Social engineering has been around since humans started talking to each other. The psychology hasn't changed, but AI has made the execution almost unrecognisable.
Welcome to Razorwire, the podcast where we share our take on the world of cybersecurity with direct, practical advice for professionals and business owners alike. I'm Jim and in this episode, I'm joined by Richard Cassidy, Field CISO at Rubrik, and Bec McKeown, a chartered psychologist specialising in human performance under pressure.
Social engineering isn't a technology problem, it's a human one that cybersecurity has inherited. The psychology behind it hasn't changed since Cleopatra was using it to outmanoeuvre empires, but AI has transformed the speed, scale and sophistication of every stage, from automated reconnaissance that builds a complete profile in 30 minutes to real-time voice cloning that references your actual projects and travel schedule.
Bec and Richard bring two very different perspectives to the same problem. Bec explains how attackers engineer the conditions in which people make decisions rather than just crafting a convincing message, and why "people are the weakest link" misses the point. Richard shares what he's seeing as a practising CISO, from family members being targeted through gaming platforms to why measuring phishing click rates gives organisations a dangerous false sense of security.
Three key talking points:
- They're not hacking people, they're shaping decisions: Social engineering works because attackers engineer the conditions under which decisions get made, not because people are careless. Bec explains why most security awareness training is solving the wrong problem by focusing on the message rather than the environment in which people are operating.
- AI has turned social engineering into an automated pipeline: What used to take weeks of manual reconnaissance now takes 30 minutes. AI-powered OSINT can build a complete profile of a target and generate a tailored attack that references their projects, travel and communication style. Combined with real-time voice cloning, these layered attacks are becoming almost impossible to distinguish from a legitimate request.
- Your family is now part of the attack surface: If the executive is too well protected, attackers go to the people around them. Children on gaming platforms are being cultivated to unknowingly share information about their parents' work and routines, and a compromised family device on a shared home network becomes a route into the corporate environment.
The psychology behind social engineering hasn't changed in thousands of years, but the tools to exploit it have. If your defences are still built around phishing simulations and click rate metrics, this episode will make you rethink.
On why social engineering isn't about fooling people:
"They're not hacking people, they're shaping the conditions in which people make decisions."
Bec McKeown
Listen to this episode on your favourite podcasting platform: https://razorwire.captivate.fm/listen
In this episode, we covered the following topics:
- The History of Social Engineering From Cleopatra to Cold War intelligence operations, social engineering has worked for as long as humans have communicated. We discuss why the psychology behind it hasn't moved an inch.
- Influence vs Manipulation Bec explains the difference between making someone do something they don't want to do and making them want to do it, and why that distinction matters for how we build defences.
- AI-Powered Reconnaissance Find out how AI has turned open source intelligence into a fully automated pipeline that can build tailored attack scenarios from public data in under 30 minutes.
- Deepfake Voice and Video Attacks We get into why real-time voice cloning combined with genuine project data and manufactured urgency makes modern social engineering attacks almost impossible to spot.
- Layered Context Attacks Discover why the most dangerous attacks don't rely on a single trick but layer urgency, authority, familiarity and isolation together until there's no reason to doubt what you're seeing.
- Family as an Attack Surface Children on gaming platforms are being cultivated to share information about their parents' work and routines. We discuss why the family network is now a recognised route into executive environments.
- Gut Feeling and When to Trust It Bec and Richard explain why intuition is often the first signal that something is wrong and why corporate culture has trained people to ignore it.
- Confirmation Bias in Action A group of colleagues all received the same phishing email, checked with each other and decided it must be legitimate because they'd all got it. We discuss why that instinct is exactly what attackers rely on.
- Why Security Awareness Training Measures the Wrong Thing Phishing click rates going down doesn't mean your organisation is safer. We discuss why this metric wouldn't have prevented any of the major social engineering incidents of the last few years.
Resources Mentioned
The Psychology of the Machines
Cialdini's Six Principles of Influence
Gary Klein / Recognition-Primed Decision Making
Trend Micro AI-powered OSINT research
Deepfake fraud - regulatory warning
Connect with your host James Rees
Hello, I am James Rees, the host of the Razorwire podcast. This podcast brings you insights from leading cyber security professionals who dedicate their careers to making a hacker’s life that much more difficult.
Our guests bring you experience and expertise from a range of disciplines and from different career stages. We give you various viewpoints for improving your cyber security – from seasoned professionals with years of experience, triumphs and lessons learned under their belt, to those in relatively early stages of their careers offering fresh eyes and new insights.
With new episodes every other Wednesday, Razorwire is a podcast for cyber security enthusiasts and professionals providing insights, news and fresh ideas on protecting your organisation from hackers.
For more information about us or if you have any questions you would like us to discuss email [email protected].
If you need consultation, visit www.razorthorn.com, We give our clients a personalised, integrated approach to information security, driven by our belief in quality and discretion.
LinkedIn: Razorthorn Security
YouTube: Razorthorn Security
TikTok: Razorwire Podcast
Instagram: Razorwire Podcast
Twitter: @RazorThornLTD
All rights reserved. © Razorthorn Security LTD 2025
Fler avsnitt av Razorwire Cyber Security & InfoSec Insights
Visa alla avsnitt av Razorwire Cyber Security & InfoSec InsightsRazorwire Cyber Security & InfoSec Insights med Razorthorn Security | Cybersecurity & InfoSec finns tillgänglig på flera plattformar. Informationen på denna sida kommer från offentliga podd-flöden.
