Infoglobez
Live Coverage
Sign in Sign up
Trending: Champions League Transfer News Premier League World Cup
Infoglobez
AI & ML

Rethinking Corporate Security: The Need for Targeted Trust and Scrutiny

Security training has failed to combat phishing effectively; companies must reassess trust levels across processes to defend against modern threats.

Jun 24, 2026 | 3 min read
Sign in to save

Security awareness training aimed at combating phishing has long outlived its usefulness. While organizations have continued funding these programs and ticking compliance boxes, the reality remains: they don't work. The premise behind this initiative was straightforward: with adequate training, employees would be able to identify the telltale signs of phishing—misspellings, odd wording, and dubious sender domains. Essentially, staff were taught to play a variant of Where’s Waldo, searching for that one anomaly in their inboxes that might indicate a malicious message.

But this model is fundamentally flawed. Today's AI-generated attacks are sophisticated, often indistinguishable from legitimate communications. The once-reliable indicators we've conditioned users to look for have evaporated. Even if they existed, expecting individuals to maintain constant vigilance over hundreds of daily messages is an unrealistic demand. No human has the capacity for consistent, flawless attention in these fast-paced environments.

Applying Kahneman's Insights to Organizational Dynamics

Discussions about phishing often reference Daniel Kahneman’s concepts of System 1 and System 2 thinking, where quick, instinctual responses can easily be manipulated, while slower, deliberate thought processes are more reliable. However, applying this insight solely to individual behavior overlooks its broader implications for organizational strategy. The reality of cognitive processes does not translate effectively into a viable security framework.

Organizations naturally evolve processes that are either rapid or thorough, typically without intentional design. Fast processes often involve established relationships and minimal friction—think wire transfers between known entities or easy acceptance of calendar invitations. In contrast, slow processes entail a real-time establishment of trust, such as employee logins with variable access requirements or the onboarding of new vendors.

This dichotomy didn’t arise by choice; rather, it evolved as businesses sought efficiency. But as attackers become increasingly adept at exploiting these fast lanes, the security framework surrounding them must be re-evaluated.

The Nexus Pass Concept in Security Design

Consider how border control manages security: they employ risk-tiering to differentiate between vetted travelers and those undergoing full inspection. This method—where trust is continuously verified and can be revoked at any time—offers a valuable lesson for enterprises. It emphasizes the need to determine which interactions warrant expedited processing and what justifies that decision.

For companies, recognizing which processes have retained their fast-track status can unveil vulnerabilities. Think about instances where banking information changes via email or calendar invites are accepted without scrutiny. These represent fast lanes ripe for exploitation, largely because the criteria establishing their speed were never reassessed.

The solution isn't to slow everything down, as that would merely replicate the pitfalls of outdated security training. Instead, organizations need to be selective. Identify which fast paths are built on outdated, faulty criteria. Reassign these processes—determine which ones truly deserve the fast lane and which should be revisited.

Addressing the Trust Inversion

This leads to a critical reassessment of security architecture. For years, organizations applied stringent zero-trust protocols to employees while maintaining standing trust for suppliers, allowing for constantly validated access for employees but relegating suppliers to more lenient oversight. This disparity deserves scrutiny as it creates pathways for attackers who often target third-party vendors with valid credentials and long-term access to systems.

The flaw here lies in misguided reliance on SOC 2 compliance certificates, which measure an organization’s adherence to internal controls but fail to capture real-time security posture. Many organizations overly simplify their vendor assessments to a single compliance report that provides little insight into the current security landscape.

Automating compliance processes has further exacerbated the issue, transforming periodic checks into continuous assessments without evaluating the underlying data's relevance or reliability. As a result, outdated vendor credentials can coexist alongside seemingly pristine compliance reports, creating a false sense of security.

Implementing Deliberate Security Design

The path forward requires meticulous work, which will not yield immediate visual results. Begin by mapping out processes organization-wide, discerning which move quickly and which are more deliberate. For every fast pathway, it’s essential to ask three pivotal questions:

  • What evidence originally justified the speed?
  • Does that evidence still hold true in light of current threat capabilities?
  • If the fast lane is removed, does the cost of change outweigh the potential impact of a breach linked to that process?

When these evaluations reveal that the original justifications are no longer valid, it’s time to adjust. Adapting these fast pathways may lead to longer vendor update processes or require additional verification steps during onboarding—but the investment in time is worthwhile when weighing it against the risks posed by inaction.

Being prepared to accept that friction is necessary in certain areas shows maturity in security posture. It acknowledges that past efficiencies were predicated on assumptions that, in the current threat environment, no longer hold. By rigorously justifying which processes maintain expedited status, organizations can take meaningful steps to counteract rising phishing threats.

The essence of deliberate design lies not in hampering efficiency across the board but in making informed decisions regarding where it is warranted. As conditions shift and threat actors adapt, organizations must be ready to reevaluate previously established speeds and adapt their strategies accordingly.

This article is published as part of the Foundry Expert Contributor Network.
Want to join?

Source: William Martinez · www.csoonline.com
Sign in to join the discussion.