Why presentation is not proof
The FBI warned in May 2024 that criminals use AI to create convincing phishing messages and voice or video impersonations. That warning does not mean every suspicious message uses AI. It does show why spelling and visual polish are weak foundations for a trust decision.
A familiar display name, logo or voice can accompany an unusual request. Training should help people examine the requested action and verify authority, rather than rely on a single clue.
Practice an independent verification step
NIST’s phishing guidance advises contacting an apparent sender through known contact information instead of relying on the message itself. Build that distinction into a scenario: the number supplied inside a suspicious request is not an independent check.
- Pause when a request changes an established process or asks for sensitive information.
- Use an approved contact directory or a known channel to verify the request.
- Follow your organization’s reporting procedure when something seems wrong.
Broaden the scenario beyond email
In an illustrative exercise, an employee receives an urgent message and then a call apparently confirming it. The learning objective is to keep the approved verification process even when a second channel adds pressure.
ASAT documents separate phishing, smishing, vishing and deepfake simulation capabilities. Choose a relevant scenario with the administrator and review scope before launching. A simulation rehearses a response; it is not a guarantee that every real attack will be detected.
Debrief the decision people made
Ask what made the request feel credible, what interrupted the normal process and whether the employee could find the approved verification route. Use the answers to refine both training and workplace instructions.
The practical goal is a repeatable habit: pause, verify through a trusted route and report uncertainty. Keep that habit consistent across channels.
Sources & further reading
These sources support the background context. The practical planning suggestions are Aspire Tech’s editorial guidance.