AI & ML

Rethinking Security Process Speed: From Awareness Training to Strategic Vigilance

Security awareness training is failing against AI threats. Businesses must evaluate and adapt their operational processes to effectively mitigate risks.

Jun 24, 2026 3 min read
Sign in to save

Security awareness training has long been a staple of the defense against phishing attacks, but it's time to acknowledge that this approach is ineffective. The standard belief that educating employees to detect spelling errors, strange sender addresses, or dubious URLs can safeguard against threats no longer holds in the age of AI. The methods attackers use have evolved; they can now simulate legitimate correspondence with stunning accuracy, rendering the old indicators that users were trained to spot obsolete.

Once, employees were tasked with applying a ‘Where’s Waldo’ approach to phishing attempts, sifting through emails to identify anomalies. But the reality is that asking individuals to maintain heightened vigilance while navigating countless messages daily is impractical — any single lapse in attention could lead to a serious compromise. So, what’s the alternative?

Kahneman’s Insights for Organizational Practices

Discussions surrounding phishing often reference Daniel Kahneman’s concepts of 'System 1' and 'System 2' thinking, where fast thinking is prone to error and slow, deliberate thinking is more accurate. While this theory highlights cognitive processes, it falls short as a security strategy when applied only to individuals. The real opportunity lies in examining how organizations operate.

Organizations have processes that are categorized into fast and slow lanes. Fast processes operate under established trust, such as internal wire transfers and accepted calendar invites, while slow processes require real-time trust-building, including new vendor onboarding and external communications. Many companies did not intentionally design this split; it arose naturally as efficiencies were sought. However, as the threat landscape has changed, this speed vs. scrutiny gap has become problematic.

Clever attackers are adept at detecting where fast paths exist within organizational processes, utilizing these moments of reduced scrutiny to execute their attacks. Acknowledging this reality is the first step toward improved security.

The Nexus Pass Model: A Framework for Security

Drawing on border control's risk-tiering approach can guide security improvements within enterprises. Just as pre-vetted travelers at borders move through fast lanes based on verified trust, businesses must assess which internal processes deserve expediting based on robust evidence.

The fast lane isn’t a flaw, nor is a full inspection excessive; it’s about strategically determining which interactions justify speed and what supporting evidence affirms that decision. Applying this logic exposes glaring vulnerabilities: for instance, fast-tracking vendor changes via email or approving calendar invites without proper checks can easily be exploited by those who understand the processes were never re-evaluated.

The solution isn’t simply to slow down every process. That would mirror the deficiencies of ineffective awareness training and would hamper organizational productivity. Instead, targeted efforts are needed to identify outdated fast paths and adjust their status based on current threat realities.

Rethinking Trust in Supplier Relationships

This process redesign leads to broader questions about employee vs. supplier trust dynamics. A decade of zero trust principles has been applied to employees, who face constant authentication and device checks, while suppliers often gain long-term access after a simple SOC 2 report. This stark contrast reveals a systemic trust inversion that welcomes risk.

Suppliers frequently represent the easiest entry points for attackers, leveraging genuine credentials to navigate systems unchallenged. The historical dependency on SOC 2 reports, which gauge internal controls rather than real-time security, has become dangerously problematic. Many firms mistakenly assume a clean report equates to security, neglecting that lingering compromised credentials can create serious vulnerabilities.

Implementing Deliberate Security Design

Moving toward genuine security improvement isn’t glamorous and won’t be reflected in sleek dashboards. The path begins with meticulously mapping organizational processes to differentiate fast from slow. For each fast lane, ask: What evidence justified this process speed initially? Is that evidence still valid given today's sophisticated attacker capabilities? And if we were to remove this expedited path, would the cost to the business outweigh the risks posed by a breach?

When the original justification no longer stands, adjustments are necessary. The acceptance of these changes often requires slower vendor updates and additional verification processes. Yet, the necessity of this shift is rooted not in a theoretical embrace of caution, but in recognizing that previous efficiencies were based on now-outdated assumptions.

Engaging with these considerations is what it truly means to design for security. It’s not about structurally imposing speed constraints but rather about consciously managing where speed is warranted and where scrupulous examination is essential. By continually revisiting these decisions as conditions evolve and revoking fast lanes when justifications decay, organizations can better fortify themselves against emerging threats.

This article is published as part of the Foundry Expert Contributor Network.
Want to join?

Source: William Martinez · www.csoonline.com

Comments

Sign in to join the discussion.