TL;DR SUMMARY: Social engineering succeeds because it works with human behaviour. Adaptive SAT, effective SAT and AI security awareness need to account for pressure, trust, urgency and cognitive load. SAT software should help people practise safer decisions in context, rather than relying on annual reminders to carry them through complex moments.
Social engineering, cognitive load and AI security awareness
Social engineering is often discussed as if it depends on trickery alone. In reality, it depends on familiarity. Attackers use behaviours that already exist in working life: responding quickly to senior people, helping colleagues, trusting known brands, clearing tasks before the end of the day and avoiding unnecessary friction.
Security awareness training can’t remain static in that environment. Annual training may tell people to watch for generic signs of risk, while real attacks arrive wrapped in plausible business context. The result is a widening gap between learning and action.
AI widens that gap. It allows attackers to produce cleaner language, create more targeted messages and scale attempts that once required more time and skill. AI security awareness should therefore focus less on novelty and more on how familiar pressures are being amplified.
Rebecca McKeown, Chartered Psychologist and founder of Mind Science Ltd, offers a helpful lens for this shift. “The brain is a limited-capacity information processor. It’s always taking shortcuts and trying to make things quick and easy.” When work is already stretched, those shortcuts become part of the risk landscape. Effective SAT, in that context, needs to strengthen the decision environment instead of simply repeat information.
Adaptive SAT and the human-in-the-loop principle
Adaptive SAT is one way to do this. Rather than sending everyone through the same programme, it can respond to role, exposure, behaviour and need. A finance team may need support around payment fraud and invoice manipulation. HR may need scenarios involving personal data and document sharing. Developers may need guidance around code, secrets and AI-assisted workflows.
SAT software should also help organisations understand whether behaviour is changing. Are risky clicks decreasing? Are suspicious messages being reported faster? Are users responding well to nudges? Are high-risk groups receiving timely support?
There is a simple question worth asking: does your training prepare people for the moment they’re actually in?
If the answer is no, the programme may be producing completion instead of resilience. The future of security awareness lies in timely, contextual and behaviour-led support, because people are the ones making decisions under pressure every day. A useful programme should leave them better equipped in those moments, not merely better recorded in a dashboard.
Interest in adaptive, behaviour-led tools such as Redflags has grown partly because this gap is becoming harder to ignore. Security teams need evidence that awareness is shaping behaviour, while employees need support that recognises the conditions they are working in: pressure, pace, divided attention and increasingly convincing AI-assisted threats.
Key takeaways
- Social engineering exploits normal workplace behaviours.
- AI makes attacks more polished, targeted and scalable.
- Adaptive SAT should reflect role, exposure and behaviour patterns.
- Effective SAT prepares people for real decision moments, beyond quizzes.
