineering and cognitive overload. Replace static awareness training with adaptive, real-time protection built for enterprise-scale risk.

Minutes to listen:
Blog

ChatGPT in the Wrong Hands: How AI is Being Used in Cybercrime

Generative AI is reshaping enterprise cybersecurity by targeting trust, behavior, and user access. Learn how AI-powered threats bypass static defenses and what CISOs must do to protect the human layer.

Minutes to listen:
Blog

Why Static Defenses Leaves Enterprises Vulnerable to Insider Risk

Insider threats are costly and hard to detect. Learn why static defenses fail and how User Adaptive Risk Management stops insider breaches early.

Minutes to listen:
Blog

Deepfake Impersonation in Remote Hiring

Deepfake impersonation is reshaping insider threats in remote hiring. Learn how AI-generated applicants are bypassing interviews – and how to stop them.

Minutes to listen:
Blog

Quishing Explained: How QR Code Phishing Bypasses Enterprise Defenses

Quishing is a growing phishing threat that uses malicious QR codes to bypass enterprise defenses. Learn how it works and why traditional tools fall short.

Minutes to listen:
Blog
Piggy bank surrounded by Bitcoin symbols, set against a blurred cryptocurrency chart, representing pig butchering scams and fake investment platforms in the cryptocurrency space.

Pig Butchering Scams: A Rising Enterprise Threat Every CISO Must Understand

Learn how pig butchering scams use social engineering and fake crypto platforms to exploit human error and bypass enterprise defenses.

Minutes to listen:
Blog

Why Traditional Security Awareness Training Can’t Stop Phishing 3.0

Phishing 3.0 weaponizes human error across email, SMS, voice, and apps. Learn how attackers use AI-driven deception to bypass static defenses and how your team can respond in real time.

Minutes to listen:
Blog

From the Founder

View Linkedin
October 22, 2025

This week in NYC, we partnered with Reality Defender to host a Cyber Happy Hour & Panel: Deepfakes & Synthetic Media focused on the rising enterprise risk of AI-generated attacks.

October 9, 2025

Wow. Less than 3 years ago, Dune Security was a figment of my imagination. When I met Michael Waite, I knew that he was the catalyst to bring the vision to life.

Never Miss a Human Risk Insights

Subscribe to the Dune Risk Brief - weekly trends, threat models,
and strategies for enterprise CISOs.
Thanks for submitting the form!
Oops! Something went wrong while submitting the form.