Published Date:
What every security leader should understand before funding another awareness campaign. This is an essay about engineering human defences — why annual training can’t keep pace with AI-driven attacks, what continuous security awareness actually requires, and how everyday users and the IT security team can work far more closely together.
In my previous article, I argued that most “cyber attack” infographics classify threats badly. They mix malware, vulnerabilities, attack techniques and threat actors into one colourful diagram that looks convincing and explains very little. My fix was simple: stop classifying attacks by technical label, and classify them by their primary attack vector instead.
Do that, and one thing stands out immediately. The largest — and fastest-growing — category is no longer malware.
It’s people. More precisely: social engineering and attacks on human behaviour.
If you accept that, it has consequences. Because if the primary attack vector has changed, shouldn’t our defensive strategy change with it? I think it should.
Traditional security awareness was built for a very different world. Attackers sent phishing emails full of spelling mistakes. The fake landing pages looked terrible. Most attacks relied on volume rather than quality.
So the logical response was education: teach employees to spot suspicious emails, explain the common warning signs, run the occasional phishing simulation, repeat the training once a year.
For a long time that was perfectly reasonable. But the world moved.
AI didn’t invent phishing, malware or social engineering. What it changed is more fundamental than any technique.
Economics.
For the first time, attackers can produce genuinely convincing attacks at almost no cost. They can harvest public information from LinkedIn and everywhere else, analyse company websites, imitate a specific writing style, translate flawlessly into nearly any language, clone a voice, even generate convincing video.
And they can do it thousands of times a day.
What used to require an experienced attacker now requires little more than a prompt. The barrier to entry has collapsed.
This is where I think many awareness programmes quietly break. They rest on a simple assumption:
Knowledge → Secure Behaviour
If employees know what phishing looks like, they will decide better. It sounds reasonable. Human psychology just doesn’t work that way.
I know eating less sugar is good for me. I still eat too much of it. I know I should work out more. I don’t. I know I shouldn’t look at my phone while driving — and sometimes I still do. I doubt I’m the only one.
Knowledge influences behaviour. It rarely determines it. Cybersecurity is no exception — we’ve written before about why attitude and behaviour are not the same thing, and why so many programmes end up training the wrong thing.
AI-powered attacks rarely exploit a gap in technical knowledge. They exploit predictable human behaviour: trust, authority, curiosity, urgency, fear, routine, time pressure. If you want the mechanics, we’ve unpacked the psychology behind why people click in detail.
The attacker doesn’t need you to misunderstand technology. The attacker needs you to behave like a normal human being. And under pressure, normal human behaviour is remarkably predictable — which is exactly what modern attackers are counting on.
There are professions where a mistake costs lives. Pilots don’t learn emergency procedures from slides. Firefighters don’t prepare for a disaster by watching a video once a year. Surgeons don’t become proficient by passing an online quiz.
They drill. Again and again, until the correct action becomes muscle memory.
Cybersecurity should work the same way. Under stress, nobody recalls a training session from six months ago — people fall back on habit. That’s precisely what happened to me when I got phished this spring.
With researchers at the Lucerne University of Applied Sciences (HSLU), we set out to answer one deliberately simple question: what actually changes defensive behaviour? Knowledge, delivered as training? Or practice, delivered as drills — and if so, which kind?
We compared three approaches [1]:
The conclusion is not that training is useless. Knowledge remains essential: people have to know, and most organisations also have to demonstrate that employees are compliant with a policy, a law or a certification.
But knowledge on its own doesn’t get you there. Behaviour changes most when people repeatedly make decisions under realistic conditions. So let’s engineer the behaviour we actually want. 🙂
Too many programmes still run as isolated campaigns. An employee completes a course. They get a phishing simulation, or a set of standard exercises — often the kind we’ve argued are mostly pointless as they’re run today. A score is recorded. The campaign closes. Sometimes there’s a certificate.
Attackers don’t work in campaigns.
They adapt continuously — and so does their AI. They learn, experiment, change tactics, exploit current events, and move across channels: email to SMS, SMS to voice, voice to collaboration platforms, and on to deepfakes. At machine speed.
Our defences should move at a comparable speed. And employees shouldn’t just be trained for this reality — they should actively contribute to defending the company.
“How do we train employees?” is, to me, yesterday’s question. The better one is:
“How do we continuously improve defensive behaviour?”
That’s a fundamentally different question, because it shifts the focus from education to engineering. From annual campaigns to continuous adaptation. It stops depending on static training and exercise libraries, and starts using real threats as immediate exercises that immunise the workforce.
It also changes what you measure. You stop tracking course completion as the headline number and start measuring the right thing — actual behaviour. You favour real-time intervention over static content.
In practice, the loop looks like this. A real attack arrives. An employee reports it. AI explains what it was and why it worked. The employee learns — and so does the security system. That real attack then becomes a simulation for everyone else. The organisation improves. And then it starts again.
Some in the industry call this continuous security awareness. I’d go one step further and call it what it really is: Behavioral Defense Engineering.
For more than twenty years, security awareness has concentrated on increasing knowledge. That made sense when attacks exploited technical ignorance and user maturity was low. Today’s attacks exploit behaviour instead — so a different mindset is needed.
Not because awareness has become obsolete. Because awareness alone is no longer sufficient. Knowledge still matters; deliberate practice becomes essential; continuous adaptation becomes mandatory. And measuring real behaviour becomes considerably more valuable than counting completed courses.
The organisations that see this shift won’t necessarily run more training than everyone else. They’ll build a stack that:
Because in the age of AI, cybersecurity isn’t only about protecting technology. It’s about engineering the behavioural defences of the people who use it. The state worth aiming for is the one where every attack becomes an opportunity to strengthen the organisation.
I don’t believe the future of cybersecurity belongs to whoever delivers the most awareness training. I believe it belongs to organisations that can continuously observe, strengthen and adapt human defensive behaviour as fast as attackers adapt their offensive techniques. If that behavioural signal feeds into security systems in real time, better still.
Taken together, that isn’t a better awareness programme.
It’s a different discipline — and I think it will define the next generation of human cyber defences.
So Long, Palo
Footnotes
[1] Improving Cyber Risk Behavior through AI-Enabled Spearphishing – A Comparative Analysis (joint study with the Lucerne University of Applied Sciences)
What is continuous security awareness?
It’s the shift from awareness as an event to awareness as an ongoing practice. Instead of one annual course plus a quarterly phishing test, employees are exposed to realistic decisions repeatedly, measured on what they actually do, and supported in the moment a threat arrives. The model is closer to how pilots or surgeons train than to how compliance training is usually delivered.
Does security awareness training actually work?
It builds the compliance baseline and shapes attitude, and both matter. But on its own it’s a weak predictor of what people do under a real, well-crafted attack. Our research with HSLU found traditional eLearning lifts defensive behaviour by roughly 40% — real, but well short of what’s needed against AI-personalised attacks.
Why isn’t knowledge enough to stop modern phishing?
Because human psychology doesn’t run on “knowledge → secure behaviour.” People know sugar is bad and eat it anyway, know they should work out and skip it, know not to text and drive and do it anyway. Under stress, people fall back on habit — not on what they learned in a course once a year.
What has AI actually changed about phishing?
Not the attack types — the economics. Attackers now run OSINT on individual targets, mimic writing style, translate flawlessly, clone voices and generate video, at a scale of thousands of attempts a day for near-zero cost. The threat categories are the same. The volume and the personalisation are not.
How often should you run phishing simulations?
Realistic behaviour is built the way pilots, firefighters and surgeons build it: through repeated practice under realistic conditions, not a once-a-year exercise. Our research backs this directly — conventional simulations beat eLearning alone, and AI-personalised OSINT simulations improved defensive behaviour by up to 60%.
How do you measure behaviour change instead of course completion?
Stop counting who finished the module and start counting what people do when a real threat lands: do they report it, click it, or escalate it? Treat every real phishing attempt an employee reports as an instant exercise — and treat those reports as early threat intelligence, not just a line in a compliance log.
You need to load content from reCAPTCHA to submit the form. Please note that doing so will share data with third-party providers.
More InformationYou are currently viewing a placeholder content from Turnstile. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More InformationYou are currently viewing a placeholder content from Vimeo. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More InformationYou need to load content from reCAPTCHA to submit the form. Please note that doing so will share data with third-party providers.
More InformationYou are currently viewing a placeholder content from Vimeo. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More InformationYou are currently viewing a placeholder content from Bunny Stream. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More InformationYou are currently viewing a placeholder content from Wistia. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More InformationYou are currently viewing a placeholder content from Facebook. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More InformationYou are currently viewing a placeholder content from Instagram. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More InformationYou are currently viewing a placeholder content from Instagram. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More InformationYou are currently viewing a placeholder content from Google Maps. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More InformationYou are currently viewing a placeholder content from Google Maps. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More InformationYou are currently viewing a placeholder content from Google Maps. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More InformationYou are currently viewing a placeholder content from X. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More Information