The attacker no longer needs to know you. AI does that part.
For years, poor language was the most reliable sign of a scam email. That sign is gone. What else has shifted, and why your firewall can’t answer the decisive question.
In the last 7 days, the BSI (Germany’s Federal Office for Information Security) has issued 27 warnings about software that runs in businesses every day.
No world map with glowing trails, but the official warning situation. I fetch it twice a day from Germany’s Federal Office for Information Security and only show what is installed on normal office computers — the rest of the feed is about server libraries and doesn’t affect you.
1
critical18
high5
medium16
newly addedWhat’s affected is what runs at your business
- critical Fortinet
- high Cisco Application Policy Infrastructure Controller
- high Cisco Nexus und Cisco NX-OS
- high GitLab
- high Cisco License On-Prem
- high Cisco Meraki (MR, MS und MX) und IOS XE
- high VMware
- high Veeam
- high SonicWall
- high Android 2 warnings
- high Microsoft 365 and Office
- high Google Chrome and Microsoft Edge 2 warnings
Source: BSI, Warning and Information Service (CERT-Bund). As of 08.10.2026, 18:00.
The warnings come from German-language sources and are shown in the original.
And this is already being attacked
A vulnerability is one thing. These ones are demonstrably being exploited — the US cybersecurity agency keeps a public catalogue of them, and its own federal agencies have to act within a deadline.
- exploited Citrix NetScaler
- exploited Fortinet FortiMail
- exploited Cisco Catalyst SD-WAN Manager
- exploited Apple Multiple Products
- exploited Citrix NetScaler
- exploited Citrix NetScaler
Source: CISA, Known Exploited Vulnerabilities Catalog.
This list doesn’t answer one question: whether your accountant will approve the fake invoice tomorrow. Updates close gaps in software. The gap my training addresses sits between a credible request and a click — and no patch closes it.
Attacks took time
Anyone targeting a company had to do research, write texts and rebuild websites. That only paid off for big targets; small businesses slipped through the net.
Attacks cost next to nothing
Research, writing and copying are automated. The same effort that used to be needed for one target now covers a thousand — and so it also hits the craft business with twelve employees.
“Too small and unknown” no longer protects you
Assuming you’re of no interest to attackers was always risky. Now it’s simply wrong, because there’s no longer any target selection that protects you.
What has actually changed
Four shifts, all pointing the same way: attacks are becoming more credible, more personal and more frequent.
Language no longer gives anything away
Spelling mistakes, clumsy grammar, odd greetings: those were the signs we were all trained to spot. Today a language model writes flawless text in the tone of your industry, including the correct technical terms and the right level of formality.
The attack knows your context
Legal notice, LinkedIn, company register, press releases, job ads: publicly available information is enough to know who approves invoices at your company, who’s new and which project is currently running. Nobody does this research by hand any more.
Voice and face are no longer proof
A few seconds of audio are enough for a convincing voice clone, and any video on the company website provides the material. The best-known case: an employee of a large corporation transferred around 25 million US dollars after a video conference in which every participant except him was fake.
Attacks run in steps, not as a single email
First a harmless contact, then a reference back to your reply, then the actual request. Such multi-step sequences used to need a person who kept at it. Today they run on automatically, even over weeks.
Technology can’t decide whether a request is legitimate.
Spam filters recognise patterns: known senders, suspicious attachments, reported domains. A flawlessly written email from a newly registered, inconspicuous domain that refers to a real process at your company and asks for a plausible action contains not a single technical feature a filter could stop it on.
No product answers the question “Is it right for me to approve this payment now?”. A person answers it, under time pressure and between forty other emails.
That’s why awareness isn’t an add-on to technology, but the layer that starts exactly where technology structurally stops.
What technology reliably does
- Intercept known malware
- Block reported senders and domains
- Isolate suspicious attachments
- Log access and keep backups
What it cannot do
- Judge whether a request is plausible in context
- Recognise that the familiar voice on the phone is synthetic
- Stop someone from entering their password voluntarily
- Replace a quick call-back when in doubt
How many vulnerabilities can you spot in an office?
Before talking about training, it helps to feel the problem once rather than have it explained. In “Operation ORION” you walk through an ordinary office and look for the places an attacker would use: the sticky note on the monitor, the open mailbox, the USB stick from the trade fair stand. In five minutes it becomes tangible what can’t be fixed technically and why it’s worth training for exactly that. That’s where awareness training comes in.
Operation ORION, the office game
Take on the role of an investigator and uncover the security gaps at a workstation. A playful start with no prior knowledge needed — also ideal for passing on to colleagues.
Start the game →The real target is rarely the computer
Anyone with login details doesn’t need malware. A hijacked mailbox reads along, knows your processes, replies in ongoing threads and requests further access in your name. To colleagues and customers it looks like you, because technically it is you.
That’s why protecting your own identity is at the heart of my training: passwords, two-factor authentication, handling confirmation requests, and what to do if it happens anyway.
Resilience is measurable, or it’s just a claim.
“Our people are aware” is an assumption. A number showing how many actually click in a realistic situation is a foundation.
For the German economy, becoming resilient here is now a strategic need: with Cybernation Deutschland, the BSI is pursuing exactly this goal — resilience as the normal state rather than a project after an incident. For an individual business that means: know where you stand, improve, measure again.
Free, three simulated attacks, anonymised results.
And yes, it’s also mandatory.
Two laws, one consequence: train and prove it. Many businesses only associate training obligations with NIS2 and consider themselves unaffected. But the GDPR applies to everyone who processes personal data.
Certain sectors above a certain size
The directive obliges management bodies of affected entities to take part in training and to regularly offer training to all employees. Management is explicitly addressed.
Generally affects companies with 50 or more employees or €10 million in turnover in energy, transport, health, water, digital infrastructure, IT services, postal services, waste, chemicals, food and mechanical engineering.
Practically every business
Article 32 requires “appropriate technical and organisational measures”. Training and raising staff awareness are organisational measures; Article 39 names them explicitly.
Anyone who processes customer data, job applications or personnel files is affected. That’s every business.
What must be provable
- That training took place
- Who took part
- When it happened
- That it is repeated
What isn’t documented is, if in doubt, considered not to have happened. With me, all four proofs are created automatically as a by-product of the training.
Five questions, instant assessment.
Obligations check: ISO 27001, NIS2, cyber insurance →