Signals Weekly Briefing

Week 34: Knowing Isn't Doing

17 August 2026 · 9 min read · Andy
← All Signals briefings

The CyBehave Weekly Briefing

17 August 2026 · 9 minute read

If there is a thread running through this week's research, it is the stubborn distance between what people know and what they do. A field experiment presented at USENIX Security showed that AI-personalised phishing sails past people who would spot a generic lure. A new peer-reviewed study found high awareness sitting comfortably alongside weak practice. And the NCSC's latest guidance argues that organisations recover well not because they had a plan, but because they had rehearsed one. Awareness, it turns out, is the easy part.

AI-written spear phishing nearly triples click rates, at three cents a message

The headline finding of the week comes from USENIX Security 2026 in Baltimore, where researchers from TU Berlin, Inria and Ruhr University Bochum presented one of the largest field experiments yet on AI-enabled phishing. Working with around 7,700 participants, the team used large language models to gather publicly available information about each recipient through web searches, then generate a personalised spear phishing email. The result: personalised, LLM-written messages achieved almost triple the click rate of generic phishing, and that held regardless of whether the generic emails were written by humans or by AI. The cost of that personalisation was roughly three US cents per email.

The uncomfortable implication is that the economics of spear phishing have collapsed. Hand-crafted targeting used to be reserved for high-value victims because it took an attacker time and effort. Now the research-and-write loop is automated, cheap and scalable, which means the "mass but mediocre versus targeted but rare" trade-off that has quietly underpinned most awareness training is disappearing. This is a peer-reviewed academic study with a serious sample, though as ever a click in a study setting is a proxy; it measures susceptibility, not full compromise.

What does this mean for me? Audit your simulation programme against this finding. If your phishing simulations are still generic templates with spelling mistakes and implausible senders, you are rehearsing your workforce for an attack that is going away. Build simulations that use the same publicly available information an attacker's LLM would find: job titles, recent projects, suppliers, conference attendance. Then shift your teaching away from "spot the telltale error" towards cues that survive personalisation, chiefly unexpected requests, urgency, and anything that asks people to move money, credentials or data through a new channel. It is also a strong evidence base for a budget conversation: the paper's authors themselves argue that awareness training needs to incorporate personalised phishing.

Source: Czybik, Kouam, Heubl, Nold and Rieck, "A Large-Scale Study of Personalized Phishing using Large Language Models", peer-reviewed paper at USENIX Security 2026 (open access): usenix.org/conference/usenixsecurity26/presentation/czybik

High awareness, weak practice: fresh evidence for the gap we keep talking about

Published on 4 August in the Journal of Cybersecurity Education, Research and Practice, a study of 553 students, faculty and administrative staff at a private university in the Philippines put numbers on something most practitioners feel in their bones. Phishing awareness was very high across every group surveyed. Actual security practices were not, and they varied significantly by role, with administrative staff, the people handling finance, HR and student records, showing the weakest practices and the greatest susceptibility. Crucially, it was practice, not awareness, that showed the strongest relationship with reduced susceptibility.

The authors propose a role-based training framework that matches interventions to each group's behavioural risk profile rather than pushing the same content to everyone. It is a single-institution, cross-sectional study built on self-report, so treat the specific numbers lightly. The pattern, though, is consistent with a decade of research: knowing about phishing and resisting phishing are different capacities, and we mostly measure the first while hoping for the second.

What does this mean for me? Two practical prompts. First, look at how your programme's success is measured. If completion rates and quiz scores dominate your reporting, you are reporting awareness, and this study is a citable, peer-reviewed reason to move towards behavioural measures such as report rates, simulation performance by role, and password manager or MFA uptake. Second, take the role-based finding seriously. Administrative and operational staff often receive the same generic training as everyone else while sitting on the most attractive workflows an attacker could ask for. A short, targeted intervention for finance and HR teams will usually beat another all-staff module.

Source: Olaybal and Olaybal, "Closing the Awareness-Behavior Gap: A Role-Based Phishing Training Framework for Higher Education", peer-reviewed, Journal of Cybersecurity Education, Research and Practice (open access): digitalcommons.kennesaw.edu/jcerp/vol2026/iss1/26

What clinicians actually worry about (and why it should reshape how we engage them)

Also at USENIX Security this week, a Tufts University team presented a mixed-methods study of how clinicians perceive security failures, combining twelve in-depth interviews with a 303-person survey across the US, UK and Canada. The findings are a small masterclass in mental models. Clinicians see data breaches as the most likely threat, broadly matching where hospital security investment goes. But for attacks on data integrity, the quiet corruption of records, they were confident they would simply notice and ignore anomalous data. And when systems go down, they reach for analogue workarounds like paper charting, improvised responses that keep patients safe while opening new security gaps nobody is watching.

The behavioural lesson travels well beyond healthcare. People in any operational role assess security risk through the lens of their professional expertise, and they will always prioritise the mission over the control. Security that ignores how work actually gets done under pressure does not get followed; it gets worked around.

What does this mean for me? This is an argument for co-design. If your organisation has safety-critical or time-critical roles, whether that is clinicians, engineers, traders or warehouse teams, their perception of which security failures matter will differ sharply from your risk register, and the workarounds they invent during outages are a live part of your attack surface. Sit with those teams, map what they actually do when systems misbehave, and build guidance for the workaround rather than pretending it will not happen. The study's authors make the same point: bring frontline staff into the design of controls, not just the receiving end of them.

Source: Thompson, Khalid, Fisher, Votipka and Votipka, peer-reviewed paper at USENIX Security 2026 (open access): usenix.org/conference/usenixsecurity26/presentation/thompson-iii

The NCSC's recovery guidance is quietly a behaviour change document

Published in late July and worth your attention if you missed it over the holidays, the UK National Cyber Security Centre's guidance on highly disruptive cyber attacks, "What to do when cyber attacks disrupt your organisation", walks through immediate response, recovery and rebuild. It is aimed at boards and executives as much as security teams, and the striking thing for this audience is how much of it is about people rather than technology: establishing governance in the first hours, controlling communication, and accepting that recovery is measured in weeks or months, with consequences that extend well beyond IT.

The NCSC's framing in its accompanying commentary is explicitly behavioural: plans on paper are not enough, and realistic simulation exercises beat tabletop discussions because they build the muscle memory people need to perform under pressure. That is a government agency making the case that incident readiness is a trained behaviour, not a documented intention.

What does this mean for me? If exercising in your organisation means an annual tabletop with the same senior faces, this guidance is your lever for something more realistic and more inclusive. Push for exercises that involve the people who would actually field the pressure: service desk staff taking panicked calls, comms teams drafting holding statements, managers deciding whether to send staff home. Human risk teams have a natural seat at this table, because how people behave in the fog of an incident, who they tell, what they improvise, whether they feel safe reporting mistakes, is culture made visible.

Source: NCSC (UK government guidance, published 28 July 2026): ncsc.gov.uk/collection/what-to-do-when-cyber-attacks-disrupt-your-organisation

On the radar: SANS puts AI at number two on the human risk list

A short one to file under "coming soon". SANS releases its 2026 Security Awareness and Culture Report at the end of August, drawing on more than 1,700 security awareness practitioners worldwide, and the preview headline is that AI has jumped from fourth to second on the ranked list of human risks in a single year, earning a dedicated section of the report for the first time. The full findings, including benchmarks on programme maturity and team size, land with webcast registrants on 27 August, with a launch webcast on the 31st. It is a practitioner survey rather than incident data, and SANS sells training, so read the rankings as a map of professional concern rather than measured harm. Still, as a barometer of where our field's attention is going, it is hard to beat.

What does this mean for me? Worth registering now if benchmarking your programme against peers is on your autumn agenda, and worth noting the AI finding for any strategy conversations already in your diary.

Source: SANS Institute (vendor practitioner survey; report to webcast registrants from 27 August): sans.org/webcasts/sans-2026-security-awareness-culture-report


That's the week. The through-line is worth sitting with: attackers are automating the personal touch while our best evidence says knowledge alone does not protect anyone. The programmes that thrive in the next few years will be the ones that treat behaviour, practice and rehearsal as the product, and awareness as merely the ingredient. See you next Monday.

The CyBehave Weekly Briefing is researched and written for human risk, security awareness and security culture professionals. Forward it to a colleague who would find it useful.

Get Signals in your inbox

Subscribe and choose the Signals weekly briefing to receive each edition the morning it publishes.