Partner Spotlight is a series designed to highlight the vendors that partner with ABA to offer discounted products, services, and business opportunities to ABA members. Each installment, we interview a different partner to learn more about their organization and why indie bookstores matter to them.
CyberHoot delivers cybersecurity awareness training that builds employee confidence through positive reinforcement, short monthly lessons, and real-world phishing simulations. CyberHoot is designed for small teams — it’s fully automated, easy to deploy, and works with Google Workspace and Microsoft 365.
Bookselling This Week met with Craig Taylor, the co-founder of CyberHoot, to learn about the company’s unique approach to cybersecurity.
Bookselling This Week: Would you tell us a little about yourself?
Craig Taylor: I was born and raised in Canada, but now I’ve lived longer in the United States than I was in Canada. 35 years ago, I got a degree in psychology and went straight into cybersecurity after graduating.
I founded my company, CyberHoot, 12 years ago with a few other co-founders, and we're trying to really educate on cybersecurity skills so that people can operate a computer personally and professionally and know how to avoid critical mistakes that people often make.
The work we do in CyberHoot is changing an industry that focuses on shame and punishment to an industry that focuses on positive rewards, gamification, and things that actually change behaviors in the long run versus tamping down bad behaviors temporarily.
BTW: We've actually done some of the CyberHoot trainings at ABA, and one of the things I appreciate about it is the education aspect instead of the popular “gotcha” phishing tests.
I can tell you that one of my previous employers did use those phishing tests and they are just not an enjoyable experience.
So, would you tell us a little bit more about CyberHoot’s approach?
CT: When we first founded the company, we knew the popular approach wasn’t working. We were seeing so many breaches — this was 12 years ago — and it’s only gotten worse.
It's summarized best, I think, simply as this: The entire industry is focused on bigger and better sticks to stop people from clicking.
But that approach only accomplishes one thing. It measures what people know or don't know. It's not an educational approach. It does absolutely no good to measure what people know or don't know if they've never been taught properly. What we’ve created is in response to that.
I think there is a place for a phishing test in a company maybe once a year, like as a final exam example.
If you teach the material, you do need to measure at some point what people learned. That seems fair, but it's been so misused and abused by IT teams, sometimes to justify their expenditures. Like, “Look, we had 25% clicks on the first campaign before we did any training, and now we have it down to 5%.”
But to explain some of the mechanics, when you send a fake email phishing test campaign, 40–60% of your employees don't open the email. So even though it's designed to measure what people know or don't know, more than half of your employees aren't being measured.
So that's the first problem with the traditional methodology, but then you have another problem: what you're measuring is not what needs to be taught.
Let’s say your company uses Google and you get a test phishing email saying you need to set up multi-factor authentication. A real hacker would probably use “google” in the domain name, but from a technical and legal standpoint, we can’t do that.
It is teaching people the wrong message. They learn that a phishing email will come with these giant red flags, and this expectation is completely inadequate for what they need to know, right?
When you use CyberHoot, we teach people what to look for and our examples are more realistic. We’re preparing you for what you need to know and giving you the confidence to say, “I actually feel like I know how phishing works, so I can actually be on the lookout for the real thing when it comes.”
We also get a metric for every single person in your organization. If you have 100 people, we know what all 100 of you did.
So for all these reasons, we have a much better mousetrap for teaching cyber literacy as it pertains to phishing.
Then when you add in the other videos, we're teaching other valuable concepts. We cover financial scams, data privacy, and all these other topics.
What's also interesting is my psychology background and my educator background tie together to say, “How do we get even more engagement?”
Psychologists have known for years these two things: No punished behavior was ever extinguished, and all rewarded behaviors are repeated. Those are two principles of psychology and behavior modification.
We're using positive reinforcement, but sometimes that's not enough. One of the biggest obstructions we face in cybersecurity today is apathy and disengagement, because of punishment. (Like with the kinds of phishing tests that are run against employees — it completely erodes the culture and the goodwill within the company.)
But when you make it a game, people want to participate, so now we've added gamification and leaderboards.
When you go to your assignments, you can see your score and your rank within the company — whether you’re first or tenth, right?
And there’s an unexpected side effect of that. The leadership of companies are typically overwhelmed by email, so they don't typically do their CyberHoot assignments — or they didn't in the past, and now they do, because once in a blue moon, they'll check their rank and realize they’re dead last.
And did any CEO or any C-suite in the world get to that position by being last at anything? It's anathema to them, so they jump in and they start doing their training, which is exactly what we needed because those are the most targeted individuals.
We now have engagement at the highest level because of the leaderboards.
The psychology that we've taken into the cyber literacy training that we deliver has really sparked a revolution of engagement, high compliance, and fun.
BTW: Some of our members may feel that because they're smaller, nobody's going to target them. What would you say to our indie bookstores about why they should also invest in cybersecurity?
CT: Almost every human being on the planet today is using a computer personally and professionally in their lives.
Think of this cyber literacy training as a benefit for you and your employees, not a cost.
Individuals that go through this program are not going to fall for a Facebook marketplace $100 scam and they’ll learn about identity theft detection.
So, it's a benefit to the store and to all the employees, to teach them the cybersecurity skills that no school or book ever taught them.
It's just that simple.
BTW: One of the biggest barriers for our bookstores, when deciding to jump into a new resource, is how much time or effort it's going to take to implement it.
How easy is it for someone to get started with CyberHoot?
CT: One of our original goals was to create a frictionless administrative experience.
When you have to do the traditional “gotcha” phishing test, there is nothing but nightmares and troubleshooting. Things break and you cannot deliver these fake messages without a monumental effort, because every tool that you put into your email security system is designed to prevent that from happening.
Not so with CyberHoot!
Everything we deliver is an in-browser exercise, whether it’s a video or an exercise. You just turn it on, synchronize users, and it's done. It runs itself for you. Then set up reporting for managers to see the compliance and the monthly report.
Literally within 10 to 15 minutes, you can have it set up forever.
If you do the user synchronization through Google Workspace or Microsoft EntraID, adding or removing users from those workspaces will automatically update in CyberHoot, so it is truly set and forget.
We have to be frictionless in the delivery of CyberHoot, in the administration of CyberHoot, in the reporting and the compliance and the benefits of CyberHoot, or fewer people will get trained.
And our goal is to train 1,000,000,000 people, so we've looked at every single point of friction and tried to remove them wherever possible.
ABA members can receive 15% off. Use the links shared on BookWeb to access the discounted rate.