MODULE 4 ยท LESSON 1
Free โ no login requiredSign in to track progress, save quiz attempts and enrol in the full course.
Sign in to track progress / enrolWhy Spotting Flaws Stopped Working
For roughly two decades, security awareness training rested on a single reliable assumption: attackers gave themselves away through imperfection.
The assumption held because the imperfections were economic in origin. Fraud was frequently run by people operating in a second or third language, at volume, without proofreaders. Odd phrasing was not carelessness. It was the visible edge of a business model that could not afford native fluency at scale.
That constraint is gone, and its disappearance did something worse than making the old advice useless. It made the advice dangerous, because the advice is a rule with two directions.
"Watch for spelling mistakes" carries an unstated companion: therefore, a message with no spelling mistakes has passed the check. When errors were a reliable signal, that inference was mostly safe. Now the population of well written messages includes essentially every attack you will receive, and a trained employee applying the rule correctly concludes that the most dangerous message in their inbox is fine.
The old training did not become useless. It inverted, and now produces false confidence exactly where you least want it.
What the current baseline looks like
Assume all of the following about any message, call or meeting request, because each is now routine rather than exotic.
The writing will be flawless, and matched to the tone your organisation actually uses, because public material about your company is available for the attacker to imitate.
It will reference real things. Real colleagues, real projects, real suppliers, a real transaction that is genuinely in progress. Much of that is discoverable from public sources, and the rest from one compromised mailbox.
The voice will be right. Convincing cloning requires only a few seconds of reference audio. Almost everyone has produced that much publicly, in a recorded meeting, a conference talk, a voice note, or a social media clip.
The face may be right too. Real time video synthesis is no longer restricted to well resourced actors, as the Arup case demonstrated with multiple simultaneous participants.
It may not arrive by email at all. Chat platforms, text messages, phone calls, meeting invitations, a comment on a shared document, or a support ticket. Attention is concentrated on email, so other channels are often less defended and less suspected.
Why perception based defence has an expiry date
There is a structural reason to stop investing in teaching people to detect fakes, and it is worth stating plainly because a great deal of training budget is currently going in that direction.
Generation quality improves continuously. Human perception does not. Any defence based on people out perceiving a synthesis model is therefore a defence whose effectiveness declines every year, without any decision on your part.
Worse, training people to look for artefacts produces a specific failure mode. Someone taught to examine video calls for unnatural blinking or lip synchronisation problems will examine a call, find nothing, and conclude that the call is genuine. You have given them a test that returns a false negative against any competent fake, and taught them to trust the result.
The alternative is not to abandon training. It is to train on something that does not decay: the structure of the request, covered next, and the verification procedure that follows it. Both are indifferent to imitation quality. A perfect deepfake making an unusual, urgent, secret request for an irreversible action is still making an unusual, urgent, secret request for an irreversible action.
Most organisations have concentrated their defences on email, for good historical reasons. Email carries the volume, has mature filtering, and is where security teams have the most visibility.
Attackers respond to that concentration by moving, and each alternative channel brings a psychological advantage on top of the weaker technical controls.
Internal chat platforms carry an implicit trust signal. A message in the company workspace feels vetted, because being there implies someone was granted access. When an attacker holds a genuine employee account, that feeling is doing real work in their favour and no filter contradicts it.
Text messages arrive with no organisational filtering at all, on a personal device, often outside working hours when the recipient is away from colleagues they might otherwise consult. Isolation is a component of the attack, and this channel supplies it for free.
Telephone calls remove the ability to reread. A written request can be examined twice and shown to someone. A spoken one arrives once, at conversational pace, with social pressure to respond immediately. Cloned voices make this dramatically more effective than it was.
Shared documents and support tickets are treated as content rather than as messages, so they bypass the mental posture people adopt toward incoming mail entirely. Module 5 shows this is also how hostile instructions reach AI systems.
Meeting invitations and calendar entries appear inside trusted infrastructure and are rarely examined at all.
The practical implication is that verification has to be channel independent. A procedure that only fires when something arrives by email will miss most of what is now aimed at you. The trigger should be the nature of the request, not the medium it travelled on.
An employee is trained to examine video calls for artefacts such as unnatural blinking. They examine a call, find nothing unusual, and proceed with the request. What is wrong with this approach?
Inverted advice
Click to flipGuidance that has become harmful rather than merely outdated. "Check for spelling errors" now certifies as safe the well written messages that constitute nearly every real attack.
Click to flip backError spotting advice did not merely expire, it inverted: it now certifies as safe the fluent messages that make up essentially every real attack. Assume perfect prose, real internal references, a correct voice from a few seconds of public audio, and possibly a correct face. Assume too that it may arrive by chat, text, call, ticket or calendar invitation rather than email. Stop investing in teaching people to perceive fakes, because generation improves every year and human perception does not. Train instead on the structure of the request, which imitation quality cannot touch.