Phishing becomes more credible through generative AI and identity data from leaks, while technical filters increasingly fail—a strategic combination of FIDO2 authentication, frequent training, and high reporting rates is now necessary.
As hybrid work models and regulatory requirements make in-person training impractical, IT leaders are replacing traditional seminars with automated e-learning platforms.
User vigilance is not a suitable defense strategy against AI-generated phishing attacks; instead, organizations should structure their processes by trust levels and continuously review fast paths.
NIS2 requires organisations to ensure security awareness functions in real work situations and does not remain merely theoretical knowledge — a focus on behavioural change rather than compliance documentation.