Start of main content

Cyber security in an AI world

Three IET experts. Six rules each. Simple ways to spot, stop and verify scams in the age of AI.

AI is changing the way criminals operate. It can generate convincing voices, messages, images and online personas, making scams harder to spot and easier to scale.

What our research tells us

Impersonation attempts are widespread

Around 8 in 10 have received an impersonation attempt from someone posing as a trusted person or organisation.

29% of those who have experienced impersonation attempts receive suspicious calls every day.

26.5% by phone, 22.8% by text and 21.2% by email - the average number of impersonation attempts a month reported by people targeted through each channel.

What makes an approach feel real?

22% would be more likely to trust an approach if the sender knew information they thought only the genuine person or organisation would know.

20% would be influenced by a familiar-looking phone number, email address or account.

13% would be more likely to trust someone who knew about their recent activities

9% would be influenced if the caller sounded like somebody they knew.

Are we prepared?

45% have some confidence they could identify AI-generated or manipulated communications, only 14% are very confident.

Around 1 in 10 have agreed a safe word with family or friends.

28% would end an unexpected call and call back using a trusted number, but only 13% would verify through another channel.

13% have spoken to older relatives about recognising scams.

7% have discussed what to do if someone's voice, number or online account is impersonated.

What are your Cyber 6?

To help people navigate this new reality, we asked three IET AI and cyber experts to share the six rules they believe everyone should follow to stay safe in an AI-enabled world.

Kirsten McCormick

IET member and AI expert

“We’ve entered an era where authenticity can be generated. For centuries we’ve trusted what we can see and hear, but AI can now create convincing voices, images, messages and personas.

"Seeing is no longer believing and hearing is no longer confirmation. That means the skill we increasingly need is verification. Technology can help defend us, but human judgement remains the final firewall.”

Follow the three-second rule

If a message creates urgency, pause before acting. Scammers want immediate reactions.  

Never make a major decision in the same conversation

Don't make a major financial, personal or account decision in the call, email chain or message thread where it was requested.

The best time to stop a scam isn't when the phone rings…

It's months earlier, by reducing the information about yourself online that enables convincing impersonation in the first place.

Authenticate the request, not just the person

Ask whether the request itself is reasonable, regardless of who appears to be asking.

Assume voices, images and messages can be spoofed

Familiarity alone is no longer proof that something is genuine.

Hang up and call back

In the AI era, hanging up and calling back should be considered good digital hygiene, not rude behaviour. 

Dr Junade Ali

Cyber security expert and IET Fellow

“Scammers can contact people at such scale that inevitably some will be expecting to hear from the person or organisation being impersonated. So don’t rely on the fact that a call feels plausible.

"If someone asks you to do something, verify it independently - hang up and call back using a number you already trust, such as one on the back of your bank card or a bill.”

Use longer, random passwords

Use a password manager to generate long, random passwords for each website.

Set up two-factor authentication

Use two-factor authentication where possible, ideally through a dedicated app rather than text message.

Back up important files separately

Keep important files backed up separately from the computer you work on, such as in the cloud.

Call back using a trusted number

If someone calls asking you to act, hang up and call back using a number you already trust.

Be cautious about urgent requests

Urgency is a warning sign. Give yourself time to check before doing anything.

Check where contact information came from

A number shown by a search engine or AI assistant can still be fraudulent. Check the original source.

Patrick Capaldo

Chair of the IET’s Artificial Intelligence Technical Network

“Very little that we see or hear in the digital world can be trusted on its own anymore, so we all need to be cautiously sceptical. That’s a small extra price to pay for the incredible technology we have access to today.

"It doesn’t mean fearing technology or trying to erase our digital footprints, but understanding what information is out there, what an attacker could use against us, and what we can still use to verify that something is genuine.”

Recognise the extra cost of convenience

Digital tools make our lives easier, but there is a trade-off between convenience and privacy. The more of our documents, photos and communications we digitise, the greater the risk that information could be used in ways we didn’t intend.

Know your digital footprint

Your digital footprint can be seen and used by attackers. Know what information about you is publicly available, set limits on what you’re happy to share and stick to them.

Real-world memories are king

Never has it been more important to remember the real-world, non-digitised memories and experiences you share with the people important to you. These can help you verify the identity of someone you know online.

Share AI and cybersecurity developments with others

AI and cybersecurity move fast, and attackers rely on people being unaware of the latest methods. Share useful news and examples with the people important to you. A family WhatsApp group, for example, can help everyone (including older relatives) stay aware of new threats.

Use multi-factor authentication beyond your accounts

If something feels odd, verify it another way.Call someone, ask a mutual contact or check another trusted source.

Create a family safe word

Agree a private word or phrase that family members can use to verify identity in an unexpected situation. Agree this in person.   

More cyber security tips

Passwords and authentication

  • Use strong, unique passwords for every account
  • Prefer long, randomly generated passwords or passphrases (e.g., three unrelated words)
  • Protect your email account with a strong password, biometrics, and secure device PIN
  • Use a reputable password manager to store and generate credentials
  • Explore password-less options like passkeys, biometrics, or hardware security keys
  • Enable Two-Factor Authentication (2FA) on all critical accounts — use apps or tokens over SMS.

Data protection and device security 

  • Back up important data using trusted cloud services or encrypted external drives
  • Keep software and devices updated to patch vulnerabilities
  • Avoid using unsupported devices that no longer receive updates
  • Set a PIN for your SIM card to prevent account takeovers
  • Set up account recovery options and designate trusted contacts for critical accounts.

Online safety and privacy

  • Be cautious of phishing and social engineering – verify links, emails, and messages
  • Limit app permissions to reduce access to personal data
  • Avoid sensitive activities on public Wi-Fi – use a trusted VPN if needed
  • Secure devices with auto-lock, strong passcodes, or biometric authentication
  • Monitor accounts for unusual activity and enable login alerts.