CyberSecurity

Cybersecurity Awareness Training, Has to Catch Up With AI. Here's Why.

Cybersecurity awareness training used to teach one simple habit: look for the tell-tale signs. Bad grammar, a strange sender address, a logo that's slightly off. That advice worked for years. It doesn't anymore, and the reason is AI.

Posted on

21 September 2026


 

Related Topics

More about Blue Saffron’s Cybersecurity Training and Awareness

 

Download our Cybersecurity Guide for UK SMBs

 

Read our blog: Security Starts With Humans So Cybersecurity Awareness Training Really Matters

 

More about Blue Saffron


 

Get In Touch

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

The UK’s National Cyber Security Centre has assessed that AI is already making cyber intrusion techniques more effective, and expects that trend to accelerate over the next few years. For a recruitment agency, accountancy firm or HR consultancy, that’s not an abstract IT concern. These businesses move client money, hold sensitive personal data on candidates and clients, and run on trust built over years. That combination makes them a genuinely attractive target, not despite being smaller than a multinational, but partly because of it.

Why the old advice stopped working

Poor spelling and clunky phrasing used to be the easiest way to spot a scam email. Generative AI has quietly removed that safety net. Attackers can now produce fluent, well punctuated messages in perfect English, referencing a recipient’s real job title or a project pulled straight from LinkedIn. According to the government’s 2025 Cyber Security Breaches Survey, phishing was identified as the cause behind 85 percent of the cyber incidents businesses experienced last year. That figure hasn’t dropped as awareness has grown, because the attacks themselves have kept pace.

The uncomfortable truth is that most staff were trained to trust their gut. AI generated phishing is specifically designed to satisfy that gut check.

When Deepfakes Take Over the Video Call

Text based phishing is only part of the shift. The more striking development is what happens when AI is used to impersonate a real person, in real time, on a call.

In early 2024, a finance employee at Arup, the London headquartered engineering firm behind the Sydney Opera House, joined what he believed was a video call with his CFO and several colleagues. Every person on that call, aside from him, was an AI generated deepfake, built from footage the real executives had appeared in during webinars and conference talks. He’d initially suspected the request was a phishing attempt, but the video call satisfied his doubts, and he authorised 15 transfers totalling roughly $25.6 million before anyone realised what had happened.

That same year, WPP’s chief executive Mark Read was the target of a similar attempt. Scammers built a fake WhatsApp profile using his public photo, then used a cloned voice and pulled YouTube footage to run a fake Microsoft Teams meeting with a senior colleague, attempting to solicit money and personal details. That one failed, caught by an alert employee rather than any piece of software. Read’s own warning to staff afterwards is worth repeating: the techniques now go well beyond email, into virtual meetings and voice as well.

Neither of these firms is small. But the tools behind both attacks have become considerably cheaper and easier to access since 2024, which is exactly why the risk has moved down the size scale rather than staying at the top.

The Numbers Behind It

The Arup deepfake cost the firm $25.6 million in a single week. The WPP attempt targeted a similar outcome but failed, caught by an alert employee rather than any technology. Both used publicly available footage, LinkedIn posts, webinar recordings, conference talks, to build the impersonation.

Why this lands particularly hard on professional services firms

Recruitment, accountancy and HR consultancies sit in an unusually exposed position. Client funds move through accountancy and payroll processes regularly. Candidate and employee data, including bank details and personal documents, sits in recruitment systems as a matter of course. And these firms tend to run lean, without a dedicated security team scrutinising every unusual request.

The financial impact when it goes wrong is significant. The same government survey found that cyber facilitated fraud, where a breach leads directly to a financial loss, cost affected businesses an average of £5,900, rising to £10,000 once genuinely zero cost incidents are excluded. Phishing was identified as the entry point in 54 percent of those fraud cases. For a business the size of most recruitment or accountancy firms, that’s not a rounding error.

Recently Updated

The NCSC updated its technical requirements in April 2026, tightening what’s expected around cloud security, authentication and patching. If your organisation is largely cloud based, that update is relevant to you specifically, not just a footnote.

Why Verifying Beats Recognising

The fix isn’t a cleverer list of red flags, because the red flags keep changing. It’s a shift in how staff verify anything unusual before acting on it, combined with training that’s updated as often as the threats are.

A few habits are proving genuinely effective against this new wave of attacks:

  • Treat any urgent request for a payment, credential, or sensitive data as a prompt to verify, not a prompt to act. A callback to a known number, not one supplied in the message itself, breaks the spell of even a convincing deepfake.
  • Agree a simple verification method in advance for anything involving money or sensitive data, a phrase or process the whole team knows and uses. It sounds basic, but it’s one of the few things a real time deepfake genuinely can’t fake.
  • Don’t rely on recognising a face or voice as proof of identity on a video call. That’s precisely the assumption both the Arup and WPP attacks were built to exploit.
  • This is where ongoing, simulated training earns its keep over a once a year session. A single annual module teaches people what phishing looked like when it was recorded. Regular, updated simulated phishing keeps pace with what it looks like now.

The One Thing to Remember

Text: A face or voice on a call is no longer proof of identity. If a request involves money, credentials or sensitive data, verify it through a separate, pre-agreed channel before acting, regardless of how convincing the call seemed.

Get Ahead of Cybersecurity Awareness Month

Cybersecurity Awareness Month runs every October, and it’s a natural point to check whether your organisation’s approach has kept up with how the threat has changed, rather than just ticking the box again. Blue Saffron delivers ongoing cybersecurity training and awareness built around this reality, simulated phishing that evolves alongside real attacks, not a static course run once and forgotten. If you’d like to talk through what that looks like for your team, get in touch.

FAQs

What is cybersecurity awareness training?

It’s ongoing education that teaches employees to recognise and respond appropriately to threats like phishing, social engineering and deepfake impersonation, rather than a one-off compliance exercise.

Why has phishing become harder to spot?

Generative AI removes the traditional warning signs, poor grammar, generic greetings, awkward phrasing, and can personalise messages using information scraped from LinkedIn and other public sources.

What is deepfake CEO fraud?

It’s when attackers use AI generated video or voice to impersonate a senior executive, usually to convince an employee to authorise an urgent payment or share sensitive information.

Are recruitment and professional services firms particularly at risk?

Yes. These firms routinely handle client funds and sensitive personal data with lean teams, which makes them an attractive and often under-defended target.

Does cybersecurity awareness training help with Cyber Essentials certification?

Yes. Cyber Essentials doesn’t formally require staff training, but the controls it covers, like secure configuration and access control, are far harder to maintain without a team that understands why they matter.

How often should staff receive cybersecurity awareness training?

Ongoing rather than annual. Awareness fades within months without reinforcement, and attack techniques change faster than a yearly session can track.

What should staff do if they suspect a phishing or deepfake attempt?

Don’t act on the request. Verify it through a separate, pre-agreed channel, such as a direct callback to a known number, before doing anything involving money, credentials or sensitive data.

Deepfake CEO fraud and AI generated phishing are already targeting UK firms your size. Get in touch today to find out how Blue Saffron can help your team stay ahead of it.