Knowledge base
Frequently Asked Questions
Clear answers about Afronomias, Guardian, cybersecurity, GRC, and structured thinking.
Afronomias
What is Afronomias?
Afronomias is a philosophy and creative technology ecosystem centered on identity, resilience, and reclamation of power. It explores how cybersecurity, artificial intelligence, education, storytelling, and structured thinking can be applied beyond traditional technical systems.
What are the three pillars of the Afronomias Philosophy?
The three pillars are Identity, Resilience, and Reclamation of Power. Identity focuses on understanding and protecting who you are. Resilience focuses on responding, recovering, adapting, and learning. Reclamation of Power focuses on autonomy, agency, judgment, and intentional decision-making.
How does Afronomias apply cybersecurity to everyday life?
Afronomias translates concepts such as incident response, defense in depth, identity management, threat verification, monitoring, remediation, lessons learned, and vulnerability management into frameworks for personal growth and everyday decision-making.
Human-Centered Security & Social Engineering
What is Human-Centered Security?
Human-Centered Security (HCS) is Afronomias' approach to examining the human decisions, behaviors, pressures, and experiences that influence security. Traditional cybersecurity often focuses heavily on systems, networks, applications, and data. HCS also asks how we can better support the person making security decisions. It applies principles such as verification, least privilege, defense in depth, authentication, authorization, and incident response to help people make more deliberate, security-conscious decisions.
How is Human-Centered Security different from traditional cybersecurity awareness training?
Traditional awareness training commonly teaches specific threats and expected behaviors, such as recognizing phishing, protecting passwords, using MFA, and reporting suspicious activity. HCS complements that education by examining the decision-making around those behaviors, including how urgency, authority, trust, pressure, uncertainty, boundaries, and verification influence a response.
What is social engineering?
Social engineering uses psychological or interpersonal techniques to influence someone into taking an action or revealing information that may compromise security. Rather than attacking technology directly, an attacker may exploit trust, urgency, fear, authority, curiosity, familiarity, or other human factors.
What are some common types of social engineering attacks?
Common examples include phishing, spear phishing, business email compromise (BEC), smishing by text message, voice-based vishing, impersonation, credential harvesting, QR-code phishing, and MFA push or fatigue attacks. Because methods keep evolving, Afronomias emphasizes verification and decision-making rather than memorizing only a fixed list of techniques.
Why do attackers create a sense of urgency?
Urgency can reduce the time someone feels they have to evaluate a situation. Claims that an account will be suspended, payment is required immediately, or an executive needs something right now may encourage action before independent verification. Afronomias teaches a simple principle: urgency may encourage movement, but security gives us a reason to verify.
Does Human-Centered Security blame employees for cybersecurity incidents?
No. HCS examines the conditions surrounding security decisions rather than simply labeling a person as the problem. Technology, processes, culture, communication, access controls, training, workload, and attacker manipulation can all influence outcomes. The goal is to strengthen the environment and decision-making processes that help people act securely.
What does “verify before trusting” mean?
Verification means using independent evidence or an approved communication channel to determine whether a person, request, message, or action is legitimate before granting trust or access. For example, verify an unexpected executive request through a known phone number or established internal process instead of replying directly to the suspicious message.
Can security awareness training prevent phishing and social engineering?
Training can help people recognize warning signs and develop safer response habits, but no program can guarantee that every attack will be prevented. Effective security uses multiple layers, including technical safeguards, organizational processes, access controls, monitoring, verification procedures, and human awareness.
What happens during an Afronomias Human-Centered Security workshop?
Afronomias HCS workshops use cybersecurity concepts, realistic scenarios, discussion, and guided exercises to explore how people recognize threats, evaluate information, verify requests, make security decisions, and respond to potential incidents. Content may vary with the audience, organizational needs, selected topics, and engagement scope.
What is the Human-Centered Security Readiness Assessment?
The HCS Readiness Assessment is a structured evaluation designed to identify areas where human factors may affect an organization's security readiness. Depending on scope, it may examine social-engineering awareness, verification behaviors, reporting confidence, authentication and access habits, security decision-making, response readiness, and security culture. Customers receive findings, priority areas, and recommended next steps. It is not a formal compliance or cybersecurity audit, penetration test, certification, regulatory assessment, or formal risk assessment.
Who are Afronomias' HCS services designed for?
HCS services support organizations and teams seeking to strengthen security awareness, employee decision-making, verification practices, and resilience against social-engineering threats. Scope and content are adapted to the organization's size, audience, needs, and existing security program.
Can Afronomias customize security awareness training for an organization?
Yes. Training may be tailored to organizational needs, audience, industry context, common threat scenarios, participant count, and engagement scope. Customization requirements may affect pricing and preparation time.
Guardian
What is Guardian?
Guardian is a cybersecurity-inspired personal incident response system designed to support structured thinking during anxiety, overthinking, uncertainty, and difficult situations.
Is Guardian a mental-health treatment application?
No. Guardian is a structured self-reflection and decision-support tool. It does not diagnose, treat, or replace therapy, medication, emergency services, or licensed professional care.
How does Guardian use incident response?
Guardian guides users through identifying an incident, examining evidence, assessing the concern, selecting personalized defense actions, monitoring unresolved situations, documenting outcomes, and recording lessons learned.
Can Guardian help with overthinking?
Guardian provides prompts that can help users slow down and examine whether a concern is realistic, verified, useful to dwell on, or primarily based on assumptions. It supports structured reflection but does not guarantee a reduction in symptoms.
What does “Not every alert is a breach” mean?
The phrase means that a concerning thought or emotional signal deserves attention, but it should not automatically be treated as proof that the feared outcome is true.
Why is the user called the Guardian?
The application supports the user’s thinking but does not replace their judgment. The person remains responsible for evaluating information and choosing their next step. The user is the Guardian—not the app.
What is a false positive in Guardian?
A false positive is a concern that initially appeared threatening but was later shown by available evidence or the final outcome not to represent the feared situation.
What does Monitoring mean in Guardian?
Monitoring allows an incident to remain open when the outcome is not yet known. Users can add timestamped updates and new evidence until they are ready to resolve and archive it.
Does Guardian use artificial intelligence?
The current beta emphasizes user-led structured thinking and does not require AI for the core incident response process. Future versions may include optional summaries or pattern insights, subject to privacy, safety, and product-design decisions.
Does Guardian store my data in the cloud?
The current beta is designed around local browser storage. Data remains associated with the browser and device where it was entered unless the user deliberately exports and transfers it through an available feature.
Do I need an account to use Guardian?
No account is required for the current beta.
Will my Guardian data appear on another device?
Not automatically. Opening Guardian on another device or browser generally creates a new local environment unless data is exported from the original device and imported into the new one through a supported feature.
Can I install Guardian on my phone?
Yes. Guardian is available as a Progressive Web App. iPhone users can open it in Safari and select “Add to Home Screen.” Android users can open it in Chrome and select “Install app” or “Add to Home screen.”
Cybersecurity and GRC
What is cybersecurity governance, risk, and compliance?
Governance, risk, and compliance, commonly called GRC, is a coordinated approach for aligning organizational goals, managing uncertainty, establishing policies and accountability, and meeting relevant legal, regulatory, contractual, and internal requirements.
What is cybersecurity governance?
Cybersecurity governance defines how security decisions are directed, owned, measured, and aligned with organizational goals. It includes leadership accountability, policies, roles, oversight, risk appetite, and performance reporting.
What is cybersecurity risk management?
Cybersecurity risk management is the process of identifying assets, threats, vulnerabilities, likelihood, and potential impact, then selecting and monitoring appropriate risk responses.
What is compliance in cybersecurity?
Compliance involves meeting applicable laws, regulations, standards, contracts, and internal policies. Compliance can support security, but passing an audit does not automatically mean an organization is secure.
What is the difference between a vulnerability and a risk?
A vulnerability is a weakness that may be exploited. Risk considers the likelihood and impact of a threat exploiting a vulnerability in a particular context.
What is incident response in cybersecurity?
Incident response is a structured process used to prepare for, detect, analyze, contain, eradicate or remediate, recover from, and learn from cybersecurity incidents.
Why are lessons learned important after an incident?
Lessons learned help organizations identify root causes, improve controls, update procedures, clarify responsibilities, strengthen training, and reduce the chance or impact of similar incidents.
Anxiety and Structured Thinking
Can structured thinking help when I am overthinking?
Structured prompts may help some people slow down, separate facts from assumptions, identify available choices, and decide whether action is needed now. They do not replace individualized professional care.
Why can anxiety feel like reality?
Anxious thoughts can feel urgent and convincing, especially when the mind is focused on possible danger or uncertainty. A structured review can help distinguish the emotional signal from confirmed evidence.
What questions can help when I am overthinking?
Examples include: Is this realistic? Has this concern been verified? What evidence supports it? What evidence challenges it? Is dwelling on it helpful right now? Does it require action, monitoring, or professional support?
What is the difference between monitoring and dwelling?
Monitoring is intentional and evidence-based. It establishes what information is being observed and when the situation will be reviewed. Dwelling repeatedly revisits the concern without a clear review plan or new evidence.
Can an unresolved concern remain open?
Yes. Not every situation can be resolved immediately. Guardian allows users to place an incident into Monitoring, add timestamped updates, and reassess it when new information becomes available.
Ready to use a structured incident response process?
Learn about Guardian