
Monday 24 August 2026 · 9-minute read
Something connects most of what crossed my desk this week, and it isn't AI, although AI is certainly in there. It's the quiet collapse of the first impression. A voice that sounds right, a friendly message from a plausible stranger, a programme everyone assumes is working: each one held up perfectly well until somebody looked twice. So this week is an argument for building the second look into the system, rather than hoping people will remember to take it on their own.
A preprint posted to arXiv on 20 August put 82 IT professionals in front of recordings and asked a simple question: real or synthetic? The team, led by Milan Šalko with colleagues including Anton Firc and Kamil Malinka, used voice synthesis tools from three different vintages (2019, 2022 and 2024) to see how human detection has held up as the technology has moved.
Against the older synthesisers, people did reasonably well, scoring an F1 of around 90 per cent. Against ElevenLabs, that fell to 48 per cent, which is roughly what you'd get by guessing. The more interesting result was partial spoofing, where a single sentence inside an otherwise genuine recording had been replaced. Accuracy there dropped to 9 per cent, and listeners classified synthetic content as genuine 77 per cent of the time. Buried in the findings is something that deserves more attention than it will get: listeners are increasingly mislabelling real speech as fake. The authors also note that humans and automated detectors fail in complementary ways, and that neither reliably pinpoints where a short manipulation sits inside a longer clip.
Worth saying plainly: this is a preprint, so it hasn't been through peer review yet, and 82 IT professionals is a small and unusually technical sample. The direction of travel is hard to argue with, though.
What does this mean for me? Retire any training content that teaches people to listen for the tells. Robotic cadence, odd breathing and flat intonation were real cues once, and teaching them now builds false confidence in a skill that no longer exists. Replace detection with procedure: a callback on a number the person already holds, an agreed challenge phrase for finance and access requests, out-of-band confirmation as a default rather than an escalation.
The trust erosion finding has an operational cost that most programmes haven't budgeted for. When people start disbelieving genuine calls, your service desk, your executive assistants and your payments team absorb the friction. Give them a fast, dignified way to verify so that scepticism doesn't turn into paralysis.
Source: Šalko et al., "Tracking the Trend in How Speech Synthesizers Deceive People", arXiv preprint, 20 August 2026. https://arxiv.org/abs/2608.19959
Huntress published an account on 19 August of one of its own researchers being worked over by a social engineering operation running in the aftermath of Black Hat and DEF CON.
The pretext was mundane and therefore excellent. A fake X account impersonating CoinDesk's VP of Marketing opened a conversation about organising an online conference and asked which events the researcher planned to attend next. Then came a Google Doc dressed as a conference planning document, which rendered a custom sidebar asking for a decryption key. The key, helpfully supplied by direct message, failed on purpose. That failure was the whole mechanism: a broken thing that needed fixing, nudging the target towards either ClickFix-style terminal commands or a manual download. When the researcher didn't bite, the actor came back with a second document posing as a Dropbox DocSend link, serving a counterfeit installer complete with genuine Dropbox marketing copy and a convincing onboarding carousel while it quietly pulled down three malicious components in the background. Payloads across the chain included the AMOS infostealer, NetSupport RAT, a Ledger wallet implant and a traffic-intercepting proxy, some of it signed with stolen certificates.
What does this mean for me? The failure mode on offer here was never credulity. It was context. The target had just come back from those conferences, so a stranger wanting to talk about organising another one was exactly what the calendar predicted. That's the uncomfortable lesson for anyone who still frames susceptibility as a knowledge problem.
Two things are directly actionable. First, treat the fortnight after any major industry event as a predictable spike and time a light-touch nudge to land in it, for your security team as much as anyone. Second, name the broken-thing pattern explicitly in your content. Friction that steers you towards pasting a command or downloading a fixer is now a far more reliable signal than spelling or grammar, and almost nobody teaches it.
If your own security function quietly considers itself out of scope for awareness activity, this is your evidence that it isn't. Note that this is a single documented case from a vendor's research team, so read it as a detailed field report rather than a base rate.
Source: Huntress, "Post-DEF CON Phishing Uses Malicious Google Doc to Deliver Malware", 19 August 2026. https://www.huntress.com/blog/defcon-phishing-google-doc-malware
The eleventh SANS Security Awareness and Culture Report reaches registrants on Thursday 27 August, drawn from more than 1,700 awareness practitioners worldwide, with Lance Spitzner and Rachael Saffer unpacking the data in a webcast on 31 August. SANS has trailed one finding ahead of publication: AI has climbed from fourth to second on the human risk list in a single year, and gets its own dedicated section for the first time in the report's eleven-year run.
The accompanying summit runs on 27 and 28 August, and the programme is a reasonable proxy for where the field's attention has moved. Elodie Bridoux is speaking on why environment design drives human cyber risk rather than awareness. Jessica Barker has a session titled "You Can't Spot What Looks Real". Pooyan Hamidi is presenting seven micro-interventions as an alternative to training people. Ashley Savageau and Harley Sugarman are describing what happened at Postman when they started treating employees as adults, and Oz Alashe is talking about SebDB maturing into a behavioural ontology. Liz Gore has the session that half the readership will relate to most, on building security culture when you are the entire department.
What does this mean for me? This is your benchmarking document for the next planning cycle, so get on the distribution list or the webcast. Be honest about what it is, though: a self-selecting sample of people who already work in awareness, which tells you what the profession believes rather than what is objectively true across all organisations. That's still valuable, and it's how you should cite it.
The signal worth carrying into your own strategy is the convergence on the agenda. Several of the headline sessions are arriving at the same conclusion as the synthetic speech research above, which is that human detection is a losing bet and environment design is where the leverage sits.
Source: SANS Institute, 2026 Security Awareness and Culture Report and Summit. https://www.sans.org/webcasts/sans-2026-security-awareness-culture-report and https://www.sans.org/cyber-security-training-events/security-awareness-summit-2026
Layer 8 has published what it describes as the first global research study into how security champions programmes reduce risk, based on responses and interviews with more than 100 organisations across the UK, Europe and the US, across sectors.
The number that should stop you is this: only 7 per cent of organisations are even attempting to measure the direct impact of champions on risk reduction. Nearly half (48 per cent) are still running impact measurement on spreadsheets, and 21 per cent say they are unsure about long-term return on investment, with lack of time cited as the main barrier to setting a programme up properly. Of those that do measure, 74 per cent report higher long-term champion engagement. The most striking finding for anyone defending a budget is that the biggest growth in secure behaviour adoption arrives after three years or more.
This is vendor research from a firm that sells champions programme services, and the engagement figure is correlational rather than causal. Neither of those things makes it useless, but do quote it as what it is.
What does this mean for me? The three-year finding is the most useful line you'll get all week for a funding conversation. It reframes a champions network from a campaign into an operating capability, and it gives you a defensible reason to resist annual pressure to show transformation in six months.
The measurement and engagement link is worth acting on for a reason that has nothing to do with reporting. Measuring gives champions feedback, and feedback is what sustains volunteers who are doing this on top of a day job. Pick two or three behaviours that map to your actual top risks, baseline them this quarter, and show the champions their own numbers.
Source: Layer 8, Champions Impact Report 2026. https://layer8ltd.co.uk/impact-report-2026/
A longitudinal case study presented at the 34th ACM International Conference on the Foundations of Software Engineering in Montreal in July offers a rare thing: 64 weeks of tracked change inside a single organisation's champions programme. Jens Christian Opdenbusch, Sangavi Shanthakumar, Martina Angela Sasse and Marco Gutfleisch worked with a company of more than 5,000 employees whose fortnightly champion meetings had gone stale.
The intervention was structural rather than motivational. Fortnightly status meetings were replaced with monthly breakout action groups, each organised around a project the champions actually owned, supported by secure coding workshops, retrospectives and a vision workshop. Engagement and motivation improved. The vision workshop and the retrospective built group cohesion, aligned champions around a shared mission, and raised the programme's visibility across the organisation.
It's one company and an industry-track paper, so treat it as a well-documented natural experiment rather than a controlled trial. Sasse on the author list is a reasonable signal of methodological care.
What does this mean for me? The cheapest intervention in this week's briefing is a calendar redesign. A recurring status meeting asks volunteers to attend something. A project group gives them something to own, and ownership is what turns a name on a list into an actual champion.
The retrospective is the underused piece. Champions are rarely asked what isn't working, partly because programme leads are nervous about the answer, and that silence is exactly where enthusiasm goes to die.
Source: Opdenbusch, Shanthakumar, Sasse and Gutfleisch, "Enabling Security Champions With Breakout Action Groups (BAGs)", FSE 2026 Industry Papers, July 2026. https://conf.researchr.org/details/fse-2026/fse-2026-industry-papers/14/Enabling-Security-Champions-With-Breakout-Action-Groups-BAGs-A-Longitudinal-Case-
If there's one thing to take into the week, it's that every item here rewards the same move. Ask what happens on the second look, whether that's a callback on a voice you recognise, a colleague's eyes on a message that feels slightly off, or an honest look at whether your own programme is doing what you believe it's doing.
See you next Monday.
Subscribe and choose the Signals weekly briefing to receive each edition the morning it publishes.