
Attackers do not always need to break through a firewall or discover some sophisticated technical vulnerability. Sometimes they only need one person to trust the wrong message.
For a few years, part of my job was making sure billions of dollars moved without anything going wrong. When you work on systems like that, security stops being something abstract and becomes very real. A small mistake can have a serious consequence. A bad configuration, a compromised account, or someone making the wrong decision at the wrong moment can affect real customers and move real money. Unlike a broken feature on a website, some mistakes cannot simply be patched and forgotten.
That experience changed how I think about cybersecurity. The more time I spent around secure systems, the more obvious it became that organisations can spend heavily on infrastructure, applications and network security while still leaving one of the most important parts of the business exposed: the people using those systems every day.
Attackers do not always need to break through a firewall or discover some sophisticated technical vulnerability. Sometimes they only need one person to trust the wrong message. It might be an email that appears to come from a senior executive, a Microsoft 365 login page that looks almost identical to the real one, a request from someone pretending to be in HR, or an invoice that arrives at exactly the right time. The technical part of the attack may be simple. What makes it effective is that it understands how people work, how businesses communicate and how easily trust can be used against someone.
That problem is becoming harder because the quality of these attacks is improving. There was a time when many phishing emails were relatively easy to recognise. The spelling was poor, the wording felt strange, the branding was wrong and the request itself was often obviously suspicious. That is no longer something organisations can rely on. Attackers can now research a company, understand its people and suppliers, study the language it uses publicly and create convincing messages quickly. AI has made that process even easier. A phishing email no longer has to look like a phishing email. It can look like something an employee was genuinely expecting to receive.
This is where I think the traditional approach to cybersecurity awareness starts to fall apart. For years, awareness training has often been treated as a compliance exercise. Employees complete a course once or twice a year, answer a few questions and the organisation records that the training has been completed. That may satisfy a policy requirement, but completion is not the same thing as preparedness. Someone can finish a training module and still struggle when a convincing social-engineering attempt arrives three months later during a busy working day.
Security behaviour has to be developed through practice. People need to experience realistic situations in a safe environment, make decisions, understand where they went wrong and become more familiar with the techniques attackers actually use. The objective should not simply be to tell employees that phishing exists. Most people already know that. The objective should be to help them recognise increasingly sophisticated attempts when the pressure, timing and context make those attempts believable.
That is the problem we are working on at Encrisoft.
Encrisoft is being built to help organisations understand and reduce human cyber risk. A central part of that is realistic phishing and social-engineering simulations that reflect the kinds of situations employees could genuinely encounter. Instead of relying only on generic awareness material, organisations can expose employees to practical scenarios, identify where the weaknesses are and provide training based on actual behaviour.
The simulation itself, however, is only one part of the problem. Sending a phishing email and recording who clicked it is relatively easy. The more important work is understanding what that behaviour means. An organisation should be able to see whether certain employees repeatedly respond to urgency, whether particular departments are more exposed to certain types of social engineering, whether people are improving over time, whether suspicious messages are being reported, and whether training is actually changing behaviour rather than simply producing another completion certificate.
That is where I believe cybersecurity awareness needs to go. Organisations need to move away from measuring activity and start measuring risk. Knowing that 95% of employees completed a course tells you very little about whether they will recognise a convincing attack. Understanding how people respond to different threats, how that behaviour changes over time and where additional training is required gives a much more useful picture.
Encrisoft AI is part of that approach, but I am careful about how we talk about AI. I do not think adding AI to a product automatically makes the product better, and cybersecurity already has enough products carrying an AI label without explaining what useful problem the technology is actually solving. For us, AI should have a practical role. One example is helping teams generate realistic phishing simulations more efficiently instead of spending hours writing scenarios manually. Over time, it can also help make simulations, analysis and training more relevant to the organisation using the platform.
The goal is not to build a product that sounds impressive in a pitch deck. The goal is to make organisations better prepared for the attacks their employees are likely to face. If Encrisoft can help a company understand where its people are vulnerable, train employees using realistic scenarios, identify whether behaviour is improving and make that capability accessible without requiring a large internal security team, then we are solving something that actually matters.
Accessibility has always been an important part of how I think about this problem. Large organisations can afford several security products, specialist teams, consultants and dedicated awareness programmes. Smaller organisations usually cannot. A company with twenty, fifty or two hundred employees may still handle payroll, customer information, sensitive documents, payment details and privileged accounts. It still has people who can be targeted through email, messaging platforms, phone calls or impersonation. Attackers do not care whether that business has a large security budget.
That creates a strange imbalance. The organisations with the greatest resources are often the ones with the most sophisticated protection, while smaller organisations are expected to defend themselves against many of the same techniques with a fraction of the people and budget. They do not need watered-down enterprise software or another complicated dashboard. They need security tools they can realistically operate, understand and act on.
That is what we are trying to build with Encrisoft. We are still early, and there will be things we learn, assumptions we change and parts of the product that become very different from how we imagine them today. I would rather be honest about that than pretend every decision was obvious from the beginning. Building something useful usually involves discovering that a few of your clever ideas were not nearly as clever as you thought. Software has a charming way of providing that education.
What feels much clearer is the direction of the problem. Technology will continue to improve, and attackers will continue to take advantage of that improvement. AI will make it easier to create convincing emails, websites, documents, voices and identities. As those attacks become harder to distinguish from legitimate communication, the ability of ordinary employees to recognise suspicious behaviour will become more important, not less.
For years, people have been described as the weakest link in cybersecurity. I think there is something wrong with repeatedly calling people the weakest link while giving them the weakest tools and the least realistic preparation. If human behaviour is such an important part of security, then organisations should treat it with the same seriousness they give to their technical controls.
That is the problem I want Encrisoft to work on.
I will use this space to write about what we learn while building it, how human cyber risk is changing, the techniques attackers are using, where I think the industry is getting things right and where I think we are still pretending old approaches are working better than they really are. I also want to write openly about the decisions we make as we build Encrisoft, including the ones that do not work as expected.
I do not want this to become a stream of polished company announcements. There are already enough places on the internet where every product update is apparently “revolutionary.” I would rather use this space to document the work properly and explain why we are building what we are building.
Because if someone is eventually going to try to deceive your employees, I would rather they had already seen something more convincing from us first.

