Cybersecurity

Your Employees Can't Spot the Fake Anymore

In 2001, a county health department in Oklahoma hired me to run an independent security assessment. This was right after 9/11 — government agencies were scrambling to figure out how exposed they were. I walked through the facility, sat down at workstations, and started looking. It didn't take long. I found plaintext credentials stored in files on shared drives. Passwords taped to monitors. Default admin accounts that had never been changed.

The threats in 2001 were crude. Someone had to physically sit down at a terminal or guess a password to get in. Today, the tools are different, but the failure is the same: businesses assume their people will catch the threat. They won't — because the threat stopped looking like a threat.

The Old Playbook Is Dead

For fifteen years, cybersecurity awareness training has leaned on the same advice: look for misspellings, check the sender address, don't click links from people you don't know. That advice made sense when phishing emails were written by someone whose first language wasn't English, blasting thousands of identical messages and hoping someone bit.

That era is over. In 2026, over 82% of phishing attacks are generated by AI. These aren't sloppy mass emails — they're personalized messages that reference your actual vendors, your real projects, and your employees by name. The grammar is flawless. The sender address is spoofed to match someone your team already does business with. An AI can generate thousands of these in minutes, each one tailored to a different person in your company.

And it goes beyond email. Deepfake-as-a-service platforms — yes, that's a real product category now — let attackers generate synthetic voice and video in real time. Criminals are joining Teams and Zoom calls impersonating executives, authorizing wire transfers, and disappearing. They only need to look convincing for 30 seconds. A CFO in Oklahoma City gets a Teams call from what looks and sounds like the CEO, asking to expedite a vendor payment. The voice is right. The face is right. The urgency feels real. By the time anyone questions it, the money is gone.

What This Means for Your Business

If your cybersecurity strategy depends on your employees spotting fakes, you're running a plan designed for 2015 against a 2026 threat. The numbers bear this out: adversary-in-the-middle attacks — where the attacker sits between your employee and a legitimate login page, capturing credentials and session tokens in real time — are up 146% this year alone.

Here's the practical impact for an SMB. A construction company in Edmond with 35 employees gets a phishing email that looks exactly like a DocuSign request from their bonding company. One person clicks, enters their Microsoft 365 credentials, and the attacker now has access to email, SharePoint, and OneDrive. Within 48 hours, the attacker has read enough email threads to impersonate the owner and request a wire transfer from the bookkeeper. Average loss in a business email compromise: $254,000.

That's not a hypothetical number. That's the current national average for SMB cyber incidents.

What Actually Works Now

The answer isn't more training videos. Training still matters, but it's the seatbelt — not the brakes. Here's what moves the needle for a business your size:

Phishing-resistant MFA. Standard text-message codes and authenticator app approvals can be intercepted by adversary-in-the-middle attacks. Hardware security keys (like YubiKeys, roughly $50 per employee) or passkeys tied to a device are the current standard. If you're on Microsoft 365 Business Premium — which runs about $22 per user per month — you already have the conditional access policies to enforce this. Most businesses haven't turned them on.

Conditional Access policies. Block sign-ins from countries you don't do business in. Require compliant devices. Force re-authentication for sensitive actions. These are configuration changes, not product purchases — they're included in licensing you likely already pay for.

Attack simulation training. Microsoft 365 includes a built-in tool that sends simulated phishing emails to your team and tracks who clicks. Running one campaign per quarter costs nothing beyond the time to set it up. The first run usually catches 25-35% of employees. By the fourth run, that drops below 5%. That's a measurable, trackable improvement you can show your cyber insurance carrier.

Verified callback procedures. For any financial transaction over $5,000, require a phone callback to a number already on file — not the number in the email, not the number the caller gives you. This one policy, written down and enforced, would have prevented the majority of business email compromise losses in Oklahoma last year.

The Real Question

Twenty-five years ago, I found passwords on sticky notes in a government health department. The technology has changed completely since then. The underlying problem hasn't: businesses trust that their people and their tools will catch the threat, and they don't verify that assumption until something goes wrong.

The difference now is that AI has made the attacks good enough to fool anyone. Your receptionist, your controller, your VP of operations — it doesn't matter how sharp they are. A well-crafted deepfake or AI-generated phishing email will beat human judgment more often than not.

The businesses that stay safe aren't the ones with smarter employees. They're the ones that built systems where a single mistake can't cascade into a six-figure loss. That's an architecture problem, not a training problem — and it's exactly the kind of work OKC CIO Partners does for businesses across the Oklahoma City metro.

If you're not sure whether your current defenses would catch an AI-generated phishing email, let's sit down and find out — no cost, no pressure, just a straight answer. The discovery call is free and there's no pitch, just whether there's a fit — for businesses across the Oklahoma City metro.

Book a free discovery call
← All articles