Signals Weekly Briefing

Week 33: Mind the Gap

10 August 2026 · 8 min read · Andy
← All Signals briefings

The CyBehave Weekly Briefing

Monday 10 August 2026 | Reading time: about 8 minutes

Good morning. This week's edition circles a single question: what happens in the space between knowing and doing? A peer-reviewed study puts fresh numbers on the awareness-behaviour gap, a benchmark of 14 million phishing simulations exposes how rarely people report what they spot, and the corridors of Black Hat were full of talk about social engineering that no longer bothers with the inbox. There is plenty here to be optimistic about, because every one of these findings points to something practical you can do. Let's get into it.

Awareness is not the finish line

We open with the academic highlight of the week. Writing in the Journal of Cybersecurity Education, Research and Practice, Ranylene and Ryan Olaybal surveyed 553 students, lecturers and administrative staff at a university in the Philippines to ask why strong phishing awareness so often fails to become secure behaviour. Awareness scores were high across every group. Behaviour was another matter, and the pattern is one many of you will recognise: administrative staff, the very people handling finance requests and personal records daily, showed the weakest security practices and the greatest susceptibility to phishing.

The finding that matters most sits quietly in the correlation tables. Actual security practices, not awareness levels, showed the strongest relationship with reduced susceptibility. In plain terms, people who do secure things are safer than people who know secure things. The authors propose a role-based framework (they call it C.A.R.E., for Cybersecurity Awareness, Reporting and Education) built around the risk profile of each group rather than a uniform campaign for everyone.

One study at a single institution, so treat it as a well-evidenced signal rather than the final word. It is, though, a rare peer-reviewed look at a gap most of us know from experience.

What does this mean for me? If your programme still reports awareness scores as its headline metric, this is your prompt to shift the dashboard towards observed behaviours: reporting rates, password manager adoption, MFA enrolment. And if your admin and finance teams get the same generic training as everyone else, the case for role-based interventions just got stronger.

Source: Closing the Phishing Awareness-Behavior Gap in Higher Ed, JCERP, 4 August 2026

Five clicks in a hundred, and hardly anyone says a word

Fortra's latest phishing simulation benchmark, drawn from more than 7,500 campaigns reaching 14 million recipients, landed in the education press this month with figures worth pinning to your wall. On convincing simulations, 5.42 per cent of recipients clicked and just under 2 per cent went on to submit credentials. Sobering, but not the headline. The headline is that only 10.5 per cent reported the message.

Read those numbers together and the story changes. For every person who clicks, roughly two people report; the rest see something suspicious, or half-see it, and simply move on with their day. Your click rate measures failure. Your report rate measures whether your people are actively defending you, and at one in ten there is enormous room to grow. Fortra's own framing is a good one: treat employees as part of the security perimeter, not simply as potential victims.

A caveat as ever with vendor benchmarks: this is Fortra's customer base, simulations vary in difficulty, and a benchmark is a mirror, not a target.

What does this mean for me? If reporting sits anywhere below your click rate, make it the metric you obsess over this quarter. Celebrate reporters visibly, thank them personally, and make the report button frictionless. A workforce that reports at 30 or 40 per cent gives your security team an early-warning network no tool can match.

Source: Report Emphasizes Importance of Building a Security Culture, THE Journal, 3 August 2026

Black Hat's message: social engineering has left the inbox

Las Vegas wrapped up another Black Hat week, and one of the sharper practitioner write-ups to emerge argues that the social engineering attack chain has quietly outgrown our defences for it. Attackers now run campaigns across email, lookalike domains, SMS, social media and messaging apps at once, hopping channels faster than siloed monitoring can follow. A lure might arrive by text, continue over WhatsApp and finish with a voice call that sounds convincingly like your CFO.

The piece comes from Doppel, a vendor with an obvious interest in this framing, so hold its statistics lightly. Its fourth lesson, however, deserves your attention regardless of who wrote it: human risk programmes built around annual videos and email-only simulations are testing people against an attack that no longer exists in that shape. If your people never practise against a smishing attempt, a voice clone or a fake login page on a lookalike domain, their first encounter will be a live one.

The encouraging read: none of this makes people the weak link. It makes realistic practice more valuable, because channel-hopping attacks still rely on a human deciding to comply.

What does this mean for me? Audit your simulation programme against your actual threat picture. If it is email-only, add SMS and voice scenarios this year, and teach one simple habit that works across every channel: verify unusual requests through a second, known-good route before acting.

Source: Checking Out of Black Hat: 4 Lessons on Defending the Modern Social Engineering Attack Chain, Security Boulevard, 7 August 2026

When the new starter is not a person at all

Here is one for anyone whose remit touches insider risk. Reporting in The Next Web pulls together a threat with a wonderful name and unpleasant implications: the synthetic insider. Rather than phishing their way in, attackers are using deepfake video and audio to pass job interviews, take up remote roles and walk in through the front door with a laptop and a login. The US Justice Department has already prosecuted North Korean operatives who used the stolen identities of more than 80 Americans to gain employment at over 100 companies.

There is an anthropological observation buried in here. Hiring is one of our oldest trust rituals, and it evolved for a world where seeing someone's face and hearing their voice was proof of personhood. That assumption has quietly expired. The piece offers pleasingly practical countermeasures, including one from SentinelOne's Tom Hegel: ask a video candidate to wave a hand across their face, which current live deepfakes still struggle to render. Worth keeping in perspective, too: Fortinet's research reminds us that most insider incidents remain accidental, born of error rather than malice.

What does this mean for me? This is a ready-made reason to build a relationship with your HR and recruitment colleagues, who are now on the security front line whether they know it or not. Offer them a short briefing on interview verification for remote roles. It is a genuinely new story to tell, and novelty is a gift in awareness work.

Source: The synthetic insider: AI deepfakes as fake employees, The Next Web, 20 July 2026

Culture is designed on paper and won in person

We close with a thoughtful essay from ASIS Security Management on why security culture is easy to design and hard to achieve. John Rodriguez's argument rests on a finding from neuroscience that should give every senior leader pause: research from the NeuroLeadership Institute suggests that power itself changes perception, shifting how executives see their people from concrete individuals towards abstract units of a system. The higher you rise, the harder it becomes to see the person behind the policy exception.

His remedy is refreshingly human. Culture programmes succeed when leaders are trusted, and trust is built the slow way, by saying what you will do and then doing it. He advises spending your effort on the sceptical executives first, listening without defensiveness, and treating credibility as your most valuable asset. None of this appears on a maturity model, which is rather the point.

What does this mean for me? Pick the one senior leader most sceptical of your programme and invest in that relationship this month, on their terms and their priorities. And look again at your own team's habits: every promise kept to the wider organisation is a deposit in the account your culture draws on.

Source: Security Culture: Why It's Easy to Design and Hard to Achieve, Security Management, 27 July 2026

Until next Monday

The thread running through this week is a hopeful one. People who practise realistic scenarios, report what they see and work for leaders they trust are not a vulnerability to be patched. They are the most adaptive part of your defence. Have a good week, and if one idea makes it from this page into your programme, let it be the reporting rate.

The CyBehave Weekly Briefing is researched and written for subscribers working in human risk management, security awareness and behaviour change. We link every source so you can go deeper, and we would love to hear what you thought.

Get Signals in your inbox

Subscribe and choose the Signals weekly briefing to receive each edition the morning it publishes.