News, Trends, and Insights for IT & Managed Services Providers
News, Trends, and Insights for IT & Managed Services Providers

Guest Interview /

MSP Cybersecurity: Psychology vs. Traditional Training with Craig Taylor

On the go? Listen to the Audio Podcast instead

Your Host

Dave sobel, host of the business of tech podcast
Dave Sobel
Dave Sobel is a leading expert in the delivery of technology services with broad experience in both technology and business. He owned and operated a technology solution provider for over a decade, and worked for vendors leading community, marketing, product strategies, and M&A activities.

This content is made possible by community-minded viewers like you

Thank you

Support Business of Tech

Episode Description

The discussion highlights the limitations of traditional cybersecurity training methods, emphasizing that a psychology-informed approach with positive reinforcement is crucial for developing genuine cyber literacy within organizations. Traditional “gotcha” tactics, such as fake phishing tests, are shown to be ineffective and can even lead to increased clicks, according to research from the University of Zurich and Black Hat. This approach risks creating a false sense of security without genuinely improving user behavior.

Craig Taylor, CEO of Cyberhoot, advocates for a positive reinforcement model rooted in operant conditioning principles, where rewarded behaviors are repeated and internalized. This strategy is implemented through gamified modules, such as interactive “Hootfish” exercises that guide users in identifying threats with in-moment assistance. Progress is tracked via avatars that mature with learning, and an anonymous company leaderboard encourages engagement, particularly motivating management to complete assignments. These elements aim to foster intrinsic motivation for security best practices rather than relying on external pressure or punishment.

The conversation also delves into the challenges of measuring security progress, noting that traditional phishing tests often fail to capture a complete picture of an organization’s security posture, particularly with C-suite employees who may not engage with such tests. The episode touches upon the complexities of evolving cybersecurity threats, including AI-powered personalized attacks, and the inherent difficulties in relying solely on human training against sophisticated adversaries. Furthermore, the discussion addresses the lack of accountability for cybersecurity vendors with faulty software, contrasting it with product liability in other industries, and the debate around the absence of consistent federal regulations for AI and data privacy in the US compared to Europe’s GDPR.

For MSPs and IT service leaders, this episode underscores the need to adopt more effective, psychology-driven security awareness programs that focus on positive reinforcement and intrinsic motivation. It highlights the limitations of purely technical or punitive cybersecurity measures and emphasizes the importance of a comprehensive strategy that combines user education with robust technical defenses. The discussion also serves as a reminder for MSPs to critically evaluate vendor security practices and to advocate for stronger accountability and clearer regulatory frameworks to protect client data and services.

💼 All Our Sponsors

Support the vendors who support the show:
👉 https://businessof.tech/sponsors/

🚀 Join Business of Tech Plus

Get exclusive access to investigative reports, vendor analysis, leadership briefings, and more.
👉 https://businessof.tech/plus

🎧 Subscribe to the Business of Tech

Want the show on your favorite podcast app or prefer the written versions of each story?
📲 https://www.businessof.tech/subscribe

📰 Story Links & Sources

Looking for the links from today’s stories?
Every episode script — with full source links — is posted at:
🌐 https://www.businessof.tech

🎙 Want to Be a Guest?

Pitch your story or appear on Business of Tech: Daily 10-Minute IT Services Insights:
💬 https://www.podmatch.com/hostdetailpreview/businessoftech

🔗 Follow Business of Tech

LinkedIn: https://www.linkedin.com/company/28908079
YouTube: https://youtube.com/mspradio
Bluesky: https://bsky.app/profile/businessof.tech
Instagram: https://www.instagram.com/mspradio
TikTok: https://www.tiktok.com/@businessoftech
Facebook: https://www.facebook.com/mspradionews

Choose your upgrade:

Get the full benefits of Business of Tech Plus

Insider Access

$12/month

Perfect for MSPs and ITSPs that want full interviews, early access, and ad-free listening

  • Programmatic Ad-free private podcast feedSame show, little interruptions
  • Channel Chatter previews1–2 topics with light insights
  • Early access to interview episodesHear it days before public release
  • Monthly Insider BriefTighter analysis you can share internally
  • Extra audio segmentsCut interviews, behind-the-scenes commentary, quick competitive notes
  • Become an Insider for $12/month

    Leadership Access

    $149/month

    Perfect for MSPs and Vendors that run a team and need the extended tactics, executive summaries, and weekly alignment brief

  • All Insider Access benefits plus . . .
  • Invite your teamIncludes access for 5 team members with option to add more
  • Vendor Strategy BriefsThe entire library, plus new analysis every month
  • Channel ChatterAll topics, full insights, complete vendor discussion + sentiment list
  • Quarterly State of the Channel Briefing
  • Monthly AMA submission priorityAsk Dave direct questions, and skip the line
  • Get the Leadership Edge for $149/month

    Vendor Partner

    $500/month

    Perfect for channel companies or vendors looking to deepen their engagement with the show.

  • All Leadership Access benefits plus . . .
  • Get highlighted as a show sponsor You'll get placement in the show notes, throughout the website, and on our dedicated sponsors page.
  • Enjoy regular shout outs You'll be featured in a rotating format during the show
  • Become a show sponsor for $500/month

    Search all stories