
The Invoice Was Real. The Bank Account Wasn't.
BEC cost businesses $3 billion last year at ~$123K per incident. How vendor payment fraud actually works, and the two habits that stop it.
Blog
Plain-spoken writing about security awareness training, MSP operations, compliance, and the occasional product update.

BEC cost businesses $3 billion last year at ~$123K per incident. How vendor payment fraud actually works, and the two habits that stop it.


41% of cyber insurance applications get denied. The 10 categories carriers actually evaluate, what they want to see, and how to close gaps before you submit.

CMMC Phase 2 is on hold, but DFARS 7012, your NIST 800-171 self-assessment, and the training controls behind your SPRS score aren't. Here's what still applies.

Most MSPs sell security awareness training wrong. The playbook for positioning it as a real service line, capturing renewal revenue, and protecting margin.

What to recommend when CMMC clients ask about security awareness training. Auditor-ready certificates, quarterly cadence, and a reseller program that pays.

CMMC Phase 2 starts November 2026. What the framework requires for security awareness training, what assessors look for, and how ClickCerts fits.

Watch for typos and bad grammar — that's outdated advice. AI-generated phishing has changed the rules. What your security training needs to teach now.

Cyber insurance now requires security awareness training. If your MSP doesn't offer it, you have a gap. Here's how ClickCerts closes it, with margin.

60% of breaches start with human error. See why security awareness training is the highest-ROI investment you can make, and how ClickCerts delivers it.

You don't need 1,000 training modules. You need certified, current training your people will finish. Why simpler beats bloated, and what CMMC requires.
Subscribe
A short note when we ship something worth knowing about. No spam, no drip campaigns.