Most employees can complete a phishing module and pass a short quiz.
That does not necessarily mean they will challenge a convincing video call from a senior executive, especially when the request is urgent, confidential and arrives at the end of a busy day.
This is the problem security teams are now confronting. The challenge is no longer limited to helping people spot badly written emails. Generative AI can produce highly plausible messages, voices and video, personalised to a particular person, role or organisation.
A Gartner survey of 302 cybersecurity leaders found that 62% of organisations had experienced at least one deepfake attack involving social engineering or the exploitation of an automated process. Some 43% reported an incident involving an audio call, while 37% had experienced deepfakes during video calls.
“Spot the fake” is becoming an unreliable defence
Traditional awareness training often focuses on warning signs: unusual language, poor-quality imagery, an unexpected sender or a request that simply does not feel right.
Those cues still have value, but they become less reliable as synthetic media improves.
Recent Cloud Security Alliance research argues that training has largely been calibrated around human levels of persuasion. As AI becomes capable of producing much more convincing and responsive social engineering, organisations need to place greater emphasis on procedural verification, regardless of how authentic a request appears.
In other words, the safer question is no longer “Does this look real?” It is “What process should I follow before I act?”
What behaviour-based intervention looks like
Behaviour-based security focuses on the decisions people make at moments of risk. It gives them a simple, realistic action to take rather than expecting them to make a perfect judgement about authenticity.
Examples include:
- Verifying sensitive requests through a separate, known communication channel.
- Requiring a second approver for payments, credential changes or privileged access.
- Displaying a short contextual warning when an unusual action is detected.
- Running role-specific simulations based on the requests an employee may genuinely receive.
- Making it quick and psychologically safe to pause or report a suspicious interaction.
The last point matters. The UK National Cyber Security Centre emphasises that secure behaviour depends on culture, trust and accessible processes. Its guidance highlights the importance of allowing employees to question senior colleagues and report concerns without fear of negative consequences.
Measure the action, not just the attendance
A training completion rate shows that people opened a course. It does not show whether behaviour changed.
More useful measures might include how frequently people use verification processes, how quickly unusual requests are reported, whether risky actions are repeated and where employees bypass a control because it is too difficult to follow.
This gives security teams a much clearer view of the underlying barriers. Sometimes people lack knowledge. In other cases, the process is confusing, the technology creates friction or the culture discourages someone from challenging authority.
The intervention should reflect the real cause.
People should not be treated as the problem
Behaviour-based security is not about monitoring employees more aggressively or blaming them when an attack succeeds.
It recognises that behaviour is shaped by technology, workload, leadership and organisational norms. A person who bypasses an unusable process is revealing a design problem as well as a security problem.
Deepfake detection technology will remain useful, but detection alone will not remove the risk. Stronger organisations will combine technical signals with clear verification processes, practical interventions and a culture in which stopping to check is viewed as good judgement, not wasted time.
To explore which security behaviours matter most in your organisation or customer market, contact Callum Budd at callum@mra-research.co.uk.