SimuPhish co-founders Shubh Arya and Hritik Jain explain why continuous behavioural intelligence is essential for building workforce cyber resilience
AI-powered social engineering, deepfakes and personalised attacks are making deception increasingly difficult for employees to detect. Traditional security awareness training alone is no longer sufficient, prompting organisations to adopt continuous Human Risk Management strategies that measure behaviour, identify vulnerabilities and deliver targeted interventions. In this interview, SimuPhish co-founders Shubh Arya and Hritik Jain discuss the changing nature of workforce cyber risk, the Middle East’s multilingual security challenges and how AI, automation and behavioural intelligence can help organisations build measurable cyber resilience.
Interview excerpts
Why must organisations move beyond security awareness training towards continuous Human Risk Management?
Shubh Arya: Traditional security awareness has largely focused on transferring knowledge — completing a course, watching a video or passing an assessment. But knowing what to do and making the right decision when faced with a convincing attack are very different things. Human Risk Management shifts the focus from completion to behaviour modeling. It allows organisations to continuously understand how employees respond to real-world risk, identify where vulnerabilities exist and provide interventions based on actual behaviour. This is particularly important because the threat landscape does not operate on an annual training cycle. Attackers continuously change their tactics, channels and techniques. Organisations therefore need to treat human risk in the same way they treat other areas of cybersecurity: continuously assess it, measure it, identify changes and take action.
“The objective is not simply to create more security-aware employees, but to build a workforce that consistently demonstrates safer security behaviour.”
How are AI-powered social engineering, deepfakes and personalised attacks reshaping workforce cyber risk?
Shubh Arya: AI is changing the economics of social engineering. Attackers can now create highly convincing, personalised communications at a speed and scale that would previously have required significant time and effort. We are moving beyond poorly written suspicious emails. Employees may encounter a convincing message written in their own language, an urgent WhatsApp request appearing to come from a senior executive, or even an AI-generated voice impersonating someone they trust. This makes traditional advice such as looking for spelling mistakes or unusual formatting increasingly inadequate. The challenge for organisations is therefore shifting from teaching employees to recognise a fixed set of warning signs to developing stronger verification and reporting behaviours. Employees need to question context, identity and unusual requests even when the communication itself appears completely authentic. In an AI-driven threat landscape, cybersecurity resilience will increasingly depend on how people make decisions when the traditional signals of deception are no longer obvious.
What cybersecurity challenges are emerging across the Middle East amid evolving regulations and multilingual workforces?
Shubh Arya: The Middle East combines rapid digital transformation with an exceptionally diverse workforce, making human cyber risk particularly complex. In the UAE and across the GCC, a single organisation can have employees communicating in multiple languages, coming from different cultural backgrounds and using different digital channels. A security programme designed around one language or one type of employee cannot adequately reflect that environment. At the same time, governments and regulators across the region are placing greater emphasis on cybersecurity, data protection, resilience and accountability. Organisations therefore need to demonstrate not only that security programmes exist, but that risk is being actively managed. This is why localisation is fundamental to our approach at SimuPhish. We support 75+ languages and build culturally aligned experiences that reflect regional communication patterns and relevant threat scenarios, making adoption natural across your workforce.
“The Middle East has an opportunity to move beyond compliance-driven awareness and become a leader in measurable, behaviour-driven cyber resilience.”
How is AI transforming both cyberattacks and the technologies used to defend against them?
Hritik Jain: AI is accelerating both sides of cybersecurity. For attackers, it dramatically reduces the effort required to create convincing and personalised social-engineering attacks. Content can be generated at scale with perfection, language barriers can be reduced, and technologies such as synthetic voice and deepfakes make impersonation significantly more sophisticated. For defenders, AI provides an equally important opportunity. Security platforms can analyse larger volumes of data, automate repetitive processes, identify behavioural patterns and adapt security interventions much faster than traditional manual approaches. The next phase will increasingly be AI versus AI, where attackers use intelligent automation to identify and exploit vulnerabilities while defenders use AI to recognise patterns, predict risk and respond faster. However, humans remain central to this equation. Technology can provide intelligence and automation, but organisations must also understand how people behave when confronted with increasingly convincing AI-generated attacks.
How does SimuPhish use AI, automation and behavioural intelligence to identify and reduce workforce risk?
Hritik Jain: At SimuPhish, AI is not treated as a standalone feature; it supports different stages of the Human Risk Management lifecycle. AI and automation can help create and personalise realistic risk scenarios, localise experiences across languages, automate programme execution and reduce the operational workload on security teams. The more important layer is what happens after an employee interacts with an assessment. SimuPhish captures behavioural signals and helps organisations identify patterns across individuals, departments, attack vectors and repeated interactions. That intelligence allows organisations to move away from treating every employee identically. Someone who demonstrates higher susceptibility to an urgent voice request, for example, may require a different intervention from someone whose risk is associated with QR codes or messaging platforms.
“The objective is a continuous cycle: assess, measure, understand, intervene and reassess, which turns behavioural data into actionable intelligence that security teams can use to systematically reduce workforce risk.”
How can organisations measure behavioural risk and cyber resilience beyond training completion and phishing click rates?
Hritik Jain: Completion and click rates provide useful data, but neither gives a complete picture of human cyber resilience. Organisations should look at a broader set of behavioural signals: whether employees report suspicious activity, how quickly they report it, repeat-risk behaviour, susceptibility across different communication vectors, departmental risk patterns and how behaviour changes following an intervention. Context also matters. An employee may perform extremely well against email-based scenarios but respond differently to a QR code, SMS, messaging application or convincing voice interaction. A single click-rate metric can hide these differences. Most importantly, organisations should measure change over time. Are repeat-risk behaviours decreasing? Is reporting improving? Are previously high-risk groups becoming more resilient? The goal should be to move from measuring security activity to measuring security outcomes. Training completion tells you that an employee received information; behavioural intelligence helps determine whether that information actually changed how they respond to risk.
Source: Tahawul Tech
