TL;DR: Generative AI is making social engineering faster, more convincing, and harder to detect, according to Living Security Human Risk Management Platform’s guide, which argues that awareness training alone cannot keep pace with deepfakes, spear phishing, and impersonation at enterprise scale. Measurable behavior change, identity-aware targeting, and continuous reinforcement now matter more than completion rates.
NHIMG editorial — based on content published by Living Security Human Risk Management Platform: How to Build Enterprise Social Engineering Security Training
Questions worth separating out
Q: How should security teams stop AI-powered social engineering from leading to privileged access?
A: Security teams should harden the approval path, not just the inbox.
Q: Why do traditional awareness programmes fail against modern social engineering?
A: They measure attendance and quiz scores, not whether employees make safer decisions under pressure.
Q: How do you know if social engineering training is actually working?
A: Look for fewer risky actions, faster reporting, and lower incident rates in the groups most exposed to attack.
Practitioner guidance
- Build a human-risk baseline Correlate employee behaviour, identity and access data, and threat intelligence before deciding where training starts.
- Target high-risk populations first Prioritise groups such as finance approvers, helpdesk staff, new hires, and privileged users for simulations and reinforcement.
- Replace annual awareness with continuous micro-training Deliver short, role-specific interventions after risky actions or simulated failures so learning arrives at the moment of decision.
What's in the full article
Living Security Human Risk Management Platform's full blog post covers the operational detail this post intentionally leaves for the source:
- Role-by-role guidance for rolling out social engineering simulations across finance, IT support, and privileged users
- Practical examples of AI-native training workflows and human-risk scoring across the employee lifecycle
- Recommended program design choices for measuring report rates, risky actions, and behavioural change over time
- The article’s own framing of Human Risk Management as an operational programme rather than a one-off awareness exercise
AI-driven social engineering is outpacing traditional security training?
Explore further
AI-native deception has turned social engineering into an identity problem, not just an awareness problem. When attackers can generate convincing text, audio, and video at scale, the defender’s challenge shifts from spotting generic phishing to validating the legitimacy of requests that target identity workflows. That means IAM, HRM, and fraud teams need shared visibility into when human trust becomes an access path. The practical conclusion is that identity governance must extend into behavioural verification and response.
A question worth separating out:
Q: What should organisations require before approving sensitive requests?
A: Require out-of-band verification for actions that can move money, reset credentials, or change privileged access. That usually means a second channel, a callback, or a human approval step that the attacker cannot easily spoof. For privileged workflows, verification should be mandatory rather than optional.
👉 Read our full editorial: AI-driven social engineering is outpacing traditional security training