Cybersecurity Awareness Month: Is AI Phishing Making Awareness Training Obsolete?

For years, identifying a fraudulent email has formed the foundation of workplace security protocols. During Cybersecurity Awareness Month, that advice appears increasingly fragile, as the traditional giveaways have become too easy for AI to mimic.

Microsoft’s fresh Digital Defense Report shows that attackers are still leaning on phishing, impersonation and social engineering to target people, with AI reducing the friction of personalised attacks. Phishing’s slice of initial intrusions has reportedly climbed sharply.

That spells trouble for standard corporate training. Awkward phrasing, robotic greetings and fake domains are the key warning signs drilled into staff during annual compliance modules, but few of those appear in a well-crafted note from a trusted source. One convincing approach can be enough, as the Aura breach demonstrated, when a single phone scam on one employee gave attackers access to a marketing tool.

So has security training reached a dead end, or does it just need a total rethink? And what are founders and small teams supposed to prioritise when there’s no dedicated security team on payroll?

 

Can You Train Your Way Out Of AI Scams?

 

Nobody’s arguing that staff should be written out of the defence picture altogether.

Microsoft notes that most network intrusions still start with human interaction or stolen credentials instead of a software exploit, making this an identity challenge just as much as an email one. The real debate is whether training focuses on the right skills.

Courses built around typos and clumsy sender addresses train people to judge surface aesthetics. AI has rendered that a losing game, since attackers can now automate hyper-personalisation and polish away every flaw. What holds up much better is scrutinising the request itself: an unexpected change in payment details, an unprompted password reset or a suspiciously urgent demand from a senior executive, regardless of how clean the formatting appears.

This points to a different operational mix. Active verification habits, easy reporting tools and robust safeguards like passkeys and phishing-resistant multifactor authentication mean human error stops short of a disaster. For smaller teams without a full-time security squad, locking down those basics beats completing another generic yearly course.

Should corporate training be tossed out or just revamped? We asked industry leaders and IT specialists to share their take.

 

 

Our Experts

 

  • Edward Tian, Co-Founder, GPTZero
  • Shlomi Beer, Co-Founder And CEO, ImpersonAlly
  • James Omanwa, Founder And Security Architect, RedArk Ventures
  • Jay Bavisi, Founder And Group President, EC-Council
  • Kadan Stadelmann, Co-Founder, Compance
  • Nishanth Sirikonda, Cloud Solutions Architect, FirstDay Foundation
  • Rafael Narezzi, Co-Founder And CEO, Centrii

 

Edward Tian, Co-Founder, GPTZero

 

Edward Tian, Co-Founder, GPTZero

 

“Cyber awareness training needs to change. The part that teaches people to spot bad grammar and odd greetings is obsolete.

“Here’s what I know from my own work. People are bad at telling AI-written text from human text just by looking. A well-written phishing email has no tells. You can’t train someone to see something that isn’t there.

“So don’t train people to judge how an email reads. Train them to check what it asks for. If a message asks for money, a login or a change to payment details, confirm it through a second channel. Call a number you already have. Message the person directly. Make that a company rule.

“Make reporting easy and free of blame. The employee who reports a bad email five minutes late is worth more than the one who hides a click.”

 

Shlomi Beer, Co-Founder And CEO, ImpersonAlly

 

Shlomi Beer, Co-Founder And CEO, ImpersonAlly

 

“Awareness training isn’t obsolete, but most of it trains people for an attack that has largely moved elsewhere. Courses still teach employees to spot bad grammar, generic greetings and odd sender domains. AI removed those and, more importantly, a growing share of attacks no longer arrive by email at all. At ImpersonAlly we see fraudsters buying their way into the trust loop: sponsored search ads, social ads and even LLM answers impersonating well-known brands, support desks and software tools. When an employee searches for a tool or a support line and clicks the top result, their guard is already down because they initiated the search. No phishing simulation tests for that.

“What should change:

“1. Don’t trust the entry point: even if you searched for it, type the URL yourself and confirm any phone number on the official site.

“2. Cover the channels attackers actually use now, such as search ads, fake install pages, ‘free’ PDF or tax tools that quietly harvest uploaded documents and copy-paste terminal ‘fixes’ (ClickFix).

“Training is still great for habit building.”

 

James Omanwa, Founder And Security Architect, RedArk Ventures

 

James Omanwa, Founder And Security Architect, RedArk Ventures

 

“Awareness training is not obsolete. The version most companies run is. For years we taught people to spot bad grammar, odd greetings and misspelled domains. AI removed all three in one go, so a course built on those cues is now training staff to catch last decade’s attacker.

“What still works is teaching behaviour, not detection. Three habits hold up no matter how polished the email: treat any request involving money, credentials or urgency as unverified until you confirm it through a channel the sender did not choose; assume a convincing email can be fake and feel no shame in checking; and report fast, because the first report is worth more than a hundred people who quietly deleted it. The goal is not a workforce that never clicks. It is one that clicks and tells you within five minutes.

“The bigger shift is to stop treating people as the last line. If a stolen password still unlocks your email or your payroll portal, training was never the real control. Phishing-resistant multi-factor authentication such as passkeys, enforced sender authentication (Domain-based Message Authentication, Reporting and Conformance, or DMARC), and payment changes that require a second approver each do more than another annual module. Train people to verify and report, and build systems where a successful click does not matter.”

 

Jay Bavisi, Founder And Group President, EC-Council

 

Jay Bavisi, Founder And Group President, EC-Council

 

“AI didn’t create the problems. It made them cheaper to exploit. A targeted phishing email that once took an attacker an hour to write now takes seconds, in flawless language, tailored to the person reading it. Awareness training needs to change with it.

“Employees are handed AI tools before anyone explains what those tools should and shouldn’t be allowed to do. We teach people to use technology first and to use it safely later, if at all. That gap is exactly where attackers operate.

“Cybersecurity Awareness Month can’t be a poster campaign anymore. Security has to be taught at every level, from the classroom to the boardroom, and AI governance has to be part of that education.

“Businesses should run realistic simulations to test how employees respond to AI-generated phishing, data leakage or misuse of an internal AI assistant. They should also provide role-based education aligned with employees’ job functions so each team develops the security knowledge needed for its responsibilities.

“Otherwise, we’ll keep building the most advanced systems in history on top of the weakest human habits.”

 

Kadan Stadelmann, Co-Founder, Compance

 

Kadan Stadelmann, Co-Founder, Compance

 

“There is no evidence that annual courses improve security behaviour amongst professionals. Instead, such events must be held quarterly in order to keep security concerns top of mind. The problem with phishing is not a knowledge one – everyone is aware of these types of scams and the language connected to them. Rather, it is more of an attention one. What is the curriculum a link must surpass before being clicked?

“Attendees forget what they’ve learned in actionable terms long before next year’s conference, which supports the idea of holding these types of events far more frequently than annually.

“Organisations must implement better risk management and risk decisions, not depend on yearly training. The broad stroke approach is to implement checks on payment and credential changes through a firm.”

 

Nishanth Sirikonda, Cloud Solutions Architect, FirstDay Foundation

 

Nishanth Sirikonda, Cloud Solutions Architect, FirstDay Foundation

 

“I approach this from the enterprise technology side, leading platforms, integrations and security governance where employee decisions affect access, payroll and sensitive data.

“Awareness training is still useful, but it needs to move beyond spotting spelling mistakes and awkward greetings. An email can be perfectly written and still be fraudulent. Employees need to know which requests require verification and how to verify them.

“Take a request to change an employee’s payroll bank account. The right response is to follow the approved verification process and use contact details already on record. A familiar name or professional tone should not replace that check.

“Annual courses give people a foundation. Short exercises based on their jobs let them practise making decisions under pressure. Finance staff should work through payment-change requests, while helpdesk teams should practise handling urgent password resets. Reporting suspicious messages should be easy, and employees should feel comfortable asking for help.

“Phishing simulations still have a place, but counting clicks tells only part of the story. Did the employee report the message? Did they verify the request before acting? Those behaviours matter.

“Businesses also need phishing-resistant MFA, limited access and separate approval for sensitive changes. Employees should have reliable processes to follow instead of being expected to spot every convincing fake.”

 

Rafael Narezzi, Co-Founder And CEO, Centrii

 

Rafael Narezzi, Co-Founder And CEO, Centrii

 

“For years, cybersecurity awareness has largely been framed around what employees should do differently – recognise phishing attempts, strengthen passwords and avoid suspicious links. Those habits still matter, but today’s threat environment requires a much broader definition of awareness.

“In critical infrastructure, cyber risk is operational risk. A compromised battery storage system, renewable energy site or remote-access connection may not produce the warning signs of a conventional data breach. Instead, the consequences can appear as lost generation, unstable operations, reduced availability and direct financial loss. As energy infrastructure becomes more distributed and interconnected, organisations need visibility not only into their own environments, but also into the vendors and technologies on which their operations depend.

“Organisations have too many alerts and too little context. Leaders must be able to determine which exposures could disrupt operations, how much capacity or revenue is at risk and which action will reduce that risk first.

“This Cybersecurity Awareness Month, we should move beyond treating awareness as an annual training exercise. True cyber resilience requires continuous asset visibility, carefully controlled access, clear supply-chain accountability and incident-response plans that are regularly tested. People should not simply be labelled the weakest link; they should be equipped to become an active layer of defence.

“Cybersecurity becomes meaningful when everyone – from operators and engineers to executives and boards – understands both their role and the real-world consequences of inaction.”