AI tools are rocketing in popularity, and as businesses grapple with striking a balance between AI-enablement and information security, there has never been a greater need to understand exactly how your people are using AI tools.

Redflags’ real-time data gives customers insights into how they are using these tools, where risk hotspots are forming and nudging them to make the secure choice; helping businesses to shape their AI governance and human risk strategies.

In this session, we will share the trends we are seeing, customer use-cases and explore where the future of “human in the loop” AI governance.
• Deep insight into how humans are using AI tools
• Guidance on where risk hotspots are forming from colleagues’ use of AI tools
• Ideas for AI governance policies
• Ideas for Human Risk AI interventions
• Key trend analysis for AI

Hosted by: John Scott (info), MD, Wildpark Security Consultancy Ltd

Speaker: Tim Ward (info), Co-Founder and CEO, Redflags

Transcript

John Scott: Good morning, everybody. Happy 1st of May. Welcome to Friday’s SASIG webinar. My name is John Scott. I’m guest chairing today and it is my joy and my honour to welcome you in. As everybody’s coming in and settling themselves down, shuffling their virtual seats, I just thought I’d tell you that at the beginning of the year, I introduced my son to punch first of the month. And I’m very proud that today he came and said, oh, Daddy, good morning, and came to give me a good big hug and then did punch first of the month, no backsides and ran away. So, you know, whilst I’m winning 3-2, I’m proud of his sneaky nature.

So please just make yourself comfortable. If you have a look at the chat, SASIG Tradition says that we always give everyone, you can say hello in the chat and just give us a little bit of an idea of where you’re from and because we’re British, what’s the weather like? So I’m beaming in from East London. I’ve got a patch of blue sky that I can see out my window. That’s not because it’s cloudy here, it’s because I’ve got a very small window, but it is a beautiful, beautiful sunny day out there, hence the massively bright colours. We’re going to get started in a couple of minutes, but I just have a couple of parish notices to go through.

So if I could have the next slide, please. Oh, relatively sunny Bournemouth. Okay. It’s always sunny when I go to Bournemouth. So if this is your first SASIG, you are very, very welcome. If it is your nth SASIG where n may be a small or large number, you’re also welcome. Just run through some house rules. We try as much as possible to honor the spirit of the Chatham House rule. So SASIG works because people come and share, they share good news stories, they share bad news stories, what worked, what didn’t. And The Chatham House rule, if you not come across it, basically says that you can talk about what you’ve learned today, but unless you have specific permission, please don’t attribute it to anybody.

So you can say, oh, I heard on a SASIC webinar X, but you can’t say, John Scott said, unless I’ve said it’s okay. And that just means that we can have those nice open conversations. As part of that, then please take part in those conversations. So I can see loads of people coming in from into the chat from lots of different places around the country. I haven’t seen anybody from overseas just yet, but I may have missed them. Please remember you can add things into the chat. When it comes to Tim’s talk, though, probably the best thing to do is if you have any questions for him, to add them into the Q&A, which I will be keeping an eye on.

That’s down at the bottom of Zoom. If you do make a comment in the chat, I will try and make a note of it to ask Tim at the end. But if it’s in the Q&A, it’s a lot easier for everyone. When the webinar is over, we’ll pop up a little survey for you just to say, what did you think? Was it good? Was it bad? What was really useful? What could have been better? The more feedback you can give us, the better, because we take those ideas and we make sure that we implement them going forward. And to that end, if part of your feedback is, I have a topic that I would love to talk about, let us know.

We are always looking for guest speakers. We’re always looking for people working in security who have got something interesting to say. So please do let us know. Deborah, I don’t actually know about CPE purposes, but if you drop a note to info at thesasinc.com, they will be able to tell you. Next slide, please. So one of the, we are a special interest group for security awareness and the human aspects of security. And as part of that, we have our series of webinars. Now, May is a relatively quiet month. We’ve had a couple of big events that we’ve been running. And as you know, since SASIG took control back from the 19 group.

There’s been an awful lot of work going on. So we’re taking it a little bit slowly, but we do have some coming up. So roughly one a week, you can see we’ve got some talking about AI agents on next Wednesday, looking at the Cyber Resilience Center Network, which is the police supported small business supports around the country. Looking at OT security operations on the third week of May, which is a fascinating subject. And then one that I think is really going to be fascinating, which is going to be a must watch, is listening to Richard Horn from the NCSE talking with Martin about what it is and what does he do?

You’ve got an answer there, Deborah, if you have a look in your chat. So yeah, the chief’s brief is there, but remember that you’ve got the full calendar at www..thesassica.com slash events, which also includes all of the recordings from previous sessions. So have a look through those. There’s some fantastic things in there. Next webinar, next webinar, next slide, please. So as much as it’s great to catch up with people via webinars, the really the beating heart of SASIC is the in-person events. So we just want to draw your attention to some of those coming up. Next week we’re in Manchester, so we’re going to be doing SASIC of the North.

So as much as we can, we try and get SASIC events out so they’re not just London-based. Having said that, the next three are London-based. So we’ve got a fantastically interesting one on governance, risk and compliance. We’ve got the financial services SASIG on the beginning of June. And then one of my absolute favorites at the end of June is the emerging technologies one. Jesus, if you have a look on the SASIG website, there’s a link literally just above you that has more details on there and it can tell you, can find out about all of the events there. So again, have a look at the calendar. Do come along to the face-to-face events because they’re a fantastic way of meeting people.

And I’ve just realised, I’ve said I’ve used my quota of fantastic for the day. So I’ve got to go. I’ve got to do better with that. Next slide, please. Our flagship event. Though the key event for SASIG through the year is Big SASIG. Now this is in September, it is in London. It’s a great coming together with the community, but it is also the only SASIG event where we actually have vendors and stalls that you can talk to. And that’s very deliberate. SASIG, whilst it is supported by an awful lot of organisations, and I’ll talk about them in a second, SASIG does very much say this is a vendor free space.

We can have those chats. Big SASIG is the difference. There’ll be loads of talks on, loads of interesting people to meet and listen to, but there will also be SASIG friendly vendors, i.e. they’re not just going to hit you with the sales pitch. They’re not just doing the same thing that they did for everyone else. They’re coming along because they know us and they understand our crowd and they know what we want. So it’s again, one of the highlights of the year I would suggest. So please do come to that if you can. Next slide, please. I mentioned our supporters and our contributors. Let me draw attention to them here.

This is what they get, by the way, for their helping SASIG run, for helping us make sure that we can keep events free for our members and for supporting us in many other different ways. They get a thank you here and it is very gratefully meant. Thank you very much to all of our supporters, all of our contributors. But that’s it. They don’t get to push into conversations. They don’t get to give you just sales pitches. If they’re going to speak, as you’re about to hear, they’re going to be talking about interesting things. So we’re very, very grateful to all of our supporters and contributors because SAS IC would not run without them.

Final slide, please. So having said, vendors aren’t going to sell you stuff. I’m going to hand you over to a vendor, but it’s not just any vendor, it’s Tim. And we know Tim really well. I don’t think I have ever been to a talk where I haven’t learned something from Tim. And that includes when I was directly working for a competitor of his and had to sneak in at the back. Not that I ever actually said that, Tim, that you could find out. But Tim’s one of the people who’s been looking at human cybersecurity for longer than I have. So we knew each other. We’ve got produced 12 years ago now, I think.

So Tim absolutely has the human cybersecurity cut through him like a stick of Blackpool rock. So when he starts talking about AI, it’s not just going to be the normal stuff. But I’m going to stop talking now. I’m going to hand over to Tim, and I’m going to be listening intently. Thanks, Tim.

Tim Ward: Thank you very much, John. Yeah, I mean, I kind of I’m so glad to have so many people here today because there is a running joke, isn’t there, at every event that how long does it take for someone to mention AI and are we getting a bit bored of it now? But what I wanted to do here is kind of highlight some of the data that we’re getting from working with clients to start to understand what’s actually going on Where does the threat lie? And so I want to kind of, I’ll go back to basics a bit of kind of, well, let’s explore this. What is AI there for? Why is it good?

Why is it bad? What are the behaviors we should be worried about? And what can we do about that? So let’s get stuck in. Tell you what, I’ll also share my slides. That would be a good start, wouldn’t it? Here we go. think that is now coming through. So yes, AI, AI everywhere. Then, and obviously it’s a good thing and it’s a bad thing. We all understand that AI is a fantastic enabler. Lots of us are using it in our organizations. We’re helping using it to organize ourselves to help us write content. It can be fantastic. adopting web-based services like ChatGPT, Copilot Core, Gemini, Deepseek even, but also now more locally desktop installed applications, agentic models, even as far as Clawball.

So I mean, this momentum is driving innovation and it’s a great thing, but it’s also slightly outpacing security policy. And I think and one I’ll turn to in a second is that the data tells us that it did set everyone into a little bit of a panic mode. It’s a fantastic enabler, but it’s creating new risks and new challenges that we really need to be all over. What are those risks? Well, you’ve actually still got the old risks, exactly the same risks, but now the bad guys are so much better at it. I’ll go into this in a bit more detail, but it means you’re getting better fishing, better social engineering.

But actually it’s creating a whole load of new rigs. So we’ve actually created a, we’ve increased the attack surface really. And so you’re now seeing some same old threats like data leakage, but now into AI tools and tools that we don’t really understand, we don’t really know where the data’s going. But at the same time, we’ve got a huge pressure from the organization to be allowing people to use these tools. So we’ve got data leakage into AI, we’ve got shadow AI. What is that AI actually doing? Where does the data go? Are people using their personal accounts to sign up? Or are they using corporate credentials? And are these things actually starting to sidestep DLP, identity and audit controls?

And then you’ve got the FET now, most recently of Corebot and things like that are this unmanaged local AI. So it’s always been a challenge for shadow IT to be installed on your device. But actually people don’t really even now understand quite what some of these tools are doing and how they’re doing it. They can very easily sort of act like they’re just running in the user space like the user, but where are they then sending that data? And one of the challenges as a people-centric security person is that you’ve been working really hard to help people try and think carefully about where to put their data. And then you’ve got this fantastic agent that’s helping them.

And how do we get to that agent? How do we tell that where to put the data and how it should? What are the guardrails to stop it doing things with browser plugins that have got excessive permissions and things like that? And then you also get into some interesting spaces around just people’s understanding of AI, of what it really is. There’s been some really interesting research around the fact that we have an overtrust in AI. And so people start to doubt themselves and they trust AI more than they trust human advice. And so this can create some real challenges as well. And just that need to help educate people and help them understand what’s going on.

And what we’ve seen, I’ll go into this in a little bit more detail, is two major challenges. First one being visibility. What on earth is going on? How do we understand this as a security team in order to then govern it? But if we can’t see it, we can’t really understand what’s going on and we don’t know how to govern it. And then of course we need to start thinking about what are governance policies. And so across the last several years, of course, we’ve been gathering data, working with clients. So we get quite a lot of telemetry from devices about who’s doing what, what behaviours are they doing. And also we learn a lot from what are our clients telling us they want to track and what behaviours they want to track.

And so we’re just about to publish a behavioural impact report that’s looking back across 2025. But for today, I just really want to dig into the AI side of it, but just to kind of give you some highlights of the kind of the wider report. This is across multiple organisations. I think it tracks essentially 29 million interventions across the year with the content that we’re pushing out and getting really good high 82% engagement stats. So people are seeing this stuff, they’re engaging with it. And then the graph in the middle is looking at, well, what were people worried about? And of all the clients that were tracking things, It’s still phishing stuff.

So 93% of people were focused on those sort of phishing based behaviors. But actually then they started to look into other things like, so 46% of our clients started to look at some of these AI nudges. And these are just, we’re giving data points on individual nudges. So broadly there are lots of different behaviors. So you could say if you partition this into AI, you might see a higher range of nudges around this. And of course, in this data, there’s different industries, but mostly we’re talking financial services, engineering and manufacturing and some government organisations. So that’s the kind of the broad high level view. But let’s go a bit deeper into the AI stuff.

So on the left hand side, you’ve got who was interested in tracking AI? And it was the financial services organisations predominantly, and then the sort of critical national infrastructure. And interestingly, even nonprofit were interested in understanding what’s going on here. And then when we started to look at what sites were people actually visiting, a very strong bias towards ChatGPT. I think that will be really interesting in 2026. I think we’ll see that shift quite a lot, but that was the first one that everyone knew about. So that was the sort of the go-to tool that everyone was trying to go to. What was really interesting, and particularly in organisations who thought they maybe had a handle on it, starting to see people drifting off to places like Deepseek when most organisations really wouldn’t want their staff doing that from a work device.

What we then wanted to look at is, well, what’s the focus? What are people actually interested in doing? And as I alluded to earlier, in sort of back end of 2024, beginning of ’25, it really was just a question of visibility. Most security teams really just wanted to understand what is going on, which departments are using tools, what tools are they using it. And we saw this real growth in the number of organizations wanting to track who is using AI. So it’s 91% growth, but then also a growth in the number of people within the organization actually using these tools. And I think if you look more widely and had even more data, you would probably see these going now pretty exponential.

Some really interesting other stats came out and I think it alludes to where this is going to go, but a little bit of the Pareto principle, but we started to see these power users where 3% of users in our data were accounting for 18% of the usage of AI. And so you’ve got some people who are just using it nonstop and then other people in the organisation who haven’t really jumped on this. at all and they aren’t really using it. And so that helps you to pin down, well, who are the people I need to educate? Who’s using this a lot? Because if you can get to those 3%, then you’re actually impacting a lot of the behaviours of a lot of people using the AI.

So just very broadly, how do we tackle this? And I think it suggests a sort of a bit of a shift from just blocking staff and scaring people about stuff because this is a really positive technology that most of our organisations want people to engage in. They want people to be using these tools because it’s driving efficiency, it’s driving innovation. So these aren’t things we can just turn off. I remember saying quite a few years ago, you’ve got to enable people. If you just turn this stuff off, they’re going to go and find other ways to do it. As it’s got better, you could just take a photo of your screen and chuck that in a personal version of one of these Then the organisation really has no idea what’s going on.

Just blocking stuff and scaring them away from it is not going to be valid tactics. Of course, I would argue, and I think John will probably agree, and we can discuss this later, that blocking things and scaring people has never been a particularly valid tactic, but it does tend to be a security tactic on certain things, but we can’t stick our heads in the sand this time and do that. We need to create these boundaries and this understanding of how should people be using it We need to help them in the context where they’re using it, create these guardrails. And as always with any behaviour or secure behaviour, make the secure way of doing things the easy way.

So I’ll come back to those in a bit more detail in a second. But if we’re looking at these new tools and these new challenges, because I think this breaks into two things. It’s the new tools and the newest cyber risks. But actually you still got all the old cyber risks and I’m going to be flipping back and forth between these two. But if we’re looking at the new tools, what we saw that was quite interesting is a real sort of shift across 2025 from people going, I want visibility, to people going, right, now I’ve had that visibility. I understand. I’ve now got a policy in place. I’ve got that policy signed off.

So now we’re steering towards more governance and guidance. Now we know what people are doing. What do we want them to do? If any of you heard me talk before, it’s really important in my view, if you’re going to change behaviour to know what you want people to do. If you’re just constantly saying, don’t do that, don’t do that, don’t do that, it’s a really negative spiral. You become very naggy and people turn off from it. So what you want to focus on is what’s the behaviour you actually want people to do so you can steer people towards it. So on the right hand side of this, we started to see the sort of governance that people were interested in.

So it’s that caution around uploading files, helping people to understand, as with any DLP, that you might have personal data, you might have commercially sensitive data. You need to think carefully about what you’re putting where and which tools you’re using. Then there’s this challenge of identity. Are you using a personal account or using a corporate account? Sometimes personal accounts, well, you don’t really know where the data’s going, the models might learn off that, whereas corporate accounts are meant to be much more locked down, it’s more restricted and the models aren’t meant to learn. So it’s really important to govern people towards the right tools, but also the corporate account tool, but also away from the unapproved tools.

So nudging people away from things like deepseek and things like that and nudging them towards the tools that you want them to use. But of course the old threats are still there and now they’re on steroids. And so with the tools that you’ve got with AI, you can be so much better at phishing. So you can personalize at scale And so by getting AI to crawl across either leaked data, but also just publicly available data like Facebook, like LinkedIn, you can start to really send a message that shows like you understand someone, that you’re their best friend because you are really trawling across all their data, everything they put out there.

And so that can make your messages really personalized and that’s going to be more impactful in terms of getting someone to click. You can also really, really tune the language and the tone and the style. And that can even go as far as role impersonation. So you can be kind of like, right, I want this fishing sim to sound like it comes in the HR department. Let’s train this on data for how HR talk to people and the sorts of things they say. Let’s get the tone and the language and the style right for this country and this organization. And of course, voice and video with deepfake is becoming more and more credible, but there’s also an interesting aspect of timing.

Because again, you’ve got the data out there, you can start to think about world, and even a feedback loop. of when is the best time to try and fish people? When are they gonna be the most busy? And you could be running fishing sims where you’re actually testing this, and sorry, real fishing, and testing this, and you check the performance of your fishing, and you see when you get the most impact, and that’s when you focus on bombarding people. And of course, the skill barrier for sending fishing has been coming down anyway with lots of these kits out there, but actually with AI, that skill barrier is even lower. So the same old, same old threats and beyond phishing, of course, but for social engineering and phishing, the same old threats are still there, but the attackers can be even quicker and faster and low cost at doing them.

So where can defenders focus? How can you stop this? In my view, context is still really, really important. It’s all very well that something sounds like the HR department, but there are certain things they should and shouldn’t and would or wouldn’t be asking you to do. I think it’s very wishful thinking that you will ever be accidentally emailed a list of all the bonuses and pay rises. It just doesn’t happen. It’s a classic phishing thing, even with all these new tools that make that look really, really legitimate. If you stop for a second and think about would this really happen, the answer is probably no. So context does still have to be really perfect.

And the tells of manipulation and all of those kind of things that are trying to play to your cognitive biases and heuristics to make you fall for social engineering, they’re probably still going to be there. All the easy tells like the misformed sentences, the typos, the poor grammar, the URLs that don’t look quite right, some of that’s going to go away. But they still need to manipulate you. And importantly, they still need you to go out of your governance cycle. You’ve got to be following poor process and poor governance if you’re going to fall for some of these things. So, for example, with invoice fraud, although you might be being pressured by these amazing deep fakes to do something beyond process, If you’ve got good governance and people understand that shouldn’t ever happen, that you should put the phone down and then recall the right person to sign something off or have two pairs of eyes on it, then you shouldn’t be able to go beyond that process and you shouldn’t be able to get hacked.

There’s some core things that I would hope are still going to remain, that need for manipulation, and so those tales remain, but the need to also go out of governance. And this still remains for me a behavioural thing. It’s still about behaviour, still about helping people learn how to react to risk and help them at that point of risk in the context where something’s happening. So if that’s the case, then let’s go into behaviour a little bit deeper. And those of you who heard me talk before, you would have heard me say this before, but I think it remains fundamentally true that if we’re going to change people’s behaviours to help them in these challenges, we really need to be delve a little bit deeper into how people really learn how they behave.

And we have had a tendency to take a very traditional approach to helping people. This idea that if I teach someone something and they have the skills and the knowledge that’s going to impact whether they behave in that particular way and great, they’ll behave. And this comes from the theory of planned behaviour. And it’s kind of true in your day-to-day when you’re a normal human being going about your business and you decide I’m going to learn how to do something and then I’m going to do it. We are dealing with people acting under pressure and context interferes with these decisions and that can be macro context of the organisation. So are people going to be following processes if it’s a really delivery focused organisation?

Carlson did some interesting research on this where they asked people if they follow process in a survey and of course most of them said yes they did. But then when they looked at whether they really did, they measured the behaviours, the people in an organisation that was very, very delivery focused, i.e. the macro context and the culture was about just get the job done regardless. Unsurprisingly, people didn’t follow security policies, even though they said they did. And that seems fairly obvious, but that macro context interferes. And so that’s quite important. What are the messages your organisation’s sending? But then of course, the micro context, those day-to-day contextual cues on your device, when you get that e-mail, when you’re about to do something, what sort of messages are we sending there?

And that’s where it comes into your heuristics and your rules of thought, which will go into a bit more detail. And of course, habit also impacts whether you behave. So how do we really decide and make decisions under pressure? So we all like to think we’re really rational human beings, and we think things through really carefully before we do things. But actually, particularly under pressure. we tend to fall into system one thinking. It’s a bit more of an automatic pilot and psychologists call it browned rationality, the bounded side rationality. And yes, we are rational human beings, but how wide does our brain go in making that rational and logical decision?

And the idea is that if you are acting under pressure, your brain is going to be a little bit lazy. They call it being a cognitive miser. It’s not going to be able to take in all possible pieces of information. And this makes sense. It’s an evolutionary thing. You are bombarded with so much information on a day-to-day basis, your brain has to filter some of it out. And so the way that we think is bounded and the brain makes slightly easier decisions than you might think it is. And these are called heuristics. They’re rules of thumb and they really help us process this data. So a great example could be, and you see it in the world of marketing, do I like this product?

Am I making really good judgment about maybe this buying this car or this very expensive watch or this perfume? Or do I find the person advertising it attractive and I want to be like them? And the marketeers know that actually we make the slightly quicker, slightly lazier decision of, yes, I really want to look like that person or be like that person. And we then sort of post fact, rationalize that and decide, yeah, actually, I bought that car because I really like that car. It’s the best car for me. And it’s not really necessarily the case. So these heuristics, these rules of thumb, they cause cognitive biases and we make mistakes.

And the bad guys use them all the time. So you’ll recognize some of these. So on the top right, we’ve got effect heuristic, that’s emotion. And so the bad guys are using emotion and fear. There’s also a conformity bias. So that’s the social proof where you’re being tricked into doing something because other people doing it. Of course, authority bias we see in CEO based fraud where you’re getting an e-mail from the CEO saying, go and buy some Amazon vouchers. I’m constantly telling my team, no, it’s not me when they’re being bombarded with those ones. And so you see the bad guys using this and they are really effective because in the moment, in the context, we make quick decisions.

So how can we help people? And so I call this my Goldilocks slide because it’s really looking into where do people behave and where do they make decisions and where’s the precise moment we should help people. And so every decision takes place in the context that’s going to be mostly on your IT and in the context that we’re talking about of risky decisions and security. there’s a decision point and an action. And of course, our traditional work here has always been e-learning videos. And I would argue it’s too soon. It’s not in the context. It’s great for building a foundation of knowledge and you do need that. But in the context where the threat lies, it’s very likely to be forgotten.

And in fact, if we’re responding to one of these cognitive biases, Our brain is simply not looking backwards and going, what did I learn six months ago? We’re just clicking before we even realize it. And then on the right hand side, you have got things like phishing sims, but also other human risk management tools where you’re looking at fantastic data sources so you can understand what’s going on in the organization. But all you’re really left with to do something about that is maybe an after the fact Teams message or an e-mail or a Slack message. Now you could call those real time, but I would argue that after the fact and they can start to get a little bit naggy and they’re not going to prevent the behaviour, they’re not going to shape the decision and the choice architecture of when you’re making a decision at the point of risk.

And so we really need to be in the context and that’s always been our focus. How do you get into the context and help people? And this is true across all these AI-based threats as well as all the traditional ones. And I’ll go into what this really looks like, particularly in the AI threats in a second. So the first thing we want to do here is really just prime people simply in and around the context. We’re helping remind people that they’re in a situation that’s slightly riskier and we want to prime and be thinking about the threat in that particular context. Is that the threat of losing corporate data? Is it the threat of phishing?

But where this gets even more interesting is looking at particular decision points where someone is about to do something that could cause a problem. So maybe they’re out of sight and they click the open file dialogue and they’re about to upload a file. If you can intervene at these points, you can both measure how often does this happen and get that visibility, but then you can intervene and steer people away from it and embed that good future behaviour. There’s an interesting extension to the idea of nudging, and this is very much that idea of nudging, with the concept of a boost. A boost is, yes, you deliver a nudge which is there to guide and influence and has been criticised essentially for being manipulative, but a boost is that you hit that with some education too.

At the same time as you’re trying to guide and steer someone, you’re explaining why and how you want them to do it and what you want them to do. By combining that intervention with a bit of education, you can be even more impactful. So this is coming from some work we’ve been doing with a global organization, trying to look at what behaviors are really, really important to them around AI. And so some of the key behaviors that they wanted to track were going to download pages of unapproved AI agents. So that’s quite a new one they’re interested in. Are people going to Clawbot and Multbot? But then also tracking use of their corporate tool versus other tools.

So they wanted people using Copilot, but they wanted to understand are people using it in the browser via the desktop app and are they using the non-logged in version of Copilot? And if they are, let’s try and steer them to log in on the right version. But also are they going off to ChatGPT or other tools? Are they uploading files? Are they pasting data? What tools are they on and let’s steer them back to the corporate tool. And then of course you’re starting to see some growing concerns and we’re developing some new numbers around some of these of like what are they now building co-pilot agents and what permissions are they giving?

What file? structures that they’re giving these agents access to. And so you want to be kind of reinforcing those principles around least privilege to try and help people, yes, use these tools to make themselves efficient, but to get it right. And so simplistically, just as many of you have seen, the sort of thing you’re trying to do with these nudges are when I go into this Copilot site that maybe is the broad one that’s going out onto the web and it’s not my corporate one, then a little bit of a nudge to say, look, You’re on one of these sites, please don’t use this, don’t download this tool, don’t upgrade, don’t upload data to this tool.

So you’re steering people into the right direction. And then maybe if I went to OpenClaw, a little nudge as I open that website to say, look, you’re on this site, looks like you might be downloading something, please don’t do that. Here’s the tools that you can use. So you’re just intervening at that point of risk. This one is a bit more kind of forceful. Say, look, we’ve seen you’re actually doing this thing. Let’s steer you away. The previous one was more about, look, you’re on this website. Here’s how to use it safely. And again, this one, I’ve gone to ChatGPT, maybe in this context of this organisation, it’s absolutely fine to use this.

However, we don’t want you to upload sensitive commercial data into this site. And so you’re really using this to both track and understand what tools people are using. But then when you see the specific behaviour, you can start to intervene and guide them in the right direction. So this is where you can start to apply that governance and policy framework that you’ve got and try and get people to do the right thing. And so more broadly, across all these behaviours that we’re interested in, you do often have to build this into the context of a behaviour change campaign. What we would normally do is drop some content onto the desktop.

Now we’ve gone back to some of your traditional threats here around phishing perhaps. We’re dropping content onto the desktop to introduce a topic and get people thinking about, look, do you really know who this e-mail is from? Maybe the context is absolutely slick and perfect, but it’s still not actually coming from the right e-mail address, the domain is slightly wrong or something like that, the name is wrong. You really should be sure that you’re replying to an e-mail from sender who you really know. And so you’re dropping that onto the desktop. There’s a desktop and there’s the content appearing. But this is really interesting because it means the content comes to you.

And so it’s very, very easy to engage with it. And what we found fascinating about this is that it’s actually quite passive. So it doesn’t force you to look at it. But that is quite a fundamental psychological principle that if you give people a bit more autonomy, then they’re actually more likely to do something and maybe do what you want them to do because they got the choice. It was up to them whether they did or they didn’t, but generally they do and we get 80% engagement month on month. When you’re running a campaign, you might start week one with that sort of content. Then week two, when I use the particular tool that’s relevant.

In this case, going into my e-mail, watching out for phishing is fundamental. We’re just setting up this idea that, look, we’re priming you again as you go into your inbox, but also we’re going to start nudging you and it’s going to start looking like this. Then of course, I don’t think this e-mail was written by someone who was using an AI tool to make it absolutely perfect because I don’t think any of us would click on this one. But if I was to, then maybe this is a point where we help someone to go, look, I know this looks absolutely legitimate, but actually you’ve never had an e-mail from this person before.

If it was really HR, you probably would have an e-mail from them before. This is not an e-mail address you recognise. Let’s just wake you up to that fact. And obviously if I’m really cyber savvy I’m just going to be yeah yeah I knew that I’d already checked I’m not going to click on this and that would be a nice pat on the back and embed that behaviour. But actually if I was on autopilot this could be the point that nudges me away from that risky behaviour at the point of risk. Sometimes people do click those links and then they get to the next step and they start to enter their password.

Threats exist outside of e-mail. We end up in the browser, we could be on the desktop, we could be plugging in USBs, connecting to insecure Wi-Fi. It’s really important to be able to track some of these behaviors across a whole load of areas. In this case, once I actually get to the browser, maybe that intervention to say, look, you just clicked a link from someone you don’t know and now you’re giving away your password. So fundamentally behind all of this you want to understand the data and see what’s going on. So I’m not going to go into these in huge detail, but obviously what you want to start to see is where does my risk lie?

and which of my users are proving to be high risk. That snapshot of all my users and a bunch of behaviours that I’ve selected, how many people are high risk users. Then I might want to be able to dig into that, start to see the breakdown, who’s in the green bit on the left, who’s in the red bit on the right, how many behaviours and which behaviours am I interested in. Then of course, what you want to be able to do is really target those people. Let’s select that bucket of people who’ve been high across all these different events. They’ve reached that threshold to say, look, I’m quite concerned about these people.

They’re doing this behaviour a lot. It’s not necessarily always risky, but if they are very high clickers in emails from people they don’t know, then they are more likely to fall for some of these risks. We might want to put them in a campaign or a group that assigns them a new campaign to push a bit deeper on a particular behaviour. And then, of course, when you’re running a campaign, you want to see your impact. What we feel is really important is to run some sort of baseline, because if you’re going to understand that you’ve changed behaviour, you need to know what the behaviour was beforehand. So we will often baseline a behaviour with a tracker to say, well, how often does this thing happen before I start my campaign?

And then you can see each of the points in here where the campaign starts and the bits of content get dropped, and you can see what impact you’ve had between different points. Once you stop nudging, what happens afterwards? Does the behavior go back up or does it sort of stay plateaued at a lower level? And then in individual campaigns, you might want to delve a bit deeper into like, what’s my change? What’s the impact I’m having? Who are the users who are changing? Who are the users who aren’t? So putting that into some final thoughts and some interesting quotes from Gartner on the left hand side. Shadow IT around and shadow AI is a risk to some degree.

It’s just increased that attack surface. It’s the same old risk, it’s the same DLP risk, but we really don’t understand where the data is going. And I think that makes us quite unsettled. We don’t know where the data is going, we don’t know how it’s going to be used. And so we’re really quite concerned how we how we manage it. So AI is fundamentally a mixed blessing. It’s a fantastic enabler for us, and it’s an enabler for the security team is efficiency as well. And so sort of obviously the next step of seeing these things are going to be fantastic tools that are going to be helping your human practitioner build those campaigns and get those campaigns out to the right people as quickly as possible.

So it’s a great efficiency driver for us, but it’s also a great efficiency driver for the bad guys. So the AI threat splits into two, I think. It’s that kind of so much better at doing the old stuff, but also a whole bunch of tools that we don’t really understand and that we now need to start to govern. And so that highlights the need for visibility. and tooling to actually enforce that governance. Let’s see people doing something and let’s steer them in the right direction. And to me, that therefore remains a behavioral challenge. We still need to get telemetry and understand who’s doing what. We need to be able to distinguish, are people using sanctioned or unsanctioned tools?

We need to get in there while they’re using those tools and start to embed the risk approach that we want to embed across all our tools and we’ve always wanted to do. And by being in the context you can do that so much more effectively and not just nudge people, but also boost them. Give them the understanding of what they’re doing and why they should be doing it, because I think that’s a really important aspect of this. If you found this interesting. We do have a deep dive AI governance pack. So there’s the behavioural impact report and we’ve got a new one pager on the AI behind all of this.

So please do take a shot of that. And I think we’ll be putting a PDF in the chat that you can take away. But I just jump back to John and we can pick up if anyone’s got any questions.

John Scott: Hey, Tim, thanks very much for that, as always. Absolutely fascinating. There’s a question that Leon’s put in the chat, but we have got plenty of time. So I’m going to use guest chair’s privilege here and go for a bit of a callback. You mentioned and you knew that I would absolutely agree with you that this sort of punitive approach to behaviour change is just ultimately it’s not effective. So why is it so persistent?

Tim Ward: I don’t know. Actually, it’s quite interesting. I was chatting to someone in the military context and apparently one of the high up generals and said, can’t we just order people not to do it? Why didn’t we think of that? Damn it all this time. Why is it so persistent? I think it’s that. It’s the easy stock answer, I suppose, in a hierarchical organisation, maybe, that you tell people to do something, you order them about. I think there’s a kind of lay approach, and it’s a challenge with mental models I’ve talked about in the past about this idea that if you do get it, then you don’t really understand why other people don’t get it.

But that’s not always true with the CEO, is it? I mean, all the kind of the bosses of the company, they might not be cyber people, but they still quite often still have this consequences culture. I’d like to think it’s shifting. I don’t know whether you’re seeing that. I think people are trying to get away from consequences culture.

John Scott: Yeah, I think so, because I think if nothing else, and your point where they said, why don’t you just tell people to do the right thing? I’ve had that quoted to me directly in a bank. to which the answer is because it doesn’t work. So I think almost out of desperation, a lot of people are going, God, we might as well try this soft skills culture thing because nothing else is working.

Tim Ward: I hope it’s out of desperation.

John Scott: Yeah, I think so. I think so.

And also I think there’s a large element of it’s easy. and wrong, that goes to one of your points, which is the make the secure behavior the easy behavior. It’s a lot easier to just tax. someone who makes a mistake. Yeah.

Tim Ward: Well, and I think it’s interesting because fishing sims did sort of originate out of America. You can sack someone, a whim in America. And so, but not still, not everyone there has a consequences culture. I think the more enlightened organisations are shifting towards, okay, look, we care about our staff and therefore we need to do something that’s in line with that in terms of helping them. I’m still very frustrated and that’s a whole other talk about kind of governance and compliance approaches which sort of allow people to get away with the bare minimum. Oh, we’ve trained them, we’ve done a sim, therefore we’ve ticked that box and that is a problem until we can tackle that, I think.

John Scott: And I think there’s a, I’m just mentioning to SASIG, there is possibly an open chat between you and me about just as much as we sort of kick back into people saying awareness doesn’t work, we say, well, no, bad awareness doesn’t work. I think bad compliance doesn’t work. And there are people out there who are doing good compliance. I’m going to come on to the questions now. But the final thing I’ll say, just because literally I was having this chat with a large telco in Australia last night. I think more and more we’re seeing people organizations understand that people who are working from a place of psychological safety work better. And that includes you can’t have the punitive culture. So I think it is shifting and I think that message is getting across and about time.

Tim Ward: Just to pick up quickly on that, and I think it’s an interesting challenge that I heard from a very despairing CISO who was actually worried about kind of world stability is that AI could get to a point you is driving social unrest. And I don’t want to be the doom on go and it might not happen. But if we’re already seeing big banks have sort of sweeping, well, we’re going to lose 20,000 people from our operational staff because we simply don’t need them because the AI does it, there are going to be some pretty peed off people out there. And that’s going to lead to both insider threat, but also people living under fear at work.

And so that psychological safety is going to be more of a challenge. which we don’t want to add to that by the fact that the security team also being really annoying and trying to scare people.

John Scott: I’m going to mention a couple of comments because I think they’re really key, but we have got questions, guys, and I’m going to ask those. So Helen said, if you work in a safety-focused organisation, there tends to be a just culture which leads to be able to convince people to report every time. Absolutely, Helen. I think that’s exactly where all my research has come from. It’s looking at people like James Reason and looking at just and secure cultures, just and safe cultures. And then Elizabeth, you say sacking people for making mistakes is ridiculous, but there are always people who are reckless, negligent, etc. Absolutely agree. But a just culture is about everybody gets what they deserve. So the people who are negligent, you know, that doesn’t mean don’t sack them. And your point about People doing the right thing, see no consequences for other people, lowers morale. Absolutely. It has to be fair.

Tim Ward: Well, it’s about understanding it, isn’t it? Because I think you might find there’s some people who’ve clicked three times, they’ve failed every one of your sims. And there’s an absolutely legitimate reason for that, that the organisation has made them overworked or that they’ve got something terrible going on in their home life and that person needs help and support. They don’t need sacking. And that’s a fundamental kind of HR thing. It’s a kind of a good organisation should be on top of that stuff anyway.

John Scott: And it’s the health and safety thing, right? It’s the how much of this is how much of that clicking is a product of its environment, not a product of the individual, you know, which is, you know, are they in a call centre where they’ve got to deal with 20 emails a minute or whatever it is? Right, so I am going to go to questions though, because otherwise it’s just me and you talking and as fun as that is. It’s not fair. So Leon said, how do you see behavioural and nudge theory apply to AI agents behaviour?

Tim Ward: That’s interesting, isn’t it? Because I’m not entirely sure that’s the way to solve AI agents. I think that’s its initial guardrails, setting up the guardrails so that their scope is managed in the first place. I’m not sure. how effective it could be to try and nudge them. I mean, obviously the sort of the nudges and the telemetry are tracking a thing happening on a device. So whether that’s a human doing it or an agent doing it, that’s absolutely sort of something. But I’m not sure the degree to which I mean, AI has its own sort of cognitive biases and in its own right. But I’m not entirely sure how susceptible to nudging they’ll be. I think you’re actually kind of better off setting up the guardrails in the first place.

John Scott: I would agree. I think especially when you’re talking about AI, we talk about them learning. They don’t learn. It’s it is a statistical analysis each time and the guardrails are just I’ve come to this conclusion. Don’t do that. So.

Tim Ward: Yeah, and that’s where all the scary stuff about them doing sort of weird things and going off and kind of and all those kind of dark films about what they might do to come some, isn’t it? And I think they will just try and solve a problem any way they possibly can. So you’ve got to build into it so that it won’t go that way. Sometimes, because I mean my background is in IT and shadow and in organizations and shadow IT has always been a nightmare problem because you want to enable your business, you want innovation, but you also need to manage the security side of it. Where AI goes is that no one really understands how these tools work. It’s a black box. And so there’s shadow IT on stairways again. But it’s the same problem to solve. It’s a governance problem and a guardrails problem.

John Scott: Yeah. And we went from shadow IT to shadow cloud to shadow AI. it will always be people see a central service as a blocker and they want to innovate or they want to, I’m going to come back to, I can’t remember whose question this was. It was Azida’s. Are there any functionalities to track the actual activities of the employees when they use AI via the browser?

Tim Ward: Yes, yes. So what we would want to be tracking is upload, download, cut and paste. So the priming nudges are there almost to kind of like when you get to a page like that, just set up a bit of a kind of think about risk, think about policy, and then you have a deeper level of nudge that’s going, oh, right, now you’re here and you just click to add a file. We might want to intervene at this point and say, please don’t upload any commercial data or here’s a reminder of our data classification or in fact we don’t want you uploading data here, please go to this one. And so yeah, so you’re looking at that deeper level and then of course your downloads as well.

Have you gone to the core bot site and you’re on the download dialogue? So absolutely, yeah.

John Scott: Yasmin, hi Yasmin, says, hey Tim, where do you think the balance is between improving the governance and setting out expectations and applying behavioural nudges? I guess before and during really.

Tim Ward: Yeah, I mean, I suppose I see nudges as, and I am obviously biased, but as the most effective way of setting out that governance and expectation, because I think, yes, you might have a policy document you send to everyone. Yes, you might get them in a room and run a PowerPoint presentation, or I don’t know, you might put it in e-learning. That’s great and it’s foundational. But you’ve just got to be realistic about how much of that’s going to be remembered X months later. We’ve all attested to policies having skin read them. I mean, look, we’re all on our iPhones or our Android devices. God knows what I’ve agreed to. And so I think that’s where the nudges come in to just really short and punchy of kind of like, here’s a reminder. Our policy says don’t upload corporate data to this site. and you need that. But you can do it in a really soft and gentle way.

It doesn’t have to be aggressive kind of don’t do that, don’t do that. It can be quite a gentle guidance. We work hard at making our nudges incredibly easy to dismiss, which seems a bit sort of counterintuitive. But there’s a level where some of these things, just seeing on our Check the Sender campaign, after the second week, the message checked the sender, even if you close it in one second, you’ve been primed whether you like it or not. It’s like a Devon Brown type thing, isn’t it? And you will therefore be more likely to be just in the back of your mind, phishing is now a thing.

John Scott: Yeah, And it’s, that’s the lesson from branding, isn’t it? You get brand activation. If I showed you a particular shade of red and a curve of yellow, 95% of people would understand which fast food restaurant that was, even if it wasn’t, you don’t need very much. Great question from Ian again, great presentation Tim. Have you had much pushback from German workers councils on monitoring employees or what approach would work best in getting approval?

Tim Ward: Yeah, great question, Ian. It can be challenging. I think it’s why, there’s a couple of routes down to this. One is starting by anonymizing. So you can do this approach and anonymize everything and still get quite interesting macro level data. You could then delve a little bit deeper and have some metadata that says, well, I don’t know who you are, but I know what department you’re in. And you can still sort of, if you’re We tend to anonymize with a one-way hash that means we still have a group of people who are the ones who are risky and we can track all the behaviors that risk imposed. We don’t know who they are, but it still means we can then put them in a group with a bunch of other people to say, right, we’re worried about these behaviors.

Don’t know who you are, but I’m going to still intervene and nudge and steer. What we’ve tended to do in Germany is often start like that with fully anonymized. But also get people on board by getting them to see the tone of voice and the approach. Now, when I do a demo, obviously it looks like there’s nudges all over the place, but it’s really very subtle. And the tone of voice should be very much about we’re here supporting you. And we’ve had that feedback with people saying, oh, it’s like having an angel on my shoulder when I got nudged to be careful on ChatGPT. So it’s about the tone of voice.

So we’re here to guide and support you and stop you making a mistake that’s going to impact you. rather than I’m monitoring you. And also it can be quite light touch. If you’re really just looking for risky behaviors, you’re not having to, you’re not scanning the deep level of what’s in the e-mail, what are all the websites you’re going to, you’re just looking out for the risky ones. One of the interesting things is there tends to be a lot more data already in the organization. The web proxy knows every website you went to, so the data’s already there. So this is actually quite like touching in that sense. But obviously, because you’re nudging a behaviour, people can be a bit more.

Oh, it must know I’m doing that.

John Scott: Yeah. And do you know it’s just made me think, especially with Helen’s comment about safety focused organisations. They must, a German factory will still know if someone is making a mistake on the operational side. They’ll, they will have an accident book and so on. So I think there is very much, exactly as you just said, there’s that we assume there’s going to be a confrontation because. And there really isn’t. Yeah. And maybe it’s because the assumption of the workers council is, well, you only do this to monitor us and to make us work harder. And actually, if we take that trust based approach and say, let us show and I think to be a just culture, you have to go first.

You have to say, let us show you why we are not monitoring you like that, exactly as you’ve said. But you can build that trust and you can show people.

Tim Ward: Yeah, absolutely. Yeah. In terms of, I mean, it’s always a concern if you’ve got, but we are deployed in Germany and there were some very sensible workers councils and they don’t just say no to everything. It’s a conversation.

John Scott: Yeah. I think we’ve got time for one last question and someone’s put there. Oh, it’s starting to see thumbs up there. Great. So someone’s someone and honestly said, do you have any tips for simplifying the level of governance or process that needs to be gone through in order to approve AI tools? I find people lose heart or patience going through it, but it is very necessary. And that, of course, is if they lose patience entirely, that’s where you get your shadow IT coming in. And how do we make it easier for people to say yes to new AI tools?

Tim Ward: Yeah. Crikey. I mean, I suppose a structured approach where you’re only asking the questions that really, really matter. And I know we’ve all filled in many, many forms where we get asked things that is kind of, oh, we should put this on the form. What we should ask them this. It’s like, do you really need to know that? And so I think a really focused approach of where does the risk lie? And you can kind of have that as a flow chart because if you’re first asking like, what sort of data is going to go into this? And the answer is publicly facing data. It’s like, okay, well, fill your boots.

Like I don’t care sort of thing. I mean, it’s not that straightforward, but it is that kind of simplistic structure. So you can very quickly focus on the things that really matter to your organization. And I mean, I suppose that is the essence of My thinking about all of this stuff is that you take a behavioural lens and a risk-based lens to your organisation and you worry about the data and the behaviours that really matter to you. And that might not be the same across all organisations. Some people would just block a whole load of stuff so that those threats don’t exist, but there will still be other threats that are fundamental.

So that’s where they focus on behaviours.

John Scott: And I think for me, just based on what you said, one of the things that comes back to is, we always talk about cyber hygiene fixing 90% of the problems. If you have a good structured approach to your data, so you know what your sensitive data is and where it is, that will not only help you with something like bringing on AI, but it will also help you in everything else. Because if you don’t have that structured approach, if you don’t have a mature understanding of risk or where your key assets are or anything like that, how do you know what you’re protecting? Yeah, and that’s why this is a little bit of a step back.

Tim Ward: It’s the same problem we’ve always had. It’s just the tools are even more daunting. But it’s still a DLP problem to some degree. It’s still a kind of behavioural and a, yeah, it’s just the same. It’s just got a bit harder.

John Scott: And I think, you know, in the same way that there are phishing attacks which date back to the 15th century because, you know, the Spanish prisoner, for example, It’s human nature. We need to, you know, nothing new under the sun. I think that’s a really good place to finish it. I’m going to quote a couple of people because I think it’s a really good thing. Simon and Nicholas both said, taking the approach that people sometimes have bad days is a really nice way to frame that. Yes, somebody makes a mistake. As long as they weren’t being malicious, as long as they won’t be reckless, people sometimes have bad days. Let’s work with them to minimize the impact of that bad day.

I think that’s a really nice framing for it.

Tim Ward: Yeah, absolutely. I like Phoebe’s comment as well. It’s kind of like encouraging people to do it properly and not just don’t use it because they don’t use it, it’s not going to work, is it? People will use it whether you like it or not.

John Scott: It’s the flip side of, well, we told them to do the right thing and suddenly they’re not doing it. It’s like, yeah, we told them not to use the AI and guess what?
Tim, as always, absolutely fascinating. I love listening to you. I love chatting with you about this stuff because it’s so fundamental to what we do. I hope you can see the huge amount of thank you and applauses in there. To everybody else, thank you for your attendance. Thank you for keeping us right up to the last minute and enjoy the rest of this lovely sunny day. Enjoy your long weekend and we will see you at the next one. Thank you very much.