For years, security training rested on one simple piece of advice: look for the mistakes. Missing diacritics, odd phrasing, “Dear customer” instead of your name, a logo that looks badly printed. If the email looks bad, it is phishing. The advice was good — as long as attackers wrote badly.
They no longer write badly. According to KnowBe4's 2025 report, 82.6% of phishing emails contain AI-generated content, and the estimates for 2026 also point towards the 80% threshold and beyond. The messages have impeccable grammar, a natural tone and — the genuinely new part — context: your colleagues' names, the real projects, the suppliers you actually work with.
This article is for managers who ticked off “security training” a year or two ago and believe the subject is closed. It is not. But the good news is that the answer does not mean more boring courses — it means a different kind of training.
What AI actually does for the attacker
The change is not just stylistic. Generative AI has automated the expensive part of the attack: the research. An automated system can gather in a few minutes everything public about your company — employee profiles on LinkedIn, pages on your website, press releases, published reports — and build from them a lure personalised for each recipient individually.
The result is that the “handcrafted” attack, once reserved for big targets, has become a mass-produced item. The email that arrives is no longer “Congratulations, you've won!” — it is a credible message from a real “supplier”, referring to a plausible order, signed with the name of a person who actually exists. Sometimes it is a natural continuation of a public conversation: a reply to one of the company's posts, an offer against a genuine request on your website.
And volume is no longer limited by the attacker's time. The same tool that writes one perfect message writes a thousand, each personalised differently.
Nor does it stop at email. The same tools feed WhatsApp messages “from the boss away on a business trip”, urgent requests by SMS and even calls with convincingly cloned voices. The channel changes, the mechanism stays: real context, time pressure and a request that breaks procedure. That is exactly why a defence built on process, not on instinct, works across all channels at once.
Why classic training no longer catches it
Three structural flaws, not execution flaws:
- It teaches surface signals. The classic list — mistakes, odd addresses, impersonal greetings — describes the phishing of a few years ago. The employee who applies it conscientiously will validate precisely the AI-generated messages, because they look impeccable.
- It is an event, not a habit. A one-hour annual course competes with the tens of thousands of emails received between two courses. Reflexes are not formed by presentations, but by repetition.
- It punishes late reporting instead of encouraging fast reporting. Where the employee who clicked is shamed, the next one who clicks will stay silent. And the difference between a minor incident and a serious one is almost always how fast someone finds out.
The essential shift: from text to process
If the text can no longer be told apart from a legitimate one, verification has to move onto something AI cannot fake: the process. The rules that work are few and rigid, precisely so they leave no room for interpretation under pressure:
- No change to a supplier's bank account without telephone confirmation on a number known beforehand — not the one in the email requesting the change.
- No new or unusual payment on the basis of an email alone, however senior it appears to come from. The urgency invoked is part of the attack, not an excuse to skip the rule.
- No passwords, codes or access details shared by email or phone, no matter who asks.
- Any odd request from a “colleague” is verified on a different channel from the one it arrived on.
Notice that none of the rules asks the employee to “detect” anything. It only asks them to follow a fixed route whenever money, passwords or data are involved. That is the whole secret: process holds where intuition gives way.
What training that keeps pace looks like
- Short and repeated, not long and annual: sessions of minutes, weeks apart, each on a single concrete scenario.
- With simulations at the level of the real attack: phishing tests written at the quality AI produces, personalised with public information about your company — not templates with deliberate mistakes that anyone catches.
- With a report button one click away, and with a visible response: whoever reports gets confirmation, not silence. What gets measured is not just how many clicked, but how many reported and how fast.
- With no culprits: the purpose of the simulations is training, not a leaderboard of shame.
Training remains the second layer, though, not the first. Email filtering, two-step authentication and limited access rights stop the bulk before it reaches people; if the company has nobody to administer them consistently, this is the kind of task that is naturally handed over through outsourcing your IT services. And for the specific questions — which filters, which policies, what can be done with the existing budget — a first reference point is the frequently asked questions about IT security.
A one-hour exercise for your company
Want a concrete feel for how exposed you are? Do this exercise with two or three people from your team:
- Spend 20 minutes gathering everything public about the company: website, LinkedIn, job adverts, press releases, news articles.
- Write, based on that information, the email an attacker would send: who it would come from, to whom, what it would ask for, what real context it would invoke.
- Put it on the table and ask yourselves honestly: who in the company would have caught it? Which rule would have stopped it, if the text itself is perfect?
If the answer to the last question is “none”, the exercise has done its job: you now know which rules are missing. And if unfamiliar terms come up along the way — spear phishing, BEC, social engineering — you will find them briefly explained in the glossary of IT terms.
The next step: pick one of the process rules above — the one about changing bank accounts is an excellent start — and turn it this week into an official rule, communicated in writing to the whole company. One rule that is followed beats ten that are written and forgotten. Neoxis, an IT services company founded in 2015 in Pitești, holds ISO 27001 certification and works with SMEs across Romania.