Ripples · Champions Weekly Briefing

Week 35: The Second Look

24 August 2026 · 5 min read · Andy
← All Ripples editions

Monday 24 August 2026 · 4-minute read

Hello, and welcome to this week's Ripples. There's a comforting thread running through everything below. Hardly any of this week's news is about people needing to be cleverer. It's about how much easier things get when somebody takes a second look.


1. You can't trust a voice any more, and that's fine

Researchers asked 82 people who work in IT to listen to recordings and say whether each voice was a real human or a computer-generated copy. With older voice-cloning software they did well. With the newest software they got it right about half the time, which is the same as tossing a coin. When only one sentence in a recording had been swapped for a fake, they spotted it about 9 times in 100.

All of which stops being frightening the moment you stop relying on your ears.

Try this activity: In your next team meeting, spend five minutes agreeing one rule. Something like: "If anyone calls asking us to move money or change an account, we hang up and ring them back on the number we already have." Write it down where everyone can see it. It works whether the voice is fake or not.

Learn more: https://arxiv.org/abs/2608.19959 (A research paper on arXiv, a site where researchers share work before it reaches a journal.)

2. The security experts got targeted too

Every August, thousands of security professionals gather in Las Vegas for two big conferences, Black Hat and DEF CON. In the weeks afterwards a criminal went after one of those professionals, and a security company called Huntress wrote up exactly how it worked.

It began as a friendly chat on social media from someone pretending to be a marketing boss at a well-known company. Then came a shared document that asked for a password to unlock it. The password arrived, and it failed. That failure was the whole trick. A broken thing that needs fixing is a wonderful way to persuade someone to run a command or download a file they'd never normally touch. There was no bad spelling to notice, and no odd grammar either.

Talking point: Try this line with your team: "The warning sign these days isn't a typo. It's something that breaks and then asks you to fix it." Anything that won't open unless you paste in a command deserves a pause and a second opinion.

Learn more: https://www.huntress.com/blog/defcon-phishing-google-doc-malware

3. What the people who do this job are worried about

SANS is a long-established security training organisation, and each year it surveys people who run security awareness programmes about what worries them. More than 1,700 took part this year, and the results come out on Thursday.

One finding is already public: worries about AI have jumped from fourth place to second in a single year. This is what professionals believe rather than a measurement of every workplace, but when that many people shift their attention this fast, it's worth noticing.

Evidence you can use: If you've been trying to get your team or your manager to take AI-powered scams seriously, quote this: "More than 1,700 security awareness professionals were surveyed this year, and AI moved from fourth to second on their list of people-related risks in twelve months."

Learn more: https://www.sans.org/webcasts/sans-2026-security-awareness-culture-report

4. Almost nobody checks whether champions programmes work

A UK company called Layer 8 asked more than 100 organisations across the UK, Europe and the US about their security champions programmes. Only about 7 in every 100 are even trying to measure whether their champions are making a difference. Nearly half still track it on spreadsheets.

Organisations that do measure are much more likely to have champions who stay engaged for the long haul, and the biggest improvements in everyday habits don't show up until a programme has been running for three years or more. So if yours feels slow, it might simply be young. (Layer 8 sells services in this area, so treat the numbers as a steer rather than the final word.)

Try this activity: Pick one small, countable behaviour, such as reporting suspicious messages, and count how many times it happens this month. Next month, count again. Your champions then get to see their own progress, which is the bit that keeps volunteers going.

Learn more: https://layer8ltd.co.uk/impact-report-2026/

5. Changing the meetings changed everything

Researchers spent about fifteen months following the security champions at a company with more than 5,000 staff, where fortnightly meetings had gone flat.

So the shape changed. Champions joined smaller monthly groups, each built around a real project they owned. They also held one session agreeing what the group was for, and another talking honestly about what wasn't working. Motivation went up, the group felt more like a group, and the rest of the company started noticing them.

Evidence you can use: If your champions meetings feel like a chore, you have research behind a change. Giving champions a project to own beat asking them to attend an update, in a study that followed a 5,000-person company for over a year. That's a good thing to take to your programme lead.

Learn more: https://conf.researchr.org/details/fse-2026/fse-2026-industry-papers/14/Enabling-Security-Champions-With-Breakout-Action-Groups-BAGs-A-Longitudinal-Case- (Presented at a software engineering research conference in Montreal in July.)


Not one of those five needs a budget, a project plan or anyone's permission. A five-minute conversation about ringing people back, or one behaviour counted twice, is genuinely enough to start with.

That's rather the point of this newsletter. You take a second look, someone beside you starts doing the same, and before long it's just how your corner of the organisation works. Have a good week.

Get Ripples in your inbox

Subscribe and choose Ripples to receive each edition the morning it publishes.