Episode 102

full
Published on:

29th Jul 2026

Why Social Engineering Still Works & Why AI Is Making It Worse

Social engineering has been around since humans started talking to each other. The psychology hasn't changed, but AI has made the execution almost unrecognisable.

Welcome to Razorwire, the podcast where we share our take on the world of cybersecurity with direct, practical advice for professionals and business owners alike. I'm Jim and in this episode, I'm joined by Richard Cassidy, Field CISO at Rubrik, and Bec McKeown, a chartered psychologist specialising in human performance under pressure.

Social engineering isn't a technology problem, it's a human one that cybersecurity has inherited. The psychology behind it hasn't changed since Cleopatra was using it to outmanoeuvre empires, but AI has transformed the speed, scale and sophistication of every stage, from automated reconnaissance that builds a complete profile in 30 minutes to real-time voice cloning that references your actual projects and travel schedule.

Bec and Richard bring two very different perspectives to the same problem. Bec explains how attackers engineer the conditions in which people make decisions rather than just crafting a convincing message, and why "people are the weakest link" misses the point. Richard shares what he's seeing as a practising CISO, from family members being targeted through gaming platforms to why measuring phishing click rates gives organisations a dangerous false sense of security.

Three key talking points:

  • They're not hacking people, they're shaping decisions: Social engineering works because attackers engineer the conditions under which decisions get made, not because people are careless. Bec explains why most security awareness training is solving the wrong problem by focusing on the message rather than the environment in which people are operating.
  • AI has turned social engineering into an automated pipeline: What used to take weeks of manual reconnaissance now takes 30 minutes. AI-powered OSINT can build a complete profile of a target and generate a tailored attack that references their projects, travel and communication style. Combined with real-time voice cloning, these layered attacks are becoming almost impossible to distinguish from a legitimate request.
  • Your family is now part of the attack surface: If the executive is too well protected, attackers go to the people around them. Children on gaming platforms are being cultivated to unknowingly share information about their parents' work and routines, and a compromised family device on a shared home network becomes a route into the corporate environment.

The psychology behind social engineering hasn't changed in thousands of years, but the tools to exploit it have. If your defences are still built around phishing simulations and click rate metrics, this episode will make you rethink.

On why social engineering isn't about fooling people:

"They're not hacking people, they're shaping the conditions in which people make decisions."

Bec McKeown

Listen to this episode on your favourite podcasting platform: https://razorwire.captivate.fm/listen

In this episode, we covered the following topics:

  • The History of Social Engineering From Cleopatra to Cold War intelligence operations, social engineering has worked for as long as humans have communicated. We discuss why the psychology behind it hasn't moved an inch.
  • Influence vs Manipulation Bec explains the difference between making someone do something they don't want to do and making them want to do it, and why that distinction matters for how we build defences.
  • AI-Powered Reconnaissance Find out how AI has turned open source intelligence into a fully automated pipeline that can build tailored attack scenarios from public data in under 30 minutes.
  • Deepfake Voice and Video Attacks We get into why real-time voice cloning combined with genuine project data and manufactured urgency makes modern social engineering attacks almost impossible to spot.
  • Layered Context Attacks Discover why the most dangerous attacks don't rely on a single trick but layer urgency, authority, familiarity and isolation together until there's no reason to doubt what you're seeing.
  • Family as an Attack Surface Children on gaming platforms are being cultivated to share information about their parents' work and routines. We discuss why the family network is now a recognised route into executive environments.
  • Gut Feeling and When to Trust It Bec and Richard explain why intuition is often the first signal that something is wrong and why corporate culture has trained people to ignore it.
  • Confirmation Bias in Action A group of colleagues all received the same phishing email, checked with each other and decided it must be legitimate because they'd all got it. We discuss why that instinct is exactly what attackers rely on.
  • Why Security Awareness Training Measures the Wrong Thing Phishing click rates going down doesn't mean your organisation is safer. We discuss why this metric wouldn't have prevented any of the major social engineering incidents of the last few years.

Resources Mentioned

Bec McKeown

Mind Science Ltd

Richard Cassidy

The Psychology of the Machines

Rubrik

Cialdini's Six Principles of Influence

Gary Klein / Recognition-Primed Decision Making

Trend Micro AI-powered OSINT research

Deepfake fraud - regulatory warning

Connect with your host James Rees

Hello, I am James Rees, the host of the Razorwire podcast. This podcast brings you insights from leading cyber security professionals who dedicate their careers to making a hacker’s life that much more difficult.

Our guests bring you experience and expertise from a range of disciplines and from different career stages. We give you various viewpoints for improving your cyber security – from seasoned professionals with years of experience, triumphs and lessons learned under their belt, to those in relatively early stages of their careers offering fresh eyes and new insights.

With new episodes every other Wednesday, Razorwire is a podcast for cyber security enthusiasts and professionals providing insights, news and fresh ideas on protecting your organisation from hackers.

For more information about us or if you have any questions you would like us to discuss email podcast@razorthorn.com.

If you need consultation, visit www.razorthorn.com, We give our clients a personalised, integrated approach to information security, driven by our belief in quality and discretion.

LinkedIn: Razorthorn Security

YouTube: Razorthorn Security

TikTok: Razorwire Podcast

Instagram: Razorwire Podcast

Twitter: @RazorThornLTD

Website: www.razorthorn.com

All rights reserved. © Razorthorn Security LTD 2025

Transcript
Jim Rees:

Social engineering is something that has been around since we started clubbing one another over the head with rocks.

Bec McKeown:

There's a difference between influence and manipulation.

Richard Cassidy:

We tend to think of social engineering as a cyber security problem and it actually isn't. It's a human problem that cyber security has inherited.

Jim Rees:

And quite often with a lot of social engineering, it's a long term thing. I mean you can do the short term stuff, but you'll get called out quickly.

I think the most insidious stuff is when it's done over a longer period of time.

Bec McKeown:

Fell for a phishing link. That was because under pressure, busy Friday afternoon and they just happened to time it with a fact.

I'd just done my VAT return for the first time unhelped with yeah, unaided by my bookkeeper.

Richard Cassidy:

video fishing has surged over:

I don't have the figures for this year. They're not, but my goodness, are you kidding me?

Bec McKeown:

The attackers know what they're doing, they know exactly how it's going to play out, whereas the defender has not always any clue that they're in the middle of this thing.

Jim Rees:

One of the things that worries me the most is how we're getting to start to see some real serious targeted social engineering attacks against organizations.

Richard Cassidy:

If you can't get the executive directly because they're well protected, well trained or they're highly spectacled, which hopefully most executives are, then you go to somebody who isn't. What about their children?

Jim Rees:

Welcome to the Razer Wire podcast where we discuss all things in the information security and cybersecurity world, from current events and trends through to commentary from experts in the field, providing vital advisory on what it is to work in the information security and cybersecurity space.

So today to explore the wonderful world or re explore the wonderful world of social engineering, why it's something we should be concerned about, where we think it's going with some of the more recent updates in technology and the capability of the wonderful field of AI, which we can't seem to ever get away from, and why social engineering works as well because it's something that's very important. I brought in two fantastic guests.

One who can look at it from a CISO perspective, from concerns within the market perspective, and another one who understands a lot more about why people do it, the mechanisms behind it and pretty much everything there is to know. About the psychology behind social engineering. So my guest today, I have Richard Cassidy and Beck McCowan.

Beck, do you want to say hi to the listeners out there, Tell them who you are, obviously. Hopefully they've seen the videos you've done with this before. But, you know, let's do the proper intro.

Bec McKeown:

Yeah, sure. My name is Bec, I'm a chartered psychologist. I've been working as a psychologist for 20 odd years now.

Defence is my background and I've for the last sort of probably eight years or so transferred into cybersecurity. My area of expertise is human performance under pressure and I think that's really very much related to social engineering and how that works.

Jim Rees:

Fantastic. And Richard, so many videos we've done together and we're here once again.

You, the man at the coal face, you see this kind of stuff within your organization and the various different organizations you've worked with over the years. Do you want to introduce yourself?

Richard Cassidy:

Absolutely. CEO Richard Cassidy, a mere CISO at Rubrik, been in industry, industry about 26 years, but who's counting?

And I've worked across pretty much every angle you can approach it from vendor advisor, board director throughout all of that, I've been a practicing paramedic on the NHS front lines and I've also just finished writing my first book called the Psychology of the Machines, which is about what AI is doing to the way we think and make decisions. I did study psychology back in the day, so that's my background, but I'm not a psychologist. Nowhere near as famous and credible as Beck.

And we're here to have a great conversation and weave in all the things that between us we've had experience on.

Jim Rees:

Fantastic. Absolute pleasure to have you both. Now social engineering, I like to start things with a bit of a journey, a bit of a story.

Social engineering is something that has been around since we started clubbing one another over the head with rocks. You know, it has been a thing for the human species since time immemorial.

Whether it was trying to convince somebody that, you know, it would be really good to have that food because I'm really hungry and you're not as hungry as me. Through to various different nation states, like for instance, Cleopatra, she was a master at social engineering.

Some of the stuff that she managed to do and get away with is truly impressive.

And there have been many, many cases over the history of social engineering and the history of the human race where this has been a significant piece of, dare I say, manipulation or the ability to get what you want out of somebody who doesn't necessarily want to give that to you initially? Is that a fair kind of walk in? I mean, let's go with Beck, you're the psychologist here.

Tell us a bit about social engineering and kind of that history.

Bec McKeown:

Well, I think that you're absolutely right. It is, is about manipulation. There's a difference between influence and manipulation.

And it's an interesting thing to think about because manipulation is where, you know, you're making somebody do something they don't want to do. Influence is where you can make want to do the thing that you don't want to do. So I think it's an interesting distinction to look between that.

Yes, social engineering has been around forever. I think AI is possibly a new medium for that, but is it actually changing the things that underpin it?

And for me, social engineering actually works operationally because what's happening is the attackers are engineering the conditions of which you make that decision in not just the message. And I think that's quite important to understand that because I still hear that people are the weakest link.

Thing is said quite frequently, but actually it's not about that. What the attack is doing is engineering those conditions.

They're creating time pressure, they're creating ambiguity, they're creating sort of signals, authority signals that make you want to act a bit faster. So they're not hacking people really, they're shaping the conditions in which people make decisions.

Jim Rees:

Fantastic. Richard, what is your take on the history of social engineering?

Richard Cassidy:

Well, it's a great way to start, isn't it? Because it's one of the oldest disciplines, to your point, in human history. And actually that's why it works, right.

The techniques haven't fundamentally changed in thousands of years.

And to your point, what Cleopatra did with Caesar, what every intelligence service has done with every target since the beginning of statecraft, as we call it, you know, and what every con artist, right, and there's plenty of good movies you can watch about that as well, has ever done. It's all the same playbook, right? You build trust, you create urgency.

To Beck's point, you exploit authority and you make what we call your mark in a social engineering campaign feel pretty special. Or under pressure, can be either or. But the medium does. Has changed. Right.

It was very different back in Cleopatra times, of course, but the psychology in my. In my estimation hasn't actually moved an inch at all.

And what's interesting from the conversation I'm having, and I've been a part of building training programs for social engineering. And so, you know, what's Interesting is that we tend to think of social engineering as a cyber security problem, and it actually isn't.

It's a human problem that cyber security has inherited, in my opinion.

inciples of influence back in:

But, but the reason I mentioned this, because every one of them has actually been weaponized by spies, by con artists, propagandists for centuries, even before they were given names.

So I would say to your point, the reason it still works social engineering in boardrooms or on phones or in inboxes or deep fakes now as well, is actually the very same reason I would argue that it worked back in ancient times. We are social animals. Of course we are. You know, we're wired to respond to authority. Not all of us, but most of us from, from research perspective.

And we're wired to trust people who seem very familiar to us, that share similar stories, and even those that act with a sense of urgency can sort of hit the right psychological markers at the right time. So these aren't flaws, by the way, in our psychological makeup. They're kind of the features of who we are and what we become.

So, you know, attackers to my final line on this, you know, whether they're nation states or whether they're cyber criminals or whoever, right.

They simply understand, I would say, that better psychology gives them a better capability around social engineering and they're doing it better than the defenders. So there you go. That's my intro to the history and why we're here.

Jim Rees:

It's interesting actually, because in some of the read ups that I've done for this particular video and from my own experiences, I mean, my children are a master of social engineering when it comes to, to me, you know, when they want sweets or something, they know that if they got the right beats that dad's probably going to buy them whatever. You know, a lot of salespeople learn a lot about social engineering.

It's kind of part of the discipline of what they're doing, but not in an insidious way. You know, it's a way.

And from what you guys have said, and I am mere layman when it comes to this kind of thing, it's not something that necessarily is bad, but it can, as you say, be weaponized. I mean, you know, look at what the Russians did with the kind of honeypot side of things. They were a master.

I mean, I'VE watched some, some really good videos and read some really good books on how they did that, you know, and how spies work as well and how they integrate themselves into society and quite often with a lot of social engineering. It's a long term thing. I mean you can do the short term stuff but you'll get caught out quickly.

I think the most insidious stuff is when it's done over a longer period of time. Is that fair to say Bet?

Bec McKeown:

Yeah, absolutely.

In the defense world, when I've worked with people who are engaged in that level of that sort of work is that it's, it's about having patience and taking your time and sometimes I can spend many months just even getting somewhere near their mark because to do it any quicker would, you know, would give the game away sort of thing. There's a whole lot of patience involved in SMC certainly.

I think when it comes to cyber security and phishing and that sort of thing, it's, there's that sort of the, the mass push, you know, there's a bit of luck involved there as well as to getting the right thing with front of the right person at the right time. I nearly fell for a fishing link.

It was back in October sometime and that was because under pressure, busy Friday afternoon and they just happened to time it with the fact I'd just done my VAT return for the first time unhelped with yeah, unaided by my bookkeeper and it was a MRC problem with your VAT return thing. And I just saw and I thought oh my God, I've done something wrong.

So I'm under pressure, I'm nervous about, I haven't got the confidence in what I've done with that sort of thing. So I just fired the email off to my bookkeeper, said oh we need to talk about this on Monday. And she just rang me up and said do not do anything.

And all the signals were there but I hadn't actually read the signals because I was too busy.

So there is some long term ways of getting in with people but I think certainly in cyber security it seems to be very much more on the instant pressure creating those, shaping those conditions for people to make snap decisions.

Richard Cassidy:

Your story on Russian intelligence operatives and then the analogy with your children, it's probably more common than most people would be comfortable admitting to themselves. But the principles are identical, aren't they?

Identify what the target wants, position yourself or whoever you may be as the person that can provide that and then build a relationship over time until the ask feels a Little bit more natural.

And the difference between a child wanting sweets and a state actor running a long term human intelligence operation is just the stakes and the patience. Children will want it quicker. Russian nation states, whoever they are, I'm not just picking on the Russians.

It could be, it could be any of them will take longer.

And patience is actually the thing that does catch most people and organizations completely off guard because we are, we have been conditioned, I would suggest, to build defenses against the faster type of attacks.

And you know, so that's the phishing email, the phone calls, the origin request, transferring money to some Nigerian prince for all sorts of manners of physical improvements. None of which ever worked, by the way, I can just tell you that. And you know, but we're, we're completely underprepared for the slow one.

And Russian intelligence operations, they've got actually very well documented examples going back decades and decades. And they will run an asset, as it's called, for years before activating them.

And these are the terms you're going to, you would hear in cyber operations. And actually what that means psychologically is the person being cultivated doesn't recognize that it's cultivation at all.

And they think they've made a friend or a contact. I'm going to go off on my own tangent here because it's a short story I'm going to share.

I hope my brother, I'm sure I have permission to share this, but we'll go on it. So my brother was on dating websites and he had made a connection with somebody that seemed legitimate, wasn't in the uk they were abroad.

And over many, many weeks, you know, they built a good relationship, they were sending videos. What he didn't know was it was all AI generated. And, and then there was the, hey, can you pay for my flight to come to see you?

And then of course he transferred some bitcoin and then they ran off into the sunset with his money. You know, and it just goes to show you, there are no, there's no honor. We used to, we said with many podcasts, James, no one amongst thieves.

There's no honor among social engineering groups as well. So, you know, that's something we also to think about, right? They play on your emotions as much as they play on your urgency.

And look, this isn't unique to espionage. I would suggest that same dynamic plays out in corporate social engineering.

So to your point, with sales teams, I hope this doesn't get me in trouble at Rubrik, but you know, a fraudster who spent, you know, six months building relationship with a finance director before asking for anything, money or otherwise.

Well, I mean, how different is that to the vendor who's become the trusted advisor before recommending a solution that ultimately served their interest far more than the clients?

Now, I'm not saying that's what all vendors do, but a lot of customers will tell you they've been burnt by over promising, under delivering, buying 100% the platform form, using 20% functionality. So long term, social engineering is everywhere. We just don't call it that in the corporate world.

Jim Rees:

No, absolutely.

I mean, you know, over the 30 years I've been doing this, I've seen social engineering in all kinds of different ways from the romance attacks where I've had friends and associates that have been burned by that. The age old, I've got nude pictures of you transfer some money or I'll release them.

And that tends to happen to the younger generations, like the, the men and the girl, you know, the girls from, from a younger era. I had to help a friend out whose son was getting really upset because he thought he was going to wind up in trouble.

I've seen it on the corporate side of things.

Obviously, you know, you've got the, I think one of my members of staff of a former member or staff got a WhatsApp allegedly from me saying, you know, I need you to transfer some cash or I need you to, to sort this out for me, you know, and they validated it with me. And I looked at it, I thought, oh, that's interesting, that's definitely not me.

So it's coming in a lot of different formats, but I mean, moving to the more modern times of where we are at the moment, do you feel that the kind of spray and pray kind of attack, I mean, obviously it's always going to be there, but let's face it, that kind of methodology where you send out phishing links and what have you, for a while, it got easy to spot them. It's now a lot harder to spot them.

But I think one of the things that worries me the most is how we're getting to start to see some real serious targeted social engineering attacks against organizations.

And as you Beck and you Richard both said, the most insidious side of this kind of thing is the real long game stuff where you think you're talking to somebody who's your friend, they're definitely not your friend. And then over time you find out they scupper you where.

Be it somebody who convinces you to become their business partner, be it somebody who convinces you that, you know They're a vendor when they're not actually the vendor. Are you starting to see a lot more of those now that we've got these kind of like AI a bit or the ability with AI to take a voice, mimic it?

Obviously we've got the whole kind of deep fake for video.

We've got documentation deepfake now which is it's not so much social engineering or is it, I don't know, I mean what are you seeing at the moment, Deck, what are your thoughts? And then we'll move on to Richard.

Bec McKeown:

I think with me, I don't sort of look at social engineering. You know, that's not my area of expertise. My area, it's firmly within psychology of how people behave when they're under pressure.

So I haven't actually seen that much by way of deep fakes. I've had conversations with somebody who morphed into somebody else mid conversation. So I understand the power behind that.

But I think the, the, the underlying point is, is that the technology with AI is making things so much quicker and easier.

And I think even though we talk about having patience and building up the story, building up the trust that is probably fast tracked I don't know how many times.

And what I was thinking about when you were talking there was that I did hear of an example where somebody has an email, thought it was from the cfo because that email mentioned the sort of a confidential acquisition that was going on. So it made it seem like actually there was inside information.

Now how they got that might not now have been through an insider, but by true scraping enough information to make some assumptions about what's going on with that organization. So I think that that is possibly more of a problem than it was 10 years ago.

Jim Rees:

And people are patient as well. I mean, let's look at the psychology behind social engineering.

I mean, you know, there are some really good social engineers out there who craft a whole career. Is that the best way to describe criminal career around doing this kind of thing? And people have gotten really bloody good at it.

And I know that obviously from your time in defense, you've probably got a hell of a lot of stories that you can't necessarily tell us about. But is it as bad in the underworld as we suspect it is with the amount of people who are actively learning and genuinely good at this kind of attack?

Bec McKeown:

Well, I think that AI and I mean all of the things around that sort of level of technology means that you don't necessarily have to be an expert anymore because there's whole ways of Becoming an expert very, very quickly.

And I think the other, the point that popped into my head while you were talking just then was, is that you think that there's that sort of asymmetry between attackers and defenders. Attackers, they've got time to plan, they've got control, know how to control the narrative. They're introducing information in the secrets there.

They're sort of operating in a very designed environment. The person on the receiving end of that, the defender, we've got fragmented inputs, little bits and bobs coming in.

They don't really know what's relevant. They're operating in a very disruptive environment.

So you've got that immediate advantage of the attackers know what they're doing, they know exactly how it's going to play out.

Whereas the defender has been not always any clue that they're in the middle of this thing and they're not always aware that they're a decision point, if you like. They just carry on the normal day to day activity until something waves a flag that they may or may not react to.

Jim Rees:

Richard, what are your thoughts?

Because I mean, you know, us infosec professionals with kind of like that technical background understand that quite often, I mean, if you're really targeting a social engineering attack, you couple it with other attacks as well.

You know, you've got the phishing and all the rest of it, but reconnaissance and information on your target seems to be a lot more people are starting to do their homework a hell of a lot better. And of course we, we put ourselves out there quite a bit on the Internet.

We've got a LinkedIn side, we've got, you know, the about us pages, we've got, you know, and if they've got access to your email internally.

And Beck, you mentioned something quite interesting that some, you know, one of the social engineers, they knew something that was quite sensitive to the organization.

So as you say, they must have either had somebody else that had planted that information to them or possibly had access to their systems and services. Are you seeing that kind of thing, Richard? Is that, is that a dense attack that keeps you up at night?

Richard Cassidy:

I would start with this statement that the attacker often knows you better than you know yourself, especially if they want to, if they want a successful operation. And I'll elaborate on that because it's very contentious point.

Before any messages are sent to you, before any deep fake is created, any sophisticated social engineering operation, they've already been running for weeks, if not months on profiling who you are, if you're of the value that they deem you to be for that level of work. Right. They still are. Spray and pray. We're still seeing that.

And the unfortunate challenge is open source intelligence is now the reconnaissance phase.

And it's actually been transformed by AI into something that's pretty much unrecognizable to me, at least at the level of CISO from what it was even five years ago.

And Trend Micro published research just back in February of this year showing that AI has turned OSINT from a manual effort into a completely automated pipeline. And I don't think anybody listening or watching this will say that's not true. That's an obvious statement.

And now we're moving from LinkedIn profiles to fully tailored attack scenarios in 30 minutes. And that is the time. 30 Minutes is what the research is showing. And you know, if we go to the deep fake. Right.

The most significant shift in the last 18 months, because remember, I have a lot of conversations with fellow CISO CIOs is actually to your point, deepfake enabled voice attacks. And so we've moved from these phishing emails to real time voice cloning and attackers generating the CEO's voice or whoever's voice.

ideo phishing has surged over:

But my goodness, are you kidding me? And by the way, that's not an error. You can check that data. And, but I would say that because we're back on the psychology side.

I'm, I am on the tech side. So let's talk a little bit about tech for a moment.

The ttp, the tactic technique procedure that keeps me up at night, James, to answer that question is what I called layered context attacks. So the attacker doesn't just clone a voice. Right. They've already done the osint, although cloning is part of it. But they know the relationship.

They know most of the current projects you're working on because you've talked about it or you've got that open GitHub repo that you haven't locked down and we can see what you're doing. They know your travel schedule because you're posting where you're heading. Oh my God, I do that a lot.

I'm already in my head saying stop people while you're traveling, but they know your travel schedule. Right. And they look at the way you talk, your communication style.

And so that's why this layered context attack becomes easier, because they can create the deepfake, phishing or voicemail. They can create the context around everything you're sharing publicly.

So actually, the call, when it comes in, the email, it sounds right, it references the right things, it comes at the right moment. And the target has got no reason to doubt because everything that you see checks out to you. To Beck's HMRC story.

Now, we're not thinking more about a technical problem.

We're going back to a process issue, and we should be doing better as individuals on what we're releasing on channels, how much we're being open about certain things. And now when I write LinkedIn posts, I don't mention anybody's name unless I have their permission.

And if I have to create stories based upon what I've experienced in the business, I make up fictitious names and stuff like this because I don't want me to be the source of data for a social engineering attack on a trusted colleague. So that's kind of where my views are and what I'm seeing over the past 12 to 18 months. The figures are just ridiculous and very concerning.

Jim Rees:

Yeah, it's certainly getting a little bit worrying. I didn't realize it was quite that bad.

And, yeah, it'll be interesting to see what the new figures are, bearing in mind what we're going through at the moment. And I think one of the things that us as infosec professionals are having to do is really kind of review our defense in depth.

It's something I've been saying for a while now to start accommodating for more and more different types of attack patterns that we kind of did before with security awareness and that kind of thing. But these types of attacks are getting so good.

And we've picked up a number of clients over the last couple of years, really from people who've transferred money to who they thought they were transferring money to to pay a bill. And you find the original attack came, the phishing attack came from the distributor who'd been compromised.

There's a whole chain of compromises sometimes that go into that final attack where they start getting vast quantities of money.

I know one organization that transferred, I think it was something in the region for just over a quarter of a million pounds on an email request from a financial director that was sitting about 10ft away from them. And they didn't validate the details of the request because the request obviously wanted them to transfer it to a bank.

Account and you would hazard a guess that people would go, oh right, let me just double click check that this bank account is right. But it was almost double reinforced, I suppose by the fact that their FD was sitting 10ft away from them. They just didn't want to check.

And that was, that was kind of a mid level accounting or finance department individual. It wasn't a high end, but that's the kind of stuff that we've been seeing quite a bit.

And then talking to identify labs with some of what they've experienced with, for instance the FD who got on a call with the other C suite members only to find out after he transferred 25 million to pay what they thought was either some debts or some bills or something like that, or investments.

To find that every single one of the C suite that was on that conference call was actually deep faked both visually and vocally, is frightening in its possibilities because geez, how do you combat that?

Richard Cassidy:

Well, I mean it's becoming such a problem, James, that regulators are now catching up with this. So in the UK specifically the FCA has formally warned UK firms about inadequate controls for deep fake fraud.

And now it made regulation expectations around this very explicit. And that was of March this year.

And if we look at:

of:

. I wouldn't even guess what:

And I wasn't sure to bring this up, but I think it's something we should talk about and I would love to Beck's Fuse on this family social engineering. It. It's actually an attack surface that a lot of people are talking about.

And it first came to my mind when I sat with the in, in the American Embassy in Rome in summer of last year, presenting with the FBI who had. And, and they did a talk on this and I thought, wow, I didn't even know about it. I did some research and here we are.

So, so we're always talking about social engineering of, of grownups and adults and you know, that certainly represents one that we've all got to deal with. The premise is straightforward, right?

If you can't get an executive directly because they're well protected, well trained or they're highly spectacled, which hopefully most executives are, then you go to somebody who isn't. And then so typically operations tend to move down that food chain to the pa, then down to the direct reports and so on and so forth.

But what about their children? If they have them, what about their nieces and nephews, right? It doesn't have to be their, their children, it can be children. Family.

Online gaming platforms have become a primary attack vector and the research whilst early is growing in this area.

So children between the ages of 8 and 16, we all know that, are expending significant amount of times on online gaming environments and they interact with strangers routinely. There's another podcast on that alone.

But the social norms of gaming, helping, sharing files, sharing in game content, the trust is already at play at a very young age and they're the exact dynamics a social engineer will thrive in. What you then are able to do is state sponsored. Actors particularly are extremely patient.

We talked about this earlier and they can spend absolutely months building relationship with these children through online gaming platforms. And then you get into the small asks, hey, what does your mum do for work? Or does your dad travel a lot? Oh yeah, he does.

What's his next business trip? Where's he going? You know, what's the name of your dad's company?

The kids aren't equipped to understand intelligence gathering disguised as what we call friendly conversation. And then it's like, hey, would you like Robux? Would you like in game currency? Hey, well can you click on this link?

I'm going to put it in the chat window for you and just install this. And there's a lot of malware now that running rife on online gaming. So the charge offered something, they download it.

Now the family device that they're running it on is compromised and that family network is more often than not in the age we're in, connected to the executive environment, to the, to the business environment. So I don't want to go into the details of how the attack will move from there. That's separate research.

But have we thought, do we even think about educating our children the psychology of how we'd even do that? Beck I don't know if you've ever come across this or it's prosth your desk but it's something I think we don't talk about enough.

Bec McKeown:

I think it's something that I've heard about in the defence realm. Well that this is again it's not a new thing, it's just a new way of doing it.

And it goes back to that age old problem of how on earth do you get the general population to keep up with all of these changes?

Because it's slow, unless you've experienced it, you don't understand is more difficult particularly because we always tend to think of our home life and our work life as being completely separate.

And I think this is something that comes up in conversation quite a bit I have is that when you work in defense or you work in intelligence or something like that, you know about these things. You know that there are boundaries.

You do open source intelligence on yourself, your family so you understand what your pattern could look like to an outsider. But particularly, you know, in cyber security, your background is technical.

It's not as an intelligence officer we're not even aware that these things are a thing. It brings up a new problem of making what was a very specialist area of knowledge is going to have to become more public.

I mean we at Cranfield we used to do a module on social engineering whereby we would do your own sort of thing for into the class and just say well here's all of the information we've pulled from different places. This is how I know who your family members are and what they're doing.

And I think it was always very shocking to the people sat in the classroom of how much information is actually out there because it's gathered from so many different places. So again, is it a case of the way that the world is going to move? Is that a whole part of online behavior?

I mean I don't know what they're teaching schools. I haven't got school age children so that's. It's not in my awareness.

But it'd be interesting to know what's going on at school level because again that's a different. That's where the education starts, isn't it?

Jim Rees:

Yeah, I mean I've got children at that kind of level and I mean they're still quite young so I don't think it's quite hit yet.

And I'm going to be very, very interested to see what that curriculum looks like because being an infosec professional myself at the coal face, you know, I Think it's going to be very different from what they're taught because it's going to have been valid for maybe 5 years ago, 10 years ago. And there's a lot of movement now towards protecting children online and so on and so forth.

And I think that it's not just the children that we have to worry about, but it's also, as was, you know, inferred other people as well.

I have read accounts where it has been found that somebody's wife or somebody's husband, you know, the target is the other person, and they found them to be on Tinder. They found them to be playing away from home and kind of jump in on the action, and then it can be done that way as well.

There's a lot of information that you can gather now with AI that allows you to very quickly ascertain whether or not some, you know, scraping information from Tinder on people in the local area, and you find somebody who looks exactly like somebody's wife or somebody's husband, boom. You know, you've got an in. Social engineering works very well in the romance side of things.

And we know that because if it didn't, then we wouldn't have so many bloody romance scams. And with AI now, I mean, we all laughed about the.

The poor lady that was conned by thinking she was having a relationship with Brad Pitt, and she got some really dodgy pictures. I mean, we look at them and think, my God, these are bad. But now you can actually do it. So they're not bad. They're actually quite good.

And it doesn't take a lot of skill. So I think I've got a lot of concerns around how this is going. I mean, one thing that I think the audience would be very.

It'd be very good for the audience to understand.

Are there some key things within a social engineering attack, a targeted social engineering attack, Beck, where you can spot or you can raise maybe a red flag? I mean, what is the process? If you were investigating something, and I'm sure you were involved in these kinds of things back in your defense days?

I know you've got to be careful what you say, but we're just talking in generalization. How do we get people to spot and raise that flag and say, actually, this might be something else? Is there a way to do that?

Bec McKeown:

I think from my perspective, it's not about spotting the red flag that's incoming. It's about spotting the signals that are going off in your own head. Because really, social engineering isn't just about that. Moment of reaction.

There's a whole chain there. So you've got your initial interpretation. This looks legitimate. It's not even a conscious thing. There's just nothing in there to raise a flag.

But sometimes what you get is that sort of something doesn't feel right. Then you then look for something that's going to confirm, is it what I think it is? Then you get what we call confirmation bias.

So we've made an assumption, something doesn't feel right. I think it's this. Then I go and look for information that proves to me that this thing is what I think it is.

That's the moment where you don't even know that you're at a decision point. But because of the way the brain works, it's designed for speed and efficiency, so you just carry on.

But I think it's understanding that when you have that little gut feeling that, oh, something doesn't feel right, that's almost like you're left of, bang, your cue to pause. And instead of thinking, this doesn't feel right, let me go and get some more information to find out whether I'm right or not.

It's just, what else could it be? So it's that initial acting on that initial gut feeling that you get instead of ignoring it.

But that's really hard to do in the moment because of the way that the brain works is just the world doesn't feel a bit right. Let me go off and do something. And it's only when you sit back after the event and think, well, actually, what happened there?

What happened before as I made that decision, what was going on before that? But you can only do that in retrospect.

And sort of doing reflective practice isn't something that comes naturally because we always want to get on with our day.

And actually, unless there was a big consequence where you've called to have a chat with somebody at work because you've said many way you shouldn't have done, if that big consequence doesn't happen, you've never got cause to go back and think about every single decision you made. Really difficult. But for me, it's just about being aware of your own thought processes.

And what happens when you get that, oh, that doesn't feel right. What. What do you normally do? And what could you do to actually pause in that moment and stop that automatic rush to action.

Jim Rees:

Is that like an instinctive thing?

Because obviously, you know, I've read a. I've read some really interesting studies around kind of like your mirror, mirror neurons, you know, and how they work and how they operate.

And sometimes when you're walking, say at night and you start to feel like somebody's around, it's usually because your perception, you've perceived something or your part of your consciousness has perceived something that you haven't necessarily perceived, but it's replayed through the mirror neurons, which makes you feel anxious, which makes you then heightened. I'm not a psychologist, but hopefully you can add meat to those bones. Is it the, is it the same thing?

Bec McKeown:

It's experience. Intuition is experience, but it is, it's very much at the. Yeah, the non conscious level. The thing you've just described there happens on.

You could be driving down a busy boat away and there's a particular lorry that's weaving about, but you just want to get past it because you're not sure that something's not going to happen. But again, it's just the fact that it happens at sort of non conscious, semi conscious level.

You're making decisions all the time about how to maneuver around and keep yourself safe, but you don't actually understand you're doing it.

It's only when you become aware of how the brain works and the sort of things that happen like that you start to notice it a bit more because you're understanding how you behave in certain situations. And you know, when you get the spidey senses we all talk about. Yeah, it's learning to listen to that. But obviously then you've got coupled with.

If you're acting on every single spidey sense you get, if you're ever going to get through your day, you know, so it's difficult, it's not easy stuff.

Richard Cassidy:

Richard, I guess to answer your question as simply as I can, urgency is the most obvious trigger. But a sophisticated operation never relies on just one lever, right? I mean they layer them, as I said earlier, urgency and then the authority. Right.

Someone's senior claiming seniority. Then you have the familiarity piece I talked about earlier. They know your name, they know your team, your current project.

And then you often have these, these modicums of isolation in there.

Right, let's keep this between us for now, you know, and, and that actually that last one is, is probably the one I'd pay close attention to because legitimate business interactions almost never require you to keep something for your colleagues in a moment. It just doesn't happen. Right. But whether those appear together, the probability that something is engineered does rise significantly.

But not enough to pause, I would say. But to go back onto the kind of the intuition stuff, the second signal is out of pattern behavior. I think that's the easy one to spot.

Jim Rees:

Right.

Richard Cassidy:

Your CEO doesn't normally contact you directly about financial transfers, do they? Or your bank that doesn't normally call you asking you to confirm your number and your sort code. And you know there's called calling about fraud.

Right. And also your IT team, right, they don't need your credentials over the phone. They're the IT team.

I mean, come on, ask yourself some logical questions here.

But when, when the channel that it comes through or the ask is inconsistent with how that person or the team in that organization normally operates with you, then there's inconsistency there. And I think that's meaningful. And most people feel it. You do feel it, right? And, but they don't override.

And I think that's the mistake because on intuition, it's a really fascinating part of psychology. This, the research is actually quite clear on this. Most people's expectations and intuitions are quite closely linked.

So Gary Klein is the person I will attribute the work to here. And he, he did work on what was called naturalistic decision making.

What he showed was that experienced professionals develop what he's calling recognition primed decision making. And this is basically a cognitive pattern matching capability that's built from thousands upon thousands of real interactions.

So your mirror neuron example there, James, is going to. Is a good segue into that.

So when something feels wrong before you can articulate why, it means your brain, more often than not, not always, has already noticed an inconsistency that your conscious mind hasn't caught up with yet. So your subconscious versus conscious. And in, in intelligence, I've been there myself in various projects and guises.

And in military context, this is actually quite well understood and it is acted on. So the feeling that something is off is. Is off. Sorry, is. Is often treated as a signal in military that you should examine.

And there's a chain of command for sort of pushing that signal up in military environments. In the corporate world that we live in, we've actually been trained to dismiss a lot of the intuition side of things.

Follow the policy, follow the playbook, follow the process. And we need to be rational about stuff. We should give doubt more benefit.

Not that we're being paranoid, we're just trying to allow our intuition with the right sort of guidance and guardrails to kind of guide some of the decisions. So yeah, the red flag databases, there aren't any particular. But intuition plays a big part of this.

And that's because you already have pattern recognition. And we could Train better in that corporate environment, but we don't.

Bec McKeown:

Yeah, I was interested, actually, as you were talking there, I was just thinking about something, an incident heard about a couple of weeks ago where somebody got an email. It felt off. It was a bit strange. It was requesting urgent action. They weren't sure about it, so they just mentioned it to a colleague.

And then there's a little group of them, had a bit of a chat about it and three other people who got the same email. So nobody did anything because it felt off. I checked it with my colleagues, they got me emailed too. Oh, it's all right.

And obviously by the time security became aware of it, it was too late. So it is. Yeah, exactly like you say it's about, do we actually understand the way we work and how our brains work?

Because if you notice those things, then you might actually be able to pause on it. But it's not something that's generally taught, is it?

Jim Rees:

So is that called consensus bias?

Bec McKeown:

There are 176 different biases. I think there is. Or something like that.

Jim Rees:

Probably one of them. Well, it's validation, isn't it? It is a form of validation. Oh, we've all had it, so it must be genuine.

Bec McKeown:

Yeah, yeah. So, you know, it is difficult. I don't think you're ever. You're never going to come up with perfection.

You're never going to be able to stop all of this. But I think that if people become more aware of these things actually happening.

I mean, the book you were referring to, I'm just looking down at my bookcase there because I've got it somewhere about recognition, prime decision making.

Let's just sort of make that standard reading, you know, because it's not something I was ever taught in school, mind you, that was a long time ago, but I think it's. To me, it's more about awareness of who we are as people, how our brains work, how we operate.

Because if you don't even know that's a thing, how can you ever be aware of it?

Jim Rees:

Well, this is it.

I mean, one of the things I always, when I'm doing virtual cisoing when I'm going in and helping organizations be at the board level or be at other levels within the business.

One of the general pieces of communication I try to get out as part of security awareness training is there is nothing wrong about validating something. If you do get a twitch or a thought that something isn't quite right, then check in. You're never going to get shouted at for checking in.

Now, people might be a bit worried about their managers getting annoyed because they've gone above the head, but that's where security steps in and says, actually guys, no, they're right to do that. What if it was a problem this time it didn't turn out to be a problem.

So don't vilify them for coming and checking on something we want them to check. Because if they don't, we could end up in a situation where there's a loss and then that becomes a management awareness program.

Because I do like to teach management and C suite. Look, you know, listen to what your people are saying.

If they're coming to you with a problem and you immediately don't think it's a problem, take a step back and just think, actually why are they asking? What are they asking?

Did I actually, you know, they saying I sent some communication out and I didn't because there might be something else at play here.

Richard Cassidy:

James, this is a good point. What do organizations need to do differently? Because like you, I think about this all the time and I think organizations keep.

Or the way I see it is keep trying to solve the wrong problem here. Right? And you'll know this, right? Security awareness training programs assumes that knowledge protects people. It doesn't. Right.

You can run the most comprehensive phishing simulation program in the world. And I ashamedly to say I've been caught by a couple of those tests in my own role. So hey, nobody's infallible.

But you can run the most comprehensive simulation programs.

And a highly trained CFO will still authorize a transfer when they receive a call from other executives with a legitimate voice referencing a legitimate project at a moment when they're already overwhelmed or between flights in Singapore and wondering whether they're going to get home because of the fuel shortages. Right? So the solution isn't actually more. More trading, it's actually better design.

And if you if and think about some of the things we said earlier, right?

If your executives are being profiled not just through open source intelligence, but through their families gaming accounts and the children's social media, you know, there's an education problem there that we're not telling the corporate world about. Max point.

There's things that schools and education students should be thinking about more and having that conversation to include families in these kinds of trainings. I do see a lot of organizations still measure their security posture by whether their phishing simulation click rates went down.

Look, I mean, come on, you got to ask yourself whether that metric would have actually prevented any of the major Social engineering incidents of the last three to six months, let alone number of years. And I don't think it would.

And not to bug the book again, but in the psychology of machines that I've written, this is actually one of the central arguments, right? It's not that AI has created new cognitive vulnerabilities, it's actually scaled the exploitation of ones that already existed within us.

So the attacker now has an AI accelerated capability to find your very specific cognitive scenes and press them at the very moment that's going to matter. And that isn't a technology issue, is it?

We're still talking to the point of this podcast about a psychology one, and it's one that we need to be doing better at at a corporate level and within our families.

Jim Rees:

Well, it sounds like people should be buying your book when it comes out and I have no problems with you plugging the book back. You know, you're, you're the, you're the master at creating all kinds of, you know, training courses and what have you.

And it sounds like you've got a brand new one there to, to, to create. You probably make an absolute packet out of it.

Just, just remember us, just credit, credit us in the, in, you know, when you built, when you build it on the forward. Our time unfortunately has come to an end. And I mean, we could talk about this all day long.

There's all kinds of great sort like information that you can get from historical events from, you know, known events recently and events that have happened way back in the past. And maybe we can explore that in further podcasts because to be honest, I don't think this is a problem.

As you guys have both said and I've said the same thing. It's not a problem that's going to go away suddenly. It's not going to suddenly disappear.

If anything, it's going to ramp up and it's going to ramp up quick and it already is. So until we can get the new data and we get. You know, it scares the piss out of me from Richard Cassidy about how bad things have got.

Maybe it's something that all of us professionals need to sit down and look are adding to our defense and depth stack. What are we doing about social engineering and security awareness? Because what we've done before probably isn't going to cut the mustard.

We need to start building different messages and different training packs and supporting, you know, other people in the corporate world.

The unfortunate truth is if these attacks are becoming so prevalent, we're going to have to do something because if you do nothing, you're just going to wind up a statistic on one of Richard's next podcasts where he says 20,000 people got compromised. So thank you guys for that conversation. I think we'll return to this in a little while.

I'm sure AI will change everything again in five minutes or two weeks or whatever. Just so you guys can plug what you're doing and what have you back. Do you want to just tell people where they can find you?

I know that you, you know, you've got some stuff in the wings as well. Do you want to plug that?

Bec McKeown:

Yeah, you can find me on LinkedIn as everybody can.

And I've got a website which is www.mindscienceltd.co.uk and what I'm developing at the moment is the diagnostic tool and a workshop for this facilitation program on exactly the things we've been talking about.

So about confidence, about how your mind works under pressure, about decision making under pressure and all of those things that can be compromised because of the pressure that you're working in and about again, building trust and relationships and all of that sort of thing. So psychology of how to work under pressure.

Jim Rees:

Fantastic. So check that out. And Richard,.

Richard Cassidy:

Look, so if you. The website's up www.projectpsychologyofthemachines.com and it's in final review now, so it'll be printing in the next sort of 30 to 60 days.

But actually forget about the book, you can find me on LinkedIn LinkedIn.com food/inforward/rv Cassidy.

I post a lot about most of these subjects and you know, it'd be great to, to, to connect with like minded individuals and have a good chat and please connect with Rebecca too because if you look at her history and her experience, it's, it's pretty incredible. So there'll be a lot to learn from both of us, I'm sure. It's been a great conversation. Thank you.

Bec McKeown:

Thank you.

Jim Rees:

And thank you to all of you out there as well. Thank you to my guests. Thank you to all of you out there.

If there is anything we discussed about in this podcast that you think we should have another one around and dig deeper into something that concerns you. Maybe you've thought of something we haven't.

Maybe, you know, there are different methods that we can deal with this or maybe you want to provide us with further information of how potentially difficult it could be, then please feel free to get in touch with me. DM me, I get loads and loads of DMS all the time now. With the razor wire, raw stuff and podcast.

But I do try to read them and get through the, you know, get through them as much as possible. I can't always answer everything. Thank you ever so much for the massive boost in people watching the videos like and subscribe.

It really helps us with the algorithm. Thank you very much. Look after yourselves and we'll be seeing you again soon.

In addition, I do have a book recently come out, the Cyber Sentinels Handbook. A primer for Information security Professionals.

Now this book is very much geared up towards professionals, all levels of their career, be they starters, be they newcomers, be they people have been in it for a little while and maybe looking for a little bit more direction, albeit the older ones looking to maybe reground themselves in some of the more important aspects of the trade that maybe they've forgotten over time. I've had lots of good feedback from a lot of different readers at lots of different levels, so please feel free to get yourselves a copy.

We've got the E copy, we've also got the paperback copy, and if you don't want to spend any money, you can go on Kindle Unlimited and read the book for free there as well. Don't forget. Thank you ever so much again. Look after yourselves and we'll be seeing you again soon.

Show artwork for Razorwire Cyber Security & InfoSec Insights

About the Podcast

Razorwire Cyber Security & InfoSec Insights
Real conversations helping cybersecurity professionals sharpen their insights, strategy & leadership skills.
Cybersecurity is evolving — and so should you. Razorwire brings the open conversations that give you the edge.

Welcome to the Razorwire podcast — your resource for practical advice, expert insights, and real-world conversations on cybersecurity, information security (InfoSec), risk management, governance, security leadership, human factors, and industry trends.

Our mission is to help you build a stronger cybersecurity career while supporting a dynamic, agile community of professionals committed to continuous improvement.

Each episode brings you actionable advice and real experiences from your host, James Rees — an information security specialist with over 25 years of experience — and from a range of respected guests across the cybersecurity industry. Together, we explore everything from technical strategies and compliance challenges to security culture, communication skills, and leadership development.

James Rees is the founder of Razorthorn Security, providing expert consultancy and testing services to a wide range of organisations, including many Fortune 500 companies. His practical, no-nonsense approach helps organisations manage cybersecurity risks effectively while strengthening resilience.

The Razorwire podcast is designed for cybersecurity professionals who want to stay ahead, sharpen their skills, and confidently respond to the challenges of today's evolving threat landscape. We believe collaboration is key to stronger security — and Razorwire gives you the conversations that help you achieve it.

For more information about us, or if you have questions you'd like discussed on the show, email podcast@razorthorn.com or visit www.razorthorn.com.