ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Out-fishing the phishers

Andrew Rose at SoSafe argues that we need a behavioural-based human risk management approach to cyber-security

 

No one wants to fall for a scam online, especially in their professional life. But increasing numbers of people are becoming unwitting victims of attacks online. Attacks are growing in scale and severity—and people are at the centre of them. 

 

 Forrester estimates that 9 in 10 data breaches this year will include some sort of human element which allows information to be stolen. Looking at the scale of the issue, we at SoSafe found that one in two businesses experienced a successful cyber-attack in the past three years – and 64 per cent assess their risk of falling for another one as high. Being involved in an incident is increasingly the norm rather than the exception. 

 

This rise in breaches comes as an ever-greater portion of the workforce are digital-native, savvy internet browsers who have spent most of their lives online. How, one might ask, are people getting more gullible? 

 

A large portion of the answer is that an attempted cyber-attack today frequently looks nothing like it did five or two years ago, or even last year. Criminals and bad actors harness emerging technologies’ power to supercharge their capabilities. 

 

The same AI-based tools and LLM-models that promise to revolutionise customer service and product development are also being used to make spurious requests for information seem ever more trustworthy. Tools with names like WormGPT and FraudGPT are spreading through hidden message boards and passed around corners of the Dark Web. 

 

Tapping into generative AI allows emails attempting to access information to be created up to 40 per cent faster than previous methods. And what’s generated is fooling people. We were able to create (in simulated attacks) messages that 78 per cent opened, while 65 per cent revealed personal information and 21 per cent clicked on malicious links or attachments.

 

What’s changed is that scammers can now incorporate industry and company-specific information and then create grammatically sound, well-formatted messages. The tell-tale signs of a phishing attempt—the strange fonts, the bizarre syntax, the unfamiliar file types – may be absent in these new forms of attacks. Criminals can now resemble the cold viruses that attack us every winter, ruthlessly iterating and evolving to find weak points.

 

Technology has a role to play in keeping the hordes at bay – but it cannot act alone. Professional hackers, working together, given enough time, will overrun every technical defence put in place by the IT department.

 

Reinforcements have to come from the people on the frontlines, employees. This is the “human factor” in cyber-defence, which will allow companies to turn the tide. Employees need to be seen as assets in the fight rather than something that is ‘allowing’ intrusions to happen. 

 

Education is vital to managing human risk. The first stage is awareness of the problem: bad actors exist are incentivised to steal valuable information and resources from a company. Compliance frameworks have long understood that importance, confronting security leaders with a series of requirements tackling the human layer.

 

But checking the compliance box is not enough because these frameworks only focus on quickly transmitting information, not changing behaviour. Too often, security training essentially stops here – but it’s not enough to tick compliance boxes. People have not been given the tools to be an active part of a company’s defence. 

 

Cyber-security training can be a dull affair – endless slides that require a user to click every 20 or 30 seconds to ‘ensure participation’, mindless quizzes with brain-thuddingly obvious answers. This is no longer fit for purpose. Companies must work to move their organisations beyond the awareness basics that don’t cut it when facing this escalating threat landscape.

 

Instead, programmes need to identify and prioritise human risks specific to a particular company and then create a corrective action plan to address these issues, creating and spreading behaviours that will allow people to understand and respond to threats.

 

These programs need to consider behaviour in its entirety, including cultural influences, motivational factors and attitudes, context, and emotional responses. There needs to be a focus on the principles behind safe and secure ways to interact with digital information and use communication tools, which will be valid even if the format or underlying technology shifts. 

 

Training should be engaging. Yes, it needs to cover relevant information, but it needs to ensure people learn to apply their knowledge, build good security habits, and understand why these things are important.

 

Good news: We can leverage long-proven psychological approaches. In practice, this means offering a multi-channel experience offering people contextual learning opportunities wherever they are. These programs create bite-size chunks over huge blocks of text, employing tactics like gamification, continuous and spaced repetition, interactive components, contextual nudging, and storytelling – all while focusing on positive reinforcement instead of learning through fear.

 

Companies that don’t act also risk overwhelming the specialists who have to deal with these threats.  Burnout in security teams is proliferating. Sixty-six per cent of security professionals in the United States and Europe suffer significant work stress, while 3.9 million cyber-security positions are currently unfilled across the globe.

 

Professionals need help from everyone else to fulfil their mission. Cyber-security needs to become a joint responsibility – and humans have the power to fight against cyber-crime. Equipped with security instincts, they become the biggest ally and most versatile part of companies’ defence strategies for sustainable risk reduction.

 

The best way to appreciate the transformation that needs to happen is through one of the most basic, common analogies: give a man a fish, he’ll eat for a day; teach him to fish, he’ll never go hungry. Here, a fish is a strictly technological approach, which may stop one threat but doesn’t solve the more significant issue.

 

Only through empowering front-line staff through a holistic human risk management program will companies be able to build resilience and sustainably mitigate cyber-risk, ensuring they are set for the long term.

 


 

Andrew Rose is CSO of SoSafe

 

Main image courtesy of iStockPhoto.com and Yuliya Taba


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543