Social Engineering in the Age of AI: Rethinking Security Awareness Training @FIRSTdotorg
Social Engineering in the Age of AI: Rethinking Security Awareness Training  @FIRSTdotorg
Uploaded August 2025 | Updated September 2026, 28 minutes ago
Cornelia Puhze (SWITCH-CERT, CH)

Cornelia is a security awareness & communications expert at Switch-CERT, advocating for a human-centred approach to security. She supports various communities to become better security advocates and thereby empower people to improve their digital literacy and be safe online. Cornelia is educated to postgraduate level in corporate and political communications and has a background in teaching. Cornelia co-chairs the FIRST SIG Human Factors in Security.
--
In the age of AI, social engineering (SE) attacks have become more sophisticated than ever. AI-generated deepfakes and flawlessly crafted phishing emails make it impossible to rely on familiar cues like voice, images, or writing styles. Yet traditional security awareness training still focuses on teaching users to spot specific signs -- an approach that assumes rational, System 2 thinking. The reality? SE attacks succeed by exploiting emotional, reactive System 1 thinking, making existing training methods increasingly ineffective.This talk introduces a different type of approach. Instead of relying on rule-based detection, we focus on meta-level awareness: teaching users the adversarial mindset so they understand how they're being targeted and manipulated. Drawing on Cialdini's principles of influence and incorporating mindfulness techniques, this approach equips users to pause, recognize emotional triggers, and respond rationally. Attendees will leave with actionable insights to build a resilient, human-centred defence against SE attacks.
Social Engineering in the Age of AI: Rethinking Security Awareness TrainingBuilding the Blueprint: Designing Effective Storyboards for Cybersecurity Tabletop ExercisesThe Dependency Mirage: Hidden Vulnerabilities in Your Compiled BinariesTransforming Vulnerability Management with Advanced Dependency Knowledge GraphsA Researcher Centric Approach to Coordinated Vulnerability DisclosureHow to Answer “What’s Affected?” in Open SourceSysmon Deep Dive: Real Detection Scenarios You Can ReproduceThe PR3TACK Initiative: Building the World’s First Preemptive Tactics & Countermeasures KnowledgebasGuardians of the HypervisorBest Practices for Data Privacy Breach Response: Lessons Learned from Social Media Case StudiesThe Ontology for SOC Creation Assistance and Replication (OSCAR)Panel: Peak Performance Under Pressure: Building Cross-Functional Resilience in Incident Response
FIRST |

Social Engineering in the Age of AI: Rethinking Security Awareness Training

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER