Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

AI-driven social engineering is outpacing traditional security training


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 18004
Topic starter  

TL;DR: Generative AI is making social engineering faster, more convincing, and harder to detect, according to Living Security Human Risk Management Platform’s guide, which argues that awareness training alone cannot keep pace with deepfakes, spear phishing, and impersonation at enterprise scale. Measurable behavior change, identity-aware targeting, and continuous reinforcement now matter more than completion rates.

NHIMG editorial — based on content published by Living Security Human Risk Management Platform: How to Build Enterprise Social Engineering Security Training

Questions worth separating out

Q: How should security teams stop AI-powered social engineering from leading to privileged access?

A: Security teams should harden the approval path, not just the inbox.

Q: Why do traditional awareness programmes fail against modern social engineering?

A: They measure attendance and quiz scores, not whether employees make safer decisions under pressure.

Q: How do you know if social engineering training is actually working?

A: Look for fewer risky actions, faster reporting, and lower incident rates in the groups most exposed to attack.

Practitioner guidance

  • Build a human-risk baseline Correlate employee behaviour, identity and access data, and threat intelligence before deciding where training starts.
  • Target high-risk populations first Prioritise groups such as finance approvers, helpdesk staff, new hires, and privileged users for simulations and reinforcement.
  • Replace annual awareness with continuous micro-training Deliver short, role-specific interventions after risky actions or simulated failures so learning arrives at the moment of decision.

What's in the full article

Living Security Human Risk Management Platform's full blog post covers the operational detail this post intentionally leaves for the source:

  • Role-by-role guidance for rolling out social engineering simulations across finance, IT support, and privileged users
  • Practical examples of AI-native training workflows and human-risk scoring across the employee lifecycle
  • Recommended program design choices for measuring report rates, risky actions, and behavioural change over time
  • The article’s own framing of Human Risk Management as an operational programme rather than a one-off awareness exercise

👉 Read Living Security Human Risk Management Platform's guide to enterprise social engineering security training →

AI-driven social engineering is outpacing traditional security training?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 17593
 

AI-native deception has turned social engineering into an identity problem, not just an awareness problem. When attackers can generate convincing text, audio, and video at scale, the defender’s challenge shifts from spotting generic phishing to validating the legitimacy of requests that target identity workflows. That means IAM, HRM, and fraud teams need shared visibility into when human trust becomes an access path. The practical conclusion is that identity governance must extend into behavioural verification and response.

A question worth separating out:

Q: What should organisations require before approving sensitive requests?

A: Require out-of-band verification for actions that can move money, reset credentials, or change privileged access. That usually means a second channel, a callback, or a human approval step that the attacker cannot easily spoof. For privileged workflows, verification should be mandatory rather than optional.

👉 Read our full editorial: AI-driven social engineering is outpacing traditional security training



   
ReplyQuote
Share: