Ripples · Champions Weekly Briefing

Week 34: Knowing Isn't Doing

17 August 2026 · 5 min read · Andy
← All Ripples editions

Week 34: Knowing Isn't Doing

17 August 2026 · 4 minute read

Hello Champions! This week's stories all circle one idea: knowing about scams is not the same as being ready for them. The good news is that readiness is built from small, practised habits, which is exactly what you are brilliant at spreading.

1. Scammers are using AI to write emails just for you

Researchers presented a big experiment this week at USENIX Security, one of the world's largest computer security research conferences. They sent test scam emails to around 7,700 people. Some got ordinary, generic scams. Others got emails written by AI, which had first searched the web for details about each person's job and company. The personalised ones fooled nearly three times as many people, and each cost the attackers only a few pence to make.

The old advice about spotting bad spelling matters less now, because AI writes fluently. What still gives a scam away is what it asks you to do: something unexpected, something urgent, or a request to pay, log in or share information in a new way.

Talking point: try this line with your team: "A scam email might mention your real job, your real projects and your real colleagues. What gives it away isn't how it looks, it's what it asks you to do." Ask everyone for one example of a request that should always make them pause.

Learn more

2. Knowing about scams doesn't automatically protect you

A new study published this month surveyed more than 550 people at a university, including students, lecturers and office staff. Nearly everyone knew plenty about phishing (fake emails designed to trick you). But knowing and doing turned out to be very different things. The people with the safest day-to-day habits were the hardest to fool, while knowledge alone made much less difference. And office staff, the people handling money and personal records, had the riskiest habits of all despite high awareness.

For Champions, this is quietly encouraging. The small habits you promote matter more than any amount of "did you know" content.

Try this activity: at your next team catch-up, skip the quiz and do a 60-second habit check instead. Ask everyone to name one security habit they actually did last week, like reporting a suspicious email or double-checking a payment request. Celebrate the doers, not the knowers.

Learn more

3. Hospital staff showed us how everyone really thinks about risk

Another study from the same conference asked doctors and nurses (a dozen interviews, plus a survey of around 300 across the US, UK and Canada) what security problems worried them most. The fascinating part: when computer systems fail, clinicians improvise to keep patients safe, for example by switching to paper notes. Sensible in the moment, but those workarounds create new gaps nobody is watching.

That is an everywhere story, not a hospital story. When systems are slow or broken, people in every workplace invent workarounds, like emailing files to personal accounts or sharing a login "just this once". They do it for good reasons, so the answer is never to shame them.

Talking point: ask your team, without judgement: "When our systems play up, what workarounds do we actually use?" You will learn a lot, and passing what you hear to your security team (kindly and anonymously) is one of the most valuable things a Champion can do.

Learn more

4. The UK's cyber agency says practice beats paperwork

The National Cyber Security Centre (the UK government's cyber security agency) recently published guidance on recovering when a cyber attack knocks out an organisation's systems. The striking message is about people, not technology. Recovery can take weeks or months, and the organisations that cope best are the ones that have practised, because practice builds the muscle memory people need under pressure. A plan sitting in a folder helps nobody if the people in it have never rehearsed their part.

Try this activity: run a five-minute "what would we do?" chat with your team. Pick one scenario, such as "our main system is down for three days". Who would we tell first? How would we keep working safely? What would we avoid doing? No wrong answers, the point is having thought about it once before it happens for real.

Learn more

5. Worries about AI are climbing fast, and that's a conversation starter

SANS, a large security training organisation, surveyed over 1,700 people who run security awareness programmes worldwide for its annual report, out later this month. The early headline: AI has jumped from fourth to second place on the list of people-related security risks in a single year. It is a survey of professional opinion rather than hard incident data, but it shows where attention is heading, and your colleagues are probably wondering about AI too.

Evidence you can use: "In a global survey of over 1,700 security professionals, AI jumped from fourth to second on the list of human security risks in one year." Use it to start a chat about your organisation's do's and don'ts for AI tools, and if nobody knows what they are, that is the perfect question to take to your security team.

Learn more


That's it for this week. None of these asks will take you more than ten minutes, and every one of them starts something: a habit noticed, a workaround surfaced, a question asked out loud. Drop your pebble in the water and see where the ripples reach.

See you next week, The CyBehave team

Get Ripples in your inbox

Subscribe and choose Ripples to receive each edition the morning it publishes.