Tobac, the CEO and cofounder of SocialProof Security, spends a lot of time thinking about how to educate people about the importance of protecting their digital data. At the time, she said, sea shanties were trending on TikTok, so the genre felt appropriate; she tweeted her video thinking it would be fun (and possibly helpful) to others.
She soon realized she had tapped into something bigger: Corporate training sessions — whether done in person or via video — are often boring and hard to remember. And dozens of companies reached out to her in the wake of her tweet, asking if they could use it as part of their security awareness training. She said sure, offering it for free, and about half of those who used it later told her the song made it easier to get employees to sign up for password managers and enforce the use of multi-factor authentication. They asked her to make more music.
Now, what started as a fun side project is a real product that SocialProof Security, which trains companies’ employees on information-security topics via workshops, trainings, and hacking demonstrations, is selling to its customers. The company is making slickly packaged music videos, such as a country western tune about how to spot a phishing scam.
“I think it really shows that many different companies, not just in tech, are looking for something that’s a lot less boring,” she said.
To make the videos, Tobac came up with a list of topics to cover — ranging from social-media safety and password management to malware and ransomware — and gave songwriters a list of details each song should include, as well as ideas for lyrics.
Johnathan Yerby, an associate professor at Mercer University who studies cybersecurity, thinks it’s a great idea to use music videos to communicate about information security. He cautioned that it may not be possible to include (or for viewers to absorb) all the relevant information in a single video, however, particularly if it goes by quickly while people are line dancing.
The biggest challenge with training employees on this particular topic, he said, is simply getting them to care. He hopes music videos can make it more approachable.
And while many people may find information security music videos fun (or at least more fun than watching a typical corporate training video or listening to a presentation), Tobac knows they’re not for everyone. She conducted research before creating the videos and found that about 20% of people are really not interested in learning about digital security issues via singing and dancing. For that audience she has a more staid solution in spoken-word videos that cover the same subjects.
“There’s just so many more topics that we can cover,” she said.