Welcome to the KuppingerCole Analysts Chat. I'm Matthias, I'm your host.
And today, don't go away, we're diving into one of the most critical challenges that CISOs face in 2025 and beyond, detecting deception. With me is Jonathan Care, our leading expert on security leadership and threat detection and telling CISOs what to do.
Jonathan, the sophistication of deceptive attacks has exploded recently. And what's behind that? What's driving that change?
Hi, well, thanks for having me, Matthias. And you're absolutely right. What we're seeing is a perfect storm of AI capabilities, social media intelligence, and psychological manipulation techniques. And what we're seeing is that threat actors are no longer just sending generic phishing emails. We all know how to figure those out now. They're crafting highly personalized attacks using AI to analyze social media profiles in depth and en masse. This allows them to generate convincing deepfake videos, emails, and even voice synthesis for phone-based attacks.
So frankly, the traditional security awareness training that we all relied on two years, five years ago, is obsolete. Well that's sobering reality check, but maybe that can keep me from having to do our next awareness training, which is still on my list to do. But before we dive deeper, you're the analyst. You're a very structured person. Can you give the listeners a kind of a framework, a taxonomy for thinking about deception? What's included? What's in there about deception and cybersecurity?
So, absolutely. And I think we can think about deception access across four main categories.
Firstly, there's social engineering and human manipulation. And that's the classic, but of course now enhanced by AI approach that we all have plenty of experience with.
Secondly, we're seeing digital identity deception. And this is where our attackers are using deepfakes and synthetic personas.
Thirdly, we're seeing vendor and supply chain impersonation, which means they're attacking through our trusted partners. And fourthly, of course, technical deception, where attackers fool security systems controls using adversarial AI. And each of these requires a different detection strategies. Right. And as I'm taking notes and I understood your four dimensions of how to categorize a deception, let's start with the first one that you've mentioned.
So, social engineering. Let's start with that. And this is the part where most organizations already have some existing defense. I just mentioned the awareness training that we do. That's mainly about social engineering. But how has AI changed the game then?
Well, I think the change is dramatic. Traditional social engineering that we all know and love and that you and I did in our younger days relied on generic scripts and broad psychological triggers.
So, we weren't looking to profile people. We didn't have the capability, frankly, as social engineering testers.
Now, of course, attackers are more sophisticated. They can and do analyze our LinkedIn posts, Twitter interactions, and other public data that we create to make incredibly convincing personas. And I've seen cases where attackers generated personal emails referencing specific projects, names of colleagues and family and friends, and even writing styles that match the supposed sender perfectly. This makes detection, especially for the layman, even impossible.
So, decision makers, CISOs, what can they do about that? As with so many things nowadays, it comes back to identity. The key is moving beyond relying on people to spot deception. And we need to build verification systems instead. For example, mandatory callback procedures for any sensitive transaction or system change request to bring it out of the IT domain into a business process. If someone claims to be your CFO and is asking for an urgent wire transfer, you call back on a known number. This sounds simple, but it is incredibly effective at stopping attackers.
There are other things you can do, of course, as well. You can do a micro deposit into your supplier's bank account. But we'll talk more about that later on. Right. But this requires that people just actually change their behavior, their processes, though they have to learn that. It has to be mandatory. Can technology support before we make them change their behavior? Are there tools that can help?
Well, no, it doesn't have to be mandatory. You can live with the increased rate of fraud. Sure. Fraud is always a matter of business risk. And if you can live with it, then that's up to you as an organization. But if you are deciding to do things about it, of course, there are technical tools that can help. And one of the things that I think is crucial is behavioral analytics. So knowing how your users normally behave, what time they log in, what system they access, and how they navigate applications is crucial at detecting deception.
When someone's account is compromised, the behavior patterns change because that person has either either the account is being operated by a different person or that person could be operating under some sort of coercion. And modern behavioral analytics solutions can catch those anomalies.
Of course, we all have already been the victim of such attacks, not really victims, but have been attacked like this. And I have received messages that claim to be by Berthold, our CEO, and they really did not sound like him. And so are there conversation analysis tools that can make this step for me already? I think so. And we're already seeing tools that can analyze language patterns. As you said, you said that didn't sound like Berthold, our CEO. But we can analyze the language patterns in emails and messages using technology tools.
We don't have to rely on the human firewall, as it's called. We can identify social engineering indicators and some obvious triggers.
Again, I'm still in the realm of general psychological triggers here. Artificial urgency, authority claims, or emotional manipulation. And as I say, these are still generic psychological triggers, and they're obviously ones that are specific to us as individuals, specific to you, specific to me. This isn't perfect, but if we can flag an email saying this email is suspicious, treat it with care, that helps our humans, our colleagues, to be able to say, okay, let me really take a suspicious look at this. Right. And in the title of this episode, also, we have this notion of advice to leadership.
So before we close down this first section about social engineering, what could be practical advice for CISOs who want to start improving towards what you just described immediately before buying a tool? What can they do? All right.
Well, three things you can do this week. First, CISOs, implement callback verification for any requests involving money, data access, or system changes. Those are the three things that criminals like and go for.
Second, establish challenge questions, information that only legitimate contacts would know. I'm not a fan of shared secrets as a ongoing verification method, but as a firefighting mechanism, until we put more sophisticated tools in, they are adequate.
Thirdly, create safe reporting mechanisms. You have to allow the culture to say, hey, I'm reporting this suspicious communication, without fear of blame or reprisal. Because if people don't feel safe to report suspicious communications, they will not do so, and thus the problem continues.
Yeah, better safe than sorry. That is, I think, really also an important part at that point to say, okay, maybe one more test rather than one too little. I think that's an issue.
Okay, that's the first part of the taxonomy that you mentioned. Second, of course, we are an identity company, most importantly. So digital identity and deepfake threats. I think that's the digital identity deception part. And deepfakes are in the news everywhere. Everybody's talking about it. We are doing it ourselves. But how real is the threat for organizations today? Is this really around the corner or already there? It's very real, and it's happening now. We've got many documented cases of attackers using AI-generated voices to impersonate executives on phone calls.
And again, requesting phone transfers, requesting sensitive information. Video deepfakes are still more challenging to create in real time, but they're being used in recorded messages and even some video calls. And let me give you an example now, which is much in the news, in fact, in the UK. The UK government is debating the right to die or assisted dying bill. And as you can imagine, things are high on both sides.
But of course, this process is exacerbated and maybe more challenging if you throw in the thought of what happens if you have deepfake coming into that scenario, which is already challenging and emotive right now. Right. So this is a controversial topic, and that can be difficult.
But again, from a protection perspective, how can organizations detect these synthetic media attacks? How can they deal with that?
Well, there are several layers of defense. And the good news is that technical detection tools are improving rapidly. There are now solutions that can analyze video and audio in real time to identify synthetic content. They look for subtle artifacts that AI generation creates, things like inconsistent lighting, unnatural eye movements, or audio-visual synchronization issues. Right. But I think this is just a game of cat and mouse. This technology arms race means that these tools will not detect everything. Sometimes the attacker is faster, sometimes the technology is faster.
What to do when this does not work? Well, I've got a very eminent colleague, John Talbot, our eminent colleague John Talbot, was recently talking about threat fraud detection processes and fraud response and interception. And what John and I talked about here is that process-based defenses are crucial. Technology tools only underpin a robust process. So for high-stakes communications, establish out-of-band verification. If the CEO suddenly joins a video call asking for something tentative, it's okay to send them a text or call their assistant to confirm.
This is okay because it breaks the attack chain. Even if the deepfake is perfect, you're asking for a verification that the attacker cannot provide. Right. We've talked about the overall tool category market segments of identity verification in this podcast, together with Annie, together with other colleagues. Can that help in that case as well? How do you verify on the fly, as you've mentioned, someone just joining the call, that they are who they claim to be in our digital world where things take just half a second to join a call?
I'm a fan of what the various vendors have done with digital presence and genuine, what do they call it, genuine persona verification. But what we actually need now is to move to multi-modal biometrics. Instead of just relying on a password or a face, we need to verify everything we can. Typing patterns, voice characteristics, and behavioral traits. And the idea is, of course, that attackers might fool one factor. If we ask them to fool a number of factors, all working in combination, it's going to be much harder to replicate someone's digital behavior.
Much harder to fake that complete signature. I think most people cannot already imagine how that really works. What are the technologies that CISOs should be watching to understand?
Yes, this is a thing. They understand how Matthias moves, how Matthias uses his hands, how he's typing, how he uses his touchpad. This is really important, because it can help in identifying what are technologies out there.
Well, you've hit on it. And behavioral biometrics is huge and is the key here. Because my belief is that these systems, well, my research tells me, these systems that learn how we interact with our devices are incredibly valuable sources of identity information. Your typing rhythm is unique to you. You and I type on our keyboards in different ways. The way you move your mouse is unique to you, as is the way I move my mouse is unique to me. And even how you hold your phone, how you brush the glass is all unique.
And all of this, of course, in the words of zero trust, these are continuous authentication mechanisms that are very hard to fake. So once you've established an identity at time of assertion, at login, then the continuous authentication says the behavior has not changed. It is still the same human agent that asserted the identity. And of course, the converse of that, if you see a swerve in behavior, say a sudden change, that's an indication of some kind of takeover, some kind of coercion. So it's very hard to fake.
The other thing to look at, and blockchain, for all its faults, is surprisingly useful at providing continuous verification or providing verification for critical communications. We are seeing financial organizations, even some governments, are using blockchains to make publicly validatable assertions for critical communications.
Because, of course, the one thing we do know about the blockchain is it does create an immutable proof of the, in this case, communication authenticity. That would be the thing you compare with. So that would be the normal, the actual, yeah, what you compare with.
But again, like we did it before, what are practical first steps to give guidance to CISOs, to organizations who are worried about deepfakes? Well, unusually, because we normally say start with low risk. Actually here, I think you should start with your highest risk scenarios, the ones that really keep the exec management group and the board awake at night. Identify the communications that could cause the most damage if compromised, usually involving executives, financial transactions, or sensitive data access, and then establish verification protocols specifically for those scenarios.
It's not necessary to verify every email. I don't need to verify an email and say, hey, I'm going to be in Wiesbaden. Do you want to come out for lunch? But every request that has a significant potential adverse business impact that could cost millions should be verified. Understood and fully agree. Let's move over to your third category. And if I remember correctly, that was vendor and supply chain deception. And that is something which I always mentioned that in that context is also in the focus of NIST 2, of DORA. So supply chain security is important, and obviously for a good reason.
This seems like it would be harder for attackers to pull off, but potentially more damaging. How can that look like? How do I pretend to be a supplier or a vendor that I'm not?
Well, there are simple ways, of course. And we are seeing that in a supply chain, there are perhaps some small organizations that are important components of a supply chain, which have nevertheless poor security. And so you find that their Office 365 tenant has been compromised, something similar.
However, if we're looking at pure deception, then it's true, the barrier to entry is higher. Attackers need to do more research and more setup, but the payoff is enormous. And I've seen single incident losses of 1.8 million euros is one that comes to mind. Threat actors can create entirely fraudulent companies, complete with websites, complete with LinkedIn profiles, and even fake references, just to allow them to win contracts, gain access into some kind of network. And we need to be on our guard against these sophisticated, organized threat actors.
And the amount of money that you just mentioned justifies quite some level of sophistication of these attacks. So how sophisticated are these fake vendor operations?
I think, I admit to a certain grudging respect, they are incredibly sophisticated. Attackers register a similar domain to a legitimate vendor. Sometimes they use Unicode lookalikes. They'll create professional looking websites. And even we've had fake employees with detailed social media histories. I've seen cases where banks, and the case in mind is a bank in the Middle East.
So yes, for example, their domain name was bankofthemiddleeast.com. And that's not the correct domain name, obviously, but it was a very similar one. And when I was doing a penetration test, I inadvertently looked at middleeastbank.com, which was an incredibly plausible facsimile of the correct website, but actually was a fake.
So again, these serious and organized organizations will spend months building credibility, will spend months creating a fake paper trail. And then of course, they'll make their move. But that's mainly for onboarding a new partner, a new vendor, a new member of the supply chain. But what you say is the traditional vendor due diligence isn't enough anymore. So there needs to be more. I think so. And I think you're absolutely spot on. Standard due diligence is just the starting point.
And I suspect in the same way that we've been talking for years about Know Your Customer, KYC, we actually now need Know Your Business Supplier and Know Your Business as well. We need enhanced verification protocols, which means verifying business registrations and with government databases, checking financial records through multiple sources, and most importantly, establishing secure communication channels.
And again, controlled and protected by strong cryptography. And that brings me back to one episode that I just did with our colleague, John Tolbert, where I talked about what I think is really essential. Also adding organizational identity to our identity management and to understand that there's a verifiable organizational identity and verifiable means, as you said, through cryptography with certificates that prove with a good trust anchor that this organization is the organization that it claims to be. How about existing vendor relationships? I already have a contract.
How do you protect against impersonation there? You won't do the due diligence for every interaction with them.
Well, first of all, monitoring for domain spoofing and lookalike communications, that should be part of your vendor supplier monitoring process. It is automatable, so we're not putting an extra load on our procurement colleagues, but there are tools that they can and should deploy to do that.
As I said, attackers register domains that are one letter off from legitimate vendors. They register domains with Unicode. They register domains with all the things that we have seen. And of course, they hope that recipients don't notice. Any good email solution nowadays will detect these domain similarities and then flag them all automatically. So there are a host of domain security solutions from Poofpoint, Agari, ValueMail, to name but three that will of course sit in front of your email server or indeed your cloud email tenant and provide that protection.
You've mentioned that briefly, but I think we should not let the human element or the vendor relationship procurement off the hook. There is a training part for that as well, right?
So, I know how overworked procurement and vendor management teams are, and I'm trying not to make their jobs more difficult, but they must, must, must verify changes to payment details, contracts or processes through independent channels. On the other side, I do tell that suppliers, you need to put in big red letters. We will not send you an email saying, hey, your payment details have changed. We will contact you. It will be from a person you know and recognize in order for a change of that name. It should be on every, something like that should be on every invoice.
Because if you suddenly get a communication out of the blue, hey, it's Bob, I'm your friendly account manager, or hey, I'm the new account manager I've taken over from Sue. And I just needed to, we need to change the bank details. And that needs to trigger a verification protocol. And please, not just an email confirmation. I saw a case where a large garment manufacturer has a supply chain, obviously to supply their garments that they make. And they had an email saying, hey, our bank details have changed. And they sent an email back saying, are you sure?
Are you sure you're not just hacking the suppliers? Ha, ha, ha. Came back the email.
No, it's okay. Ha, ha, ha. From the email address that they were expecting. And of course, what had happened is the attackers had compromised in that case, Office 365 email tenant of the supplier. So they were able to extract 500,000, I think it was, which in itself was not significant given the size of this particular garment manufacturer.
However, it did make it onto their financial reports because the auditors are saying there was nothing stopping this from being a loss in the millions. So, but until now, we mainly talked about communication, about interacting with an onboarding vendor, a partner. How about the technology that's already in your organization? Our supply chains are much more complex. There are systems that we are using provided by others. So how about supply chain integrity monitoring? How about understanding what's going on in these systems?
Well, absolutely. Yeah, we are, you know, Matthias, you and I, we are technologists. And so this is where our job comes into play. This is where technology and our job as technologists becomes crucial. We need to deploy tools that monitor for unexpected changes in software packages. If part of your software supply chain suddenly updates itself and looks very different, then that's a red flag that needs to be investigated.
If all of a sudden your API gateway is seeing unusual messages from part of your software infrastructure, if your microservice starts going macro, let's put it that way, then that's a big red flag that needs to be investigated. If your vendor provided system suddenly exhibits unusual network communications, if it's no longer phoning home, but it's phoning somewhere else on the Internet, that's a red flag that should be investigated. Any anomaly in our supply chain, in our software supply chain logistics needs to be investigated. And SolarWinds taught us that. And Log4j taught us that.
We need continuous monitoring of everything that enters our environment. I loved your approach, what should happen in the next two weeks? What should happen in the next two weeks for improving vendor deception detection?
Again, so we can establish secure vendor communication channels. We can use mutual authentication. We don't need to rely solely upon email for sensitive, high impact vendor communications. We can use platforms that provide cryptographic verification or sender identity and message integrity.
Of course, this is an investment, but it does pay off when you avoid a major supply chain compromise. Really good, good advice. Final category, technical deception, where attackers try to fool our security systems themselves. Sounds a bit like, yeah, future science fiction, but also this is as well happening right now, right? It's very real.
And yes, it does sound like something out of a William Gibson novel. I'm a big fan of Neuromancer and that whole cyberpunk genre.
But yeah, this is the world we're living in, folks. We are seeing attackers using adversarial machine learning to create inputs designed to fool security tools. They're crafting emails that bypass fan filters. They're creating network traffic that flies under the radar and evades intrusion detection or generating malware that fools AI-based endpoint protection. And in all these cases, it's working out what the normal is and working out how you make yourself look normal. Right.
So when you say it's flying under the radar, how can security teams defend against that, adjust their radar so that they identify these attacks that are actually designed to fool their own tools? Just as I talked about multimodal identification, here the same key applies. It's ensemble-based detection. So instead of a single AI model or a single detection method, we need to use multiple different approaches.
So an adversarial input might fool a network-based system, but it's much harder to fool one that looks at data repository access or application access or looks at the authentication process access. It's hard to fool different detection methods simultaneously.
And again, an aberrance in behavior is a red flag. Maybe one additional thought. Before these adversaries attack our critical systems or our rescue systems, could we not just make them attack something that we just put in there for them to attack them? And so honey, tokens, deception technology, is this something where we can keep them at arm length away? I've always liked deception technology. I think it's a very clever idea. It's turning the tables on the attackers.
We plant fake credentials, decoy files that nobody would have any reason to access, and in fact, just dummy systems throughout the environment. When someone attacks with those, you know, it is by definition unauthorized access, whether it's an internal source or an external source. There are no false positives. If someone accesses a file or a system or user credentials that they have no right to use, it's a red flag and you should investigate it.
And normally, I am cautious about insider risk management tools, because of course, we run the risk of damaging corporate culture and all the rest of it. And the traditional threat eradication procedure, where you corner it and squash it, doesn't work when you're talking about fellow employees. It leaves a mess on the carpet. So when we're thinking about this kind of thing, the fact that we can then use digital methods to identify and indeed flag up behavior that is aberrant by definition, it's highly valuable. Good to hear that.
When there's something that I learned as an analyst, then it's that technology is not everything, but without technology, everything is not enough. Are there specific technologies that you would recommend for detecting these adversarial attacks?
Well, absolutely. Monitor for inputs that seem designed to test the security boundary. So for example, if Jonathan Kerr sends Matthias slightly modified versions of the same file, or Jonathan Kerr makes requests of an application with very small variations, there might be probing for weaknesses. And this can be at the protocol level or at the application and business logic level. And so when we see that, again, that's something that indicates a cause for investigation. The second thing is we need to establish baseline behavior models for critical systems.
What is normal access for the payroll system? What's normal access for the treasury? What's normal access for supplier management? What's normal access for production operations? And so on and so forth. Whatever the critical system may be for your organization. If we establish these baseline behavior models, it means that when we see a deviation, we can alert on it. And of course, as I said previously, the goal of many sophisticated attackers now is to try and fly under the radar. So this is not a panacea, but we are raising the bar of the attacker.
We're making it harder to attack the organization. You've mentioned that throughout our discussion, one key factor behind that, behind the changes that we're just observing is the leveraging of AI for the attacker. On the other hand, you just mentioned there is a pattern. I have a normal, I have to identify an unexpected behavior.
But that, again, is AI on our side. So we have AI on the attacker side. We have AI on the cybersecurity protection defender side. The broader challenge behind that is that these systems are communicating with each other. And on both sides, it's AI.
Well, like so many defense technologies, it's an arms race. Attackers are using AI to generate attacks. Defenders are using AI to detect them, respond, and detain them as quickly as possible. And oftentimes, the winner is the one that has the better data, more diverse model training, and faster adaptation cycles, which is why — come on to another topic here — threat intelligence sharing and collaborative defense are becoming so important. And I heard one former CEO, someone I respect very much, talking about the art of modern defense. We're no longer isolated.
And in fact, let me give you an example. In my former career, I used to use the joke about two people lost in the woods, and they hear a bear roar behind them. And one of them starts running, and the other one gets their training shoes on. And they say, why did they do that?
Well, you can't run a bear, no, but I can outrun you. I was so wrong.
So, so wrong. We only win when we protect ourselves collaboratively, our organizations, our supply chains, for that matter, our competitive partners. We need to stand together. And this is in fact what modern cyber defense is moving towards. Collaborative defense, threat intelligence sharing are critical against ETH attacks. I fully get that. And I think that is really an important aspect, because this is a different thing. I don't think that I should ask the next two weeks question at the end of that segment.
But nevertheless, what should CISOs at least prioritize when they try to build defenses against technical deception? Yeah, we can't do everything all at once. So where do we start?
CISOs, start with diversity in your security stack. Don't trust any single vendor or single detection method. You need to implement multiple layers with different detection approaches, and invest in skilled security analysts who can investigate the anomalies that these systems flag. Human insight is still crucial to understand sophisticated attacks augmented by sophisticated knowledge management, sophisticated automated defense and indeed prescriptive action systems, but still human insight is crucial.
So now we went through these four categories, these four dimensions of this framework taxonomy that we looked at in the beginning. And that is really quite something to chew on. So this is really something where people have to think about, me myself as well. So if you combine this, usually when you do presentation, there's this final slide with three main recommendations as the takeaway. What would be your takeaway for CISO's three immediate actions for improving deception detection?
First, and I stressed it during this web book podcast, implement verification protocols for high risk transactions communications. Don't rely on people to spot deception. There's considerable evidence now that it is impossible for humans to maintain that state of constant vigilance. So we need to build systems that require verification.
Secondly, behavioral analytics will allow you to establish baselines for normal user, and for that matter, NHI, non human actors will also give you a behavior pattern. Thirdly, you need to create a culture where it's okay to report suspicious activity. It's encouraged, it's protected, and it's not blank.
Hey, oh, why are you flagging this again? You're wrong three times last week.
Yeah, but they might be right this time. Yeah, not very popular topic, but technology investments, where should organizations focus their initial budgets when they're starting on their journey here?
Well, not a very popular topic, as you say, because everyone wants to invest in the latest and the shiniest. But look at your communication flows and your business pathways. Prioritize the technologies that integrate well with those existing systems. So advanced email security with impersonation detection. Most organizations I know do a lot of high value business. They send contracts, they send payments back and forth via email. So impersonation detection, behavioral analytics platforms that can analyze user behavior across multiple systems.
You need to have a person centric view of behavior or need a non human actor centric personality behavior profile. And then detection protection technology. Fairly underutilized, but it does allow you to detect unauthorized access. It's possible to solve everything at once. But if you can focus on your highest risk scenarios, that's where you'll get the biggest wins and therefore the mandate to move forward. We've mentioned that before we've mentioned William Gibson, it sounds like science fiction already. There's deep fake videos.
And if I imagine I have 250 episodes of this podcast out there, I think there's enough material to train an AI to impersonate me. I think that should be doable. But what do you expect coming our way? How do you see the deception landscape evolving? We'll see attacks becoming more automated and scalable. We'll see AI generated attack campaigns that can adapt in real time based on our responses as defenders.
Hey, is that really you? Yes, it is really me.
Oh, okay. If it's really you, Matthias, what do we talk about on the last? And the answer will come back will be plausible and correct. We're going to see the volume of attacks increasing dramatically, together, unfortunately, with their sophistication. So my advice is organizations prepare now for these emerging threats. In some recent episodes, which had a very different focus, I talked with psychologists about the pressure that CISOs endure by the sheer amount of work they need to do and security teams in general. Now we are adding more complexity, more responsibility on CISOs.
What is your advice for CISOs who are just overwhelmed by the scope of this additional challenge? The job of a CISO has never been harder. And it's every indication that CISO's day is going to be the easiest day you've ever had. So it's only going to get more difficult. But what can we practically intangibly do? We can start with a deception risk assessment. We can map critical business processes and identify where deception could cause the most damage. This gives us our hot points.
If we build defenses around these hot points, these high value targets first, then that's where we get the most likelihood of a win. We don't need to solve everything immediately. But we do need to build organizational resilience systematically, starting with the hot points and working outward.
So again, we're back to slicing the elephant, really identifying where to start and what makes most sense based on a risk assessment. And that finally is nice for me because this is my standard reply. Start with a risk-based approach and here we are. That again can help cutting down the issue, at least allowing that to put it on a timeline and not do everything at once. First of all, thank you, Jonathan, for this great insight about the overall landscape. Any final thoughts for our listeners?
When you look back on our conversation on the framework that you just created, anything that you would like to add that is important? There's a couple of things. First of all, detecting deception is not just a technical problem. It's an organizational capability. You need the right combination of people, processes and technology working together. Not the first time we've given that message, I'm sure. You need to invest in training your team to think like attackers. Which is especially key when you are talking about that risk-based approach.
Don't give in to the temptation of risk management being shutting your eyes and hoping it doesn't happen. I've seen that too many times. So instead, you must create processes that are resistant to manipulation and deploy technologies that detect what humans might miss. Great advice. Thank you very much, Jonathan. And we are at the end of the episode. It's a bit longer, but it was so much worth it. I hope you all stayed with us until the end because this is so important. For our listeners, you'll find more resources on deception detection on our website because this is what Jonathan does.
So there will be more research on that. And I think educating yourself and preparing and actually doing something is key here. Absolutely. Thank you very much for having me. It has been a great discussion. Thank you very much for our listeners for joining in. If you have any questions, as usual, you can leave your comments at our website on LinkedIn where we announced this episode and on YouTube in the comment section. We are looking at that and we will pick up on that. And Jonathan and I will be happy to do another episode just with your questions. Just leave them here.
Until that and until next time with you, Jonathan, we all have the wish that we stay secure and stay skeptical. So this is a business practice. Just do it. Thank you again, Jonathan, for being my guest today.