惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

V
Visual Studio Blog
A
About on SuperTechFans
J
Java Code Geeks
G
Google Developers Blog
L
LangChain Blog
小众软件
小众软件
宝玉的分享
宝玉的分享
云风的 BLOG
云风的 BLOG
P
Proofpoint News Feed
博客园 - 【当耐特】
IT之家
IT之家
F
Fortinet All Blogs
aimingoo的专栏
aimingoo的专栏
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
阮一峰的网络日志
阮一峰的网络日志
V
V2EX
博客园 - Franky
博客园_首页
雷峰网
雷峰网
Microsoft Security Blog
Microsoft Security Blog
Vercel News
Vercel News
B
Blog
月光博客
月光博客
酷 壳 – CoolShell
酷 壳 – CoolShell

Heimdal Security Blog

Slow is a design principle, not a delay AI adoption that pays off is built around keeping humans in the driver's seat Phishing in 2026. Latest statistics and analysis Shift Browser is signed adware that fingerprints your endpoint before it drops payload 6 ThreatLocker alternatives that should make your shortlist 50+ insider threat statistics for 2026 The Planting Seeds philosophy. Selling into schools takes years, not quarters What the DfE's cyber security update means for multi-academy trusts 9 Proofpoint alternatives. Pros & cons of the leading options Heimdal data reveals MediaArena adware completes persistence before antivirus quarantine finishes How Heimdal grew from a bold idea into a global cybersecurity platform Tools Change. Teach People How to Keep Up The 4 best managed EDR service suppliers (and how to choose) How to choose the best SOC platform in 2026 (and our top 4) MediaArena malvertising: why a quarantine isn't the end of the incident Top 6 Managed Detection and Response Providers Cyber-Aware Customers Are Raising the Bar for MSPs and Other Vendors Cyber-Aware Customers Are Raising the Bar for MSPs and Other Vendors How to scale your patches without scaling your team (the patch wave) AI didn't break patching. It showed us patching was already broken. Heimdal Launches MSP Onboarding Wizard to Help Partners Onboard Microsoft CSP Customers in 2 Minutes How Dynamic Defense shuts an attacker out without shutting down the business Static security has run out of road. The case for Dynamic Defense Breaking the MSP Echo Chamber: The Power of Community How attackers built a RAT on a Windows machine using its own .NET compiler Attacker enables RDP, creates admin, erases evidence in ten seconds Heimdal Survey: Executives Four Times More Confident About AI Risk Than the Teams Managing It Your Next Insider Threat May Be an AI Coworker The OSI Model and Its Two Missing Layers Heimdal® Marks Six Years of Consecutive ISAE 3000 SOC 2 Type II Certification
The risk awareness radar. A superpower every MSP needs to...
Adam Pilton · 2026-08-06 · via Heimdal Security Blog

Most of the cyber incidents landing on our desks these days start with someone believing a lie.

It’s not a brilliant piece of code that causes most breaches. A convincing email, a confident phone call, and a fake sense of urgency can make people hand over exactly what the attacker needs.

Last week I talked to Aran Dharmeratnam about that, although he’s not a cyber security person. He built a career in the physical world, in risk intelligence and private investigations.

The skill sitting at the centre of everything he does would stop half the incidents we deal with. Aran’s superpower is the ability to read people and anticipate their behaviour.

How Aran learned to read people

Aran didn’t learn this skill in a classroom. His first security role was as a door supervisor in Sheffield.

It was very much about learning to de-escalate or prevent trouble from getting in. It was about reading behaviour, reading body language.

Several years later, martial arts training around the world sharpened those instincts he now uses professionally.

That background is exactly why I wanted to talk to him.

While people working in cybersecurity spend their careers thinking about technical controls, Aran thinks about the human sitting in front of a screen or facing down a scammer. How can that person tell if they’re being played?

When clients come to Aran, most are dealing with something that’s already gone wrong. His method starts simply. He listens.

Sometimes it can be the most seemingly minute detail that they give you that’s incredibly impactful.

If the problem goes beyond what he can handle directly, he brings in specialists who can.

But the skill he teaches clients, the one he calls out as his own, is reading third-party deception. In a world where cyber incidents increasingly start with a scam rather than an exploit, that’s not a soft skill. That’s the actual perimeter.

The people doing social engineering aren’t amateurs, so it’s not that easy to recognise it. Aran says:

They can be very good at exploiting vulnerabilities. They can also be very good at doing their own intelligence gathering and looking for weaknesses, looking for gaps.

Human vulnerabilities vs. software flaws

People make mistakes. Aran thinks they’re “always going to have vulnerabilities”, just like software. If any software needs patches to become safer, why not accept the same is true for humans?

Aran locates the real risk in what he calls the grey area between cyber and physical security. His example was simple:

Someone has their phone stolen and then their data gets accessed.

A second version of the same gap is:

Someone reading a stranger’s emails off a laptop screen over their shoulder on a train.

Neither needs a single line of malicious code, both exploit the same flaw, a person not being aware of what’s happening around them.

Aran’s suggestion for patching this kind of vulnerability is training risk awareness.

How to train that radar yourself

So how do you actually build Aran’s superpower rather than just admire it from a distance?

He says training starts before any research or reading. The first thing you need to do is sharpen your own instincts.

Develop your own intuition. The human body’s an incredibly powerful awareness mechanism.

This skill isn’t something exotic that only a few chosen ones can develop. It’s something most people already have but have quietly stopped using.

To reconnect with it, observe the moments that push you to lower your guard. Look for the details that create a sense of urgency or false familiarity. When you get that feeling, treat it as a reason to slow down and dig deeper before acting.

The second half of building that instinct is deliberate exposure. Aran’s advice was to develop a genuine, ongoing interest in security. If you don’t do this already, start reading about emerging threats.

As Aran told me,

The more people immerse themselves in their own security and the world around them, the better they’re going to be.

That won’t necessarily turn them into risk analysts, but it will help them recognise fraud patterns.

Why risk awareness matters more than any tool

None of the above replaces technical controls. But it addresses the part of the attack surface no software update can patch.

If your team and your clients can tell when they’re being manipulated, like an urgency that doesn’t add up, a request that skips the normal process, they’ll be able to avoid a breach.

Even if they won’t become immune to manipulation, risk awareness training can make them quicker to spot it and recover from it.

The technical stack is still the foundation.

But if the incidents we’re seeing are increasingly powered by a lie rather than an exploit, the sharpest tool in the box is the one Aran’s spent his whole career building. It’s the ability to read a person and know when something’s off.

If you liked this article, follow us on LinkedIn, Reddit, X, Facebook, and Youtube.

Newsletter

If you liked this post, you will enjoy our newsletter.

Get cybersecurity updates you'll actually want to read directly in your inbox.

Author Profile

Adam is the Cybersecurity Advisor at Heimdal. With over 15 years in law enforcement, where he served as a Detective Sergeant leading Covert Operations and Cyber Crime teams, Adam transitioned to cybersecurity in 2016. Known for simplifying complex topics, Adam leverages his investigative and communication experience to engage leaders and end users alike, driving stronger cyber resilience.