惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Y
Y Combinator Blog
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
V
V2EX
博客园 - 三生石上(FineUI控件)
Hugging Face - Blog
Hugging Face - Blog
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
罗磊的独立博客
博客园_首页
量子位
雷峰网
雷峰网
GbyAI
GbyAI
小众软件
小众软件
酷 壳 – CoolShell
酷 壳 – CoolShell
D
DataBreaches.Net
H
Hackread – Cybersecurity News, Data Breaches, AI and More
The Cloudflare Blog
IT之家
IT之家
WordPress大学
WordPress大学
人人都是产品经理
人人都是产品经理
Apple Machine Learning Research
Apple Machine Learning Research
P
Proofpoint News Feed
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
博客园 - 聂微东

Fortinet All Blogs

FortiEndpoint Earns Certified Leader Status in the 2026 AV-Comparatives EPR Test | Fortinet Blog From Intelligence to Disruption: Strengthening the Fight Against Cybercrime in Latin America | Fortinet Blog FortiSOAR 8.0 Unites Agentic AI and Automation to Revolutionize Security Operations | Fortinet Blog The Cybersecurity Hiring Challenge | Fortinet Blog Casbaneiro: A Banking Trojan with Distributed Data-Receiving Servers | FortiGuard Labs FortiManagement Cloud: Centralized Network and Security Control for Distributed SMB Operations | Fortinet Blog Fortinet Joins Project Watershed 250 to Strengthen National Water Cybersecurity Infrastructure | Fortinet Blog Fortinet and FIRST: Strengthening Cyber Resilience through Global Collaboration | Fortinet Blog Someone Else Is Using Your AI | FortiGuard Labs The Industrialization of Cybercrime in Africa | Fortinet Blog Join the 2026 SASE Summit: Building Autonomous Trust for the AI Era | Fortinet Blog Defending Critical Infrastructure in the Age of Internet-Connected Facilities | Fortinet Blog Black Hat and DEF CON 2026: When Autonomous AI Became Operational | Fortinet Blog Public-Private Partnership Must Move at the Speed of Cyber Risk | Fortinet Blog Secure by Design: Fortinet’s Continued Commitment and the Work Ahead | CISO Collective From Awareness to Action: Building A Behavior-Based Security Program | Fortinet Blog Multi-Functional Linux Botnet “Evooo1Bot” | FortiGuard Labs Cybersecurity Skills Gap: More Than Just a Workforce Challenge | Fortinet Blog Fortinet Achieves IEC 62443-4-2 Security Level 4 Certification for FortiOS 7.6 | Fortinet Blog QuickFox Supply Chain Attack Used to Deploy FDMTP Implant | FortiGuard Labs From Threat Intelligence to Action: The First Cybercrime Bounty Is Now Live | Fortinet Blog While External Threats Are Driving Security Awareness, Internal Risks Are Growing | Fortinet Blog Canada Signs the UN Cybercrime Convention: Turning Global Agreement into Coordinated Action | Fortinet Blog Expert Density as Strategy: How 2F-IT Built One of Germany’s Deepest Fortinet Practices | Fortinet Blog From Awareness to Action: Helping Organizations Prepare for Post-Quantum Cryptography | Fortinet Blog A Conversation with Crime Stoppers International About Our Shared Cybercrime Bounty Initiative | Fortinet Blog Inside a TrickBot Variant Using DNS Tunneling for C2 | FortiGuard Labs Meeting the European Central Bank’s AI Cybersecurity Mandate | Fortinet Blog The TTF Trap: A Global Campaign of a Low-Detection Lua Loader | FortiGuard Labs Helping Law Enforcement Keep Pace with the Future of Cybercrime | Fortinet Blog
Cyber Attacks Leveraging AI Require Behavior-First Securi...
Melonia da Gama · 2026-07-13 · via Fortinet All Blogs

Artificial intelligence has made cybersecurity awareness more visible across the workforce. Employees increasingly understand that attackers can use AI to make phishing messages more convincing, impersonation more believable, and social engineering harder to detect. Many are also using AI tools to draft content, summarize information, analyze data, write code, review logs, or support daily decisions.

While visibility matters, awareness is not the same as readiness. The operational challenge for security and business leaders is no longer simply whether employees know AI-related cyber risks exist. It is whether they can make the right decisions when those risks appear in real time: when a message looks legitimate, when an AI-generated summary seems plausible, when a tool requests sensitive information, or when an urgent request appears to come from a trusted source.

According to the 2025 Security Awareness and Training Global Research Report, 88% of organizations report that the growing use of AI by bad actors has significantly or somewhat increased employees’ understanding of the importance of security awareness and training. That is encouraging. AI-driven threats are helping employees view cybersecurity as part of everyday work rather than as a responsibility owned only by IT or security teams.

But the same report shows a clear readiness gap. Only 40% of respondents say their employees are highly trained and prepared to identify, avoid, and report AI-based cyberthreats over the next year. Another 58% say employees are only moderately or slightly prepared.

That gap is where security awareness training must evolve. In an AI-driven threat environment, awareness alone does not reduce risk. Organizations need behavior-first training that helps employees apply judgment, follow policy, and respond appropriately when situations are unclear.

AI Makes Familiar Risks Harder to Recognize

Not only has AI created an entirely new category of employee risk, but it also makes existing risks harder to detect. A phishing email may be better written. A fake vendor request may sound more credible. A fraudulent message may be personalized using information from public sources, breached data, or prior interactions. An attacker may use AI to adjust tone, remove obvious grammar mistakes, or imitate the language of a trusted colleague, executive, customer, or partner.

This changes what employees need from cybersecurity training. Traditional warning signs still matter, but they are no longer sufficient. Employees need to understand how AI can alter the cues they have been trained to rely on. They also need practical ways to slow down, verify requests, report suspicious activity, and avoid risky shortcuts.

This is especially important because AI risk is not limited to attacks from outside the organization. Employees are also using AI tools as part of their work. Without clear guidance, they may paste sensitive data into public tools, rely on AI-generated content without review, use unapproved applications, or fail to recognize when AI output introduces business, security, privacy, or compliance risks.

That is why AI security awareness training must focus on behavior. The goal is not just to help employees understand that AI-enabled threats exist. It is to help them act differently when they encounter those threats.

AI Governance Depends on Employee Execution

Many organizations are already taking steps to manage AI-related risk. The report found that 53% train employees on the proper use of generative AI tools, and the same percentage use technologies to monitor or prevent the sharing of sensitive data with these tools. Forty-eight percent have established policies governing AI tool use, and 45% maintain lists of authorized applications.

While such controls are important, they only work if employees understand how to apply them. A policy prohibiting the sharing of confidential data with AI tools is necessary. But employees also need to know what qualifies as confidential, which tools are approved, what information can be used safely, and when to seek guidance. An authorized app list helps reduce risk, but only if employees know it exists, understand why it matters, and consult it before adopting a new tool.

The report also found that 96% of organizations have either adopted or are developing security policies for generative AI applications and other AI tools. The same percentage have established or are exploring methods to test and validate the security of deployed AI and large language model systems.

Those findings point to a broader shift toward AI governance. But governance cannot remain confined to policy documents, legal reviews, or technical controls. It must reach the employees who make everyday decisions about tools, data, content, and communication. This is the execution gap that leaders must address. AI governance reduces risk only when employees can translate it into action.

Behavior-First Training Builds Operational Readiness

AI-related training should not be treated as a single update to an annual awareness module. Risks are evolving too quickly, and employee use of AI tools is expanding too rapidly. Organizations need practical, frequent training tied to real work.

The report notes that many organizations remain in the early stages of managing AI-related risks. For example, only 42% of respondents report having tools to oversee employee AI use. This makes employee cybersecurity training even more important. When technical visibility is incomplete, employees need clear guidance on recognizing risky situations and responding appropriately.

Behavior-first training should center on the decisions employees actually face. That includes identifying AI-enhanced phishing, verifying unusual requests, protecting sensitive information, using approved AI tools, evaluating AI-generated content, and reporting suspicious activity. Short, scenario-driven modules can help employees connect policy language to real decisions without overwhelming them.

Regular, brief training sessions on recognizing AI phishing can be more effective than broad annual overviews. Short updates on approved AI tools can clarify when employees should seek guidance. Scenario-driven modules can help employees understand how to handle customer information, proprietary data, code, contracts, regulated content, or other sensitive material when AI tools are involved.

This approach also improves retention. Employees are more likely to remember and apply training when it is specific, timely, and relevant to their daily responsibilities. A finance employee may need training on invoice fraud and executive impersonation. A developer may need guidance on AI-assisted coding and code review. A sales employee may need examples involving customer data, meeting summaries, and CRM content. A support engineer may need to understand where AI can help and where sensitive logs or configuration details require extra caution. The more closely training mirrors real-world behavior, the more useful it becomes.

Workforce Resilience Requires Judgment, Not Just Knowledge

Security awareness has always depended on people recognizing risk. AI raises the bar because it makes risk harder to see and easier to act on too quickly.

That does not mean employees are the weak link. It means employees are often the decision point. They decide whether to click, report, verify, share, approve, download, summarize, paste, or trust. In an AI-enabled workplace, those decisions carry more weight because attackers can move faster, messages can appear more credible, and tools can blur the line between productivity and exposure.

The strongest security awareness programs help employees build habits that hold up under pressure. They teach users to pause before acting, verify before trusting, protect data before sharing, and report concerns before an incident escalates. They also make cybersecurity feel like part of everyday work rather than a separate compliance exercise.

That is where awareness becomes resilience. AI does not reduce the need for human judgment. It increases the need for employees to know where their judgment matters most. As AI-generated content becomes more convincing and AI tools become more embedded in daily workflows, organizations need training programs that help employees consistently make safer decisions.

Build AI-Ready Workforce Resilience with Fortinet Training

AI governance reduces risk only when employees understand how to apply policies in their daily work. While organizations can implement approved AI tools, data-handling protocols, and security measures, these are effective only if employees consistently make secure choices.

Fortinet Security Awareness and Training (FortiSAT) helps organizations translate AI governance into actionable workforce behaviors. Employees learn how attackers use AI for phishing, impersonation, and social engineering, and they also gain skills to use AI tools safely, protect sensitive data, verify unusual requests, and report suspicious activity.

By combining role-based training with real-world scenarios, organizations can strengthen secure behaviors among employees, minimize AI-related risks, and promote responsible AI use. This strategy fosters a more resilient workforce, enabling organizations to harness AI’s benefits while maintaining strong security measures.

Explore Fortinet’s security awareness and training programs and read the full 2025 Security Awareness and Training Global Research Report to learn how organizations can help employees recognize today’s threats, use AI tools responsibly, and make safer decisions as risks continue to evolve.