
Episode notes
Can defenders keep pace when generative AI gives attackers faster ways to create convincing phishing messages, research targets, and test new attack methods?
In this episode of The Business of Cybersecurity, I speak with Professor Steven Furnell from the University of Nottingham for an IEEE conversation about AI-enabled threats, security awareness, passkeys, cyber hygiene, and the continuing gap between cybersecurity policy and everyday practice.
Steven explains why the current AI contest does not give either side exclusive access to powerful technology. Attackers, however, often gain the early advantage because they use it to create opportunity and set the agenda. Defenders are then left identifying the new behavior, adapting controls, and managing the extra work. Generative AI also removes much of the effort once required to research an organization and produce credible spear-phishing messages, making familiar advice about spelling errors and obvious scams less useful than it once was.
We discuss whether passkeys could finally reduce our dependence on passwords and why adoption will still require technical preparation and clear communication with users. A control may improve security while adding friction, so businesses must consider how authentication, updates, access controls, and other interventions fit into real working routines.
Steven also points to a recurring problem in cybersecurity awareness. Fewer than one in five organizations in the UK Cyber Security Breaches Survey reported staff awareness training in the previous 12 months, according to the figures he discusses. Even where annual training exists, watching a video and answering questions may satisfy a compliance requirement without showing whether an employee can respond effectively when a real incident occurs.
For smaller organizations that find security frameworks overwhelming, Steven recommends Cyber Essentials as a practical baseline. We also discuss secure design, the difficulty of regulation keeping pace with technology, and the Cyber Games Lab activities created at the University of Nottingham. Hacker Whacker and Cyber Defense Dice use play and conversation to make cyber education easier to understand for young people and business audiences.
What would improve security behavior inside your organization, another annual training module or regular opportunities to practice realistic decisions? Listen to the episode and share your thoughts.
