The More Convincing the Threat Becomes, the Harder It Can Be to Recognise

Estimated reading time: 7 minutes

The more convincing a threat becomes, the harder it can be to recognise.

Security awareness needs to move beyond spotting suspicious emails and toward helping people know when to stop, question and verify.

October is Cybersecurity Awareness Month, and this year the first theme is one that affects every organisation regardless of size, sector or maturity: phishing and social engineering.

The challenge is no longer simply identifying an obviously suspicious email. Social engineering can use trusted names, familiar organisations, urgency and publicly available information to make a request appear entirely legitimate. A recent AUSTRAC warning illustrates the point clearly. In August 2026, AUSTRAC CEO Brendan Thomas warned the public that scammers had been impersonating the agency and its staff, using real employee names and job titles, and moving conversations to messaging platforms such as WhatsApp to create a sense of personal credibility.

This creates a wider question for every organisation. What happens when people cannot easily tell whether a request is genuine?

Sources: AUSTRAC, AUSTRAC warns scammers impersonating agency and staff, 26 August 2026. Full citations in the References section below.

Threats Are Becoming More Convincing


Traditional phishing relied on volume. Poorly written messages sent to large numbers of recipients, hoping a small percentage would respond. The signals were often easy to spot: misspellings, unusual formatting, unfamiliar sender addresses, generic greetings and implausible requests.

That picture has changed. Social engineering can now be carefully researched, personalised and presented in a way that closely mirrors the legitimate communications people receive every day. An attacker may reference a real person, a genuine organisation, a plausible scenario or a current event. The AUSTRAC impersonation scam is a good example. One scammer claimed to have access to an AUSTRAC investigator and shared a real staff member's name before moving the conversation to WhatsApp. Another pretended to put a person in touch with AUSTRAC's General Counsel.

When the communication itself looks credible, the traditional advice of looking for red flags becomes less reliable on its own.

The more convincing the threat becomes,
the more important it is that people know when to stop, question and verify.

Social Engineering Works by Exploiting Trust


Effective social engineering does not rely on technical sophistication alone. It relies on trust, familiarity and urgency. A message that appears to come from a known authority, that references a situation the recipient recognises and that creates pressure to respond quickly can be far more effective than any technical exploit.

What the Attacker UsesWhy It Works
A familiar name or organisationPeople are more likely to trust a message from someone they believe they know or a body they recognise
Publicly available informationDetails from websites, social media or directories can make a message appear informed and specific
Urgency or authorityA sense that something needs to happen quickly, or that a senior person is requesting action, can override caution
A plausible scenarioA request that looks like a normal business interaction is harder to question than an obviously unusual one

Understanding these patterns helps organisations recognise that phishing is not just a technology problem. It is a human decision making problem, and the defences need to reflect that.

Awareness Needs to Go Beyond Red Flags


Many organisations approach security awareness as training people to identify suspicious messages. That remains valuable. But when the threat itself is designed to look legitimate, awareness also needs to equip people with a different set of responses.

  • Knowing when to pause before acting on an unexpected or urgent request
  • Understanding what kinds of requests should always be verified through a separate channel
  • Recognising that a message can appear credible and still be fraudulent
  • Having clear steps to follow when something feels unusual, even if it looks right

This is the shift that effective security awareness training is built around. It moves the objective from identifying obvious threats to building the judgement people need when a threat does not look like one.

The Organisation Needs to Support the Response


Asking people to stop and question a request only works if the organisation supports them when they do. A person who hesitates over an apparently urgent request from a senior figure needs to know that pausing to verify is expected behaviour, not a career risk.

This is where awareness connects to governance. Organisations need processes that make verification straightforward, that reward caution rather than speed and that do not punish people for questioning something that turns out to be genuine. These are the same governance foundations explored in New Zealand's Cyber Incidents Reveal a Governance Blind Spot, where the gap between having a control and having a culture that supports it can determine whether the control actually works.

The Awareness Test

Could your team confidently answer these three questions?

If I receive an unexpected request that looks genuine, what should I do?

How do I verify a request through a separate channel?

Will the organisation support me if I pause to check?

If those answers are unclear, the awareness programme may be teaching people what to look for without preparing them for what to do when they cannot easily tell.


What Business Leaders Can Learn


Social engineering is becoming harder to spot. Attackers can use real names, genuine organisations, publicly available information and plausible scenarios to make a request appear credible. Traditional red flags are no longer enough on their own.

Awareness needs to build judgement. People need to know not only what a suspicious message might look like, but when to pause, how to verify and what to do when they are unsure. A programme that covers only the obvious threats leaves a gap around the convincing ones.

Process supports people. Verification channels, clear escalation steps and a culture that rewards caution over speed all help turn individual judgement into an organisational defence. Without them, even well trained people can be left unsupported at the point of decision.

The threat landscape is evolving. AI is contributing to more convincing phishing, scams and social engineering, a development highlighted in the NCSC's Cyber Threat Report 2026. The same tools discussed in When AI Stops Waiting for Instructions can also be turned outward, making the messages employees receive harder to distinguish from legitimate communications.

Leadership sets the tone. When senior leaders take awareness seriously, participate in training and treat verification as expected behaviour rather than an inconvenience, that signal travels through the organisation. This is the kind of leadership posture that vCISO advisory often helps establish, connecting the awareness programme to broader governance and risk expectations.

Questions Every Executive Should Ask


  • Does our awareness programme prepare people for threats that look legitimate?
  • Do our people know when to pause and how to verify an unexpected request?
  • Is there a clear process for verifying requests through a separate channel?
  • Does our culture support people who stop and question something that looks right?
  • Are we testing against realistic scenarios or only obvious ones?
  • How would we detect a successful social engineering attempt after it happened?
  • Are senior leaders visibly participating in awareness activities?
  • Who is responsible for reviewing and improving our awareness programme?
  • When was the last time we updated our awareness content to reflect how threats have changed?

If these questions are difficult to answer, the gap may not be in the security technology. It may be in how well the organisation has prepared its people for threats they cannot easily see.

Awareness Is a Continuous Responsibility


Social engineering succeeds because it targets people, not systems. The technical controls remain important, but they cannot replace the judgement of a person who knows when something does not feel right and has a clear path to act on that instinct. Cybersecurity Awareness Month is a useful reminder that this judgement is not built once and left alone. It needs to be practised, supported and updated as the threats change around it.

At SeComPass, we help organisations build cybersecurity awareness into their broader governance and risk approach. Through security awareness programmes, security leadership and governance support, we help leadership teams understand where their people are most exposed, whether current awareness reflects how threats have changed and what practical steps can strengthen the organisation's first line of defence.

Key Takeaways


  • Social engineering is becoming more convincing, using real names, trusted organisations and publicly available information to make threats harder to recognise
  • Traditional red flags are no longer enough on their own when the threat itself is designed to look legitimate
  • Awareness needs to build the judgement to pause, question and verify rather than relying solely on spotting suspicious messages
  • Organisations need processes and a culture that support people when they stop to check, rather than rewarding speed over caution
  • AI is making threats more convincing, which means awareness programmes need to evolve alongside the technology

Cybersecurity Awareness Month

How Prepared Are Your People for Threats They Cannot Easily See?

We explore the governance lessons behind recent cyber incidents in New Zealand and why the gap between having a control and having a culture that supports it can make all the difference.

Read the Article →

We are also marking Cybersecurity Awareness Month with additional resources from our partnership with KnowBe4.

Explore the Awareness Resources →

References


  • AUSTRAC. "AUSTRAC warns scammers impersonating agency and staff," 26 August 2026. austrac.gov.au
  • Australian Signals Directorate's Australian Cyber Security Centre. "Threats." cyber.gov.au
  • Scamwatch (ACCC). "Impersonation scams." scamwatch.gov.au

This article is for general informational purposes only and does not constitute legal, technical, or professional cybersecurity advice. SeComPass recommends engaging a qualified adviser before making decisions based on this content. AUSTRAC's warning describes scammers impersonating the agency and its staff. It does not indicate that AUSTRAC itself was compromised, and the reference should not be read as a claim that every organisation is currently being targeted in the same way.

Jatinder Oberoi

Founder and Principal Consultant at SeComPass, where he helps organisations across Australia and New Zealand strengthen cybersecurity, governance, risk management, and regulatory compliance. With extensive experience in information security strategy, ISO 27001, SOC 2, AI governance, privacy, and virtual CISO (vCISO) services, Jatinder works with executive teams to align cybersecurity with business objectives, improve organisational resilience, and build lasting customer trust.

https://au.linkedin.com/in/jsoberoi
Next
Next

When AI Stops Waiting for Instructions