Cyber Defense Magazine | Banking on Reporting: A Culture-First Defense Against AI-Powered Phishing

By Jeremy Herr, Senior Director of Security Operations, Abrigo
Today’s phishing attacks still succeed because they look familiar. They’ve followed the same basic play for decades: trick a person into trusting something they shouldn’t, then exploit human traits like trust, the desire to be helpful, and respect for authority while using urgency to get them to act. But while phishing hasn’t been reinvented, it has been industrialized and refined. Artificial intelligence (AI) enables cybercriminals to weaponize those same human traits with near-perfect language, deep context, and mass-scale personalization that can overwhelm human detection. As a result, attackers are succeeding with greater precision, increased AI use, and expanded delivery channels, even as overall phishing volume is flattening in some security data.
For decades, organizations have relied on signature-based prevention methods and employee education that emphasized withholding credentials, avoiding clicking links, and simply deleting or ignoring anything suspicious. That approach helped reduce some risky behaviors, but it also treated employee mistakes as failures. We socialized errors through reports, company-wide communications, or disciplinary measures, while those people who successfully reported phishing attempts received far less attention. Over time, this approach has established an environment that could discourage reporting suspicious activity for fear of “being wrong”. Many security professionals and practitioners, including me, were blind to this “culture of fear” we were unintentionally creating. Many of us still are.
That same mindset has influenced the primary method for measuring the effectiveness of a phishing awareness program. Historically, success has focused on who refrained from clicking a suspicious link or entering credentials, rather than on how often employees reported anything they perceived as suspicious. This approach produces overly optimistic metrics. An employee may read a phishing email and delete it without reporting it or forward it to coworkers with a warning instead of sending it to the security operations team for review. In each case, the platform may record a “success” because no one clicked, but it misses the more important signal: whether the organization can detect, escalate, and respond to threats quickly. Without measuring reporting behavior, these programs fail to capture employee judgment or the organization’s true readiness against phishing threats.
Humans play a different role now
We’ve all viewed humans as the “weakest link” in our organization’s defense in depth. Our mindset must change, especially at financial institutions, where customers and members trust that their money is safe. The simple adage “See something, Say Something” is more important today than ever before. At Abrigo, we are building a supportive security culture across our entire organization, shifting our mindset to perceive humans as a key layer in our detection methodology and championing those who report phishing attempts, vulnerable code, or other security issues. Employees can serve as early indicators that technical controls may have overlooked certain threats. We’re focusing our awareness training on continuously educating individuals to report potential phishing messages quickly to prevent additional users from being affected.
We no longer measure program effectiveness by focusing heavily on data showing the number of employees who didn’t enter their credentials when prompted during an exercise. At Abrigo, we recognize that this focus can have an inadvertent psychological effect on those who failed the test. If employees believe mistakes will be punished, they may be less likely to report promptly if they “get it wrong” with the next phishing email, whether the email is real or a test.
Employees should be treated as “human firewalls” or “early-warning signals,” not as the problem. Users are on the front lines of a financial institution‘s detection layer, and their observations can be a huge asset to its defense-in-depth design.
. . .
To see the full article, visit Cyber Defense Magazine, page 112 “Banking on Reporting: A Culture-First Defense Against AI-Powered Phishing.”