Why Is 'Training' The Default Fix?
Tving just leaked the data of roughly 40 million users. Their immediate response? Company-wide privacy training.
It's a standard play. When a system breaks on this scale, management pivots to "awareness" because it turns a design flaw into a human error problem. If you blame the staff for not being aware enough, you don't have to admit your access controls are garbage.
I've seen this since 2003, and back when SOX was new, some firms thought an employee's signed acknowledgement form counted as a control. It didn't. A signature proves a document was handed over (nothing more), but it doesn't prove a risk was mitigated.
Take Revolut this week. They fell for fake government requests and lost sensitive customer data. Is that really a training gap? You don't fix social engineering by telling people to be careful. You fix it by building a verification workflow where the person getting the request physically cannot authorize the data release without a secondary confirmation from a verified source using an out-of-band method.
The failure is in the design, not the awareness.
Florida's DMV had SSNs and driver licenses leak through ShinyHunters. You'll probably see "security updates" or "staff reminders" in the press. But if someone can pull that much PII, your perimeter isn't just weak. It's gone.
This hits auditors and insurers hard next. For ages, audit firms have accepted "annual privacy training completion" as a main control for data protection, and they check the box, note 98% of staff finished the module, and sign off on the control environment.
When forty million records disappear, those workpapers look terrible. The auditor didn't verify if the training stopped unauthorized access. They verified people watched a PowerPoint. Now insurers see those same "controls" and raise premiums. Why? Because the risk isn't managed. It's performed.
The common objection is that humans are the weakest link. The industry argues that since you can't automate away every human interaction, training is your only line of defence.
That’s a lie used to justify lazy architecture.
People are the weakest link, and that's why building a security model around them is a mistake. You have to assume they'll click the link, and assume they'll fall for some fake government letter. A tight control environment works because it accepts that humans fail, and then makes sure that failure doesn't cost the company its reputation or millions in fines.
If your primary mitigation for a data breach is a training session, you aren't managing risk. You're doing theatre.
Think about it from the perspective of a CISO. What is the actual bill at the end of the year? If you're counting on "awareness" as your primary shield for a database, you aren't actually protected, and you're just preparing to pay a mountain of legal fees and regulatory fines.
I've been keeping an eye on how the SEC is tightening corporate governance training rules. It feels like a performance right now. But what happens when they stop asking if a course was finished and start asking if it actually worked? That's when the compliance officers will really panic.
Meanwhile, Connexa Sports is delaying its quarterly filing. I suspect their internals are as messy as the rest of these "trained" organizations.
Sources
The reporting this piece was written from. Check the originals before relying on anything here.
- Revolut confirms sensitive customer data breach, falling for fake government requests - KWSN Data Privacy (Google News)
- Florida Confirms DMV Breach as ShinyHunters Leak Exposes SSN Cards and Licenses - Hackread Data Privacy (Google News)
- Ex-Funko Exec To Pay SEC $1M In Insider Trading Case - Law360 Compliance Week (Google News)
- Florida order to remove automatic license plate readers sparks privacy and public safety concerns - The Independent Florida Alligator Data Privacy (Google News)
- SEC tightens corporate governance training rules - business.inquirer.net Compliance Week (Google News)
- Tving holds company-wide privacy training after massive data breach - 헤럴드경제 Data Privacy (Google News)
- '40 million data breach' TVING conducts privacy protection training for all employees - starnewskorea.com Data Privacy (Google News)
- RPS civilian employee charged with violating privacy act by snooping in police database - CBC Data Privacy (Google News)