I’m a cognitive security independent researcher which means I spend most of my time researching how corporate workers fall for phishing attacks through their emotions and how CISOs can use that insight to reduce breaches.

A few days ago, I surveyed r/CISO from April 2013 to the present to discover which problem chief security officers rated as their most challenging. For most executives, it was superficial compliance. Employees do all the obligatory workshops, games, simulations - and still fall for phishing attempts. Indeed, Cybsafe

Why do employees pass security training—and still fall for bait?

To cite psychologists

What is needed is to somehow flip the sequence: have detached System 2 inspect the email for phishing bait before emotion-driven System 1 kicks in.

How do we do that?

Neuroscientists link System 1 to the brain's emotional center (the amygdala), and System 2 to the logic-processing prefrontal cortex (PFC) - the part of the brain that memorizes security rules

Studies

Could focusing on just the raw data neutralize phishing threats?

I hired 24 individuals from Reddit, vetted them to ensure they worked for businesses and handled heavy email loads, then ran them through 30-minute Google Meet training sessions. I trained the control group—12 people—on common social engineering tactics like phishing. I trained the experimental group—12 others—on the same tactics, plus my method for analyzing emails objectively, using the two examples below

Example 1: The Phishing Lure

  • Hacker’s emotional bait:Anxiety or curiosity (- what are those emails!)
  • Deconstruction (focusing on neutral facts):

  • Name it:

  • Frame it:The message claims 6 emails were withheld and requests a click to recover them")
  • Check it:
    Example 2: The Bait

  • Hacker’s emotional bait:Greed (- Gimme that iPhone!)

  • Deconstruction (focusing on neutral facts):

  • Name it:- Scan QR code

  • Frame it:- The message claims a reward is available for an iPhone15 and requests a scan to claim it”)
  • Check it:

Participants who responded received an automated email debriefing them that the message was our pre-agreed phishing test.

** Results:** Six people from the control group fell for the lure, while only one person from the experiment group responded to my phishing simulation.

“Name it, Frame it, Check it”

When I discussed this rough experiment with my CISO connections, two of them suggested using my model to invert the standard approach.

In other words, instead of endeavoring to memorize all the rules, employees simply focus on only one thing: Look for the command (What does Sender want me to do?) The brain is now in analytical mode. It’s shifted from heady emotion to focused analytical processing - from emotion-driven System 1 to reality-monitoring System 2.

Released from emotion, workers can now "stand back”, summarize the message in third-person language (further reinforcing the neural loop of objective analysis) and, if uncertain, contact their supervisor.

For example, here’s what Nilesh told me he did when he received my test:

  • Name it:- Send Sender a screenshot of his Reddit account).
  • Frame it:- Email told recipient to provide Sender a screenshot of his Reddit account for possible).- compensation
  • Check it:

Conclusion

As threats become more convincing through sophisticated AI, we face two problems:

First, how to persuade employees to remember the admittedly boring security rules when it matters most. Second, how to prevent employees from falling for emotion-driven bait.

To help employees prevail, we use a three-step approach:

  • Name it-
  • Frame it-
  • Check it-

With our analytical brain now in charge, employees are more likely to make the right decision.