Cyber security in an AI world
Three IET experts. Six rules each. Simple ways to spot, stop and verify scams in the age of AI.
AI is changing the way criminals operate. It can generate convincing voices, messages, images and online personas, making scams harder to spot and easier to scale.
What our research tells us
Impersonation attempts are widespread
Around 8 in 10 have received an impersonation attempt from someone posing as a trusted person or organisation.
29% of those who have experienced impersonation attempts receive suspicious calls every day.
26.5% by phone, 22.8% by text and 21.2% by email - the average number of impersonation attempts a month reported by people targeted through each channel.
What makes an approach feel real?
22% would be more likely to trust an approach if the sender knew information they thought only the genuine person or organisation would know.
20% would be influenced by a familiar-looking phone number, email address or account.
13% would be more likely to trust someone who knew about their recent activities
9% would be influenced if the caller sounded like somebody they knew.
Are we prepared?
45% have some confidence they could identify AI-generated or manipulated communications, only 14% are very confident.
Around 1 in 10 have agreed a safe word with family or friends.
28% would end an unexpected call and call back using a trusted number, but only 13% would verify through another channel.
13% have spoken to older relatives about recognising scams.
7% have discussed what to do if someone's voice, number or online account is impersonated.
What are your Cyber 6?
To help people navigate this new reality, we asked three IET AI and cyber experts to share the six rules they believe everyone should follow to stay safe in an AI-enabled world.
Kirsten McCormick
IET member and AI expert
“We’ve entered an era where authenticity can be generated. For centuries we’ve trusted what we can see and hear, but AI can now create convincing voices, images, messages and personas.
"Seeing is no longer believing and hearing is no longer confirmation. That means the skill we increasingly need is verification. Technology can help defend us, but human judgement remains the final firewall.”
Follow the three-second rule
If a message creates urgency, pause before acting. Scammers want immediate reactions.
Never make a major decision in the same conversation
Don't make a major financial, personal or account decision in the call, email chain or message thread where it was requested.
The best time to stop a scam isn't when the phone rings…
It's months earlier, by reducing the information about yourself online that enables convincing impersonation in the first place.
Authenticate the request, not just the person
Ask whether the request itself is reasonable, regardless of who appears to be asking.
Assume voices, images and messages can be spoofed
Familiarity alone is no longer proof that something is genuine.
Hang up and call back
In the AI era, hanging up and calling back should be considered good digital hygiene, not rude behaviour.
Dr Junade Ali
Cyber security expert and IET Fellow
“Scammers can contact people at such scale that inevitably some will be expecting to hear from the person or organisation being impersonated. So don’t rely on the fact that a call feels plausible.
"If someone asks you to do something, verify it independently - hang up and call back using a number you already trust, such as one on the back of your bank card or a bill.”
Use longer, random passwords
Use a password manager to generate long, random passwords for each website.
Set up two-factor authentication
Use two-factor authentication where possible, ideally through a dedicated app rather than text message.
Back up important files separately
Keep important files backed up separately from the computer you work on, such as in the cloud.
Call back using a trusted number
If someone calls asking you to act, hang up and call back using a number you already trust.
Be cautious about urgent requests
Urgency is a warning sign. Give yourself time to check before doing anything.
Check where contact information came from
A number shown by a search engine or AI assistant can still be fraudulent. Check the original source.
Patrick Capaldo
Chair of the IET’s Artificial Intelligence Technical Network
“Very little that we see or hear in the digital world can be trusted on its own anymore, so we all need to be cautiously sceptical. That’s a small extra price to pay for the incredible technology we have access to today.
"It doesn’t mean fearing technology or trying to erase our digital footprints, but understanding what information is out there, what an attacker could use against us, and what we can still use to verify that something is genuine.”
Recognise the extra cost of convenience
Digital tools make our lives easier, but there is a trade-off between convenience and privacy. The more of our documents, photos and communications we digitise, the greater the risk that information could be used in ways we didn’t intend.
Know your digital footprint
Your digital footprint can be seen and used by attackers. Know what information about you is publicly available, set limits on what you’re happy to share and stick to them.
Real-world memories are king
Never has it been more important to remember the real-world, non-digitised memories and experiences you share with the people important to you. These can help you verify the identity of someone you know online.
Share AI and cybersecurity developments with others
AI and cybersecurity move fast, and attackers rely on people being unaware of the latest methods. Share useful news and examples with the people important to you. A family WhatsApp group, for example, can help everyone (including older relatives) stay aware of new threats.
Use multi-factor authentication beyond your accounts
If something feels odd, verify it another way.Call someone, ask a mutual contact or check another trusted source.
Create a family safe word
Agree a private word or phrase that family members can use to verify identity in an unexpected situation. Agree this in person.
More cyber security tips
Online safety and privacy
- Be cautious of phishing and social engineering – verify links, emails, and messages
- Limit app permissions to reduce access to personal data
- Avoid sensitive activities on public Wi-Fi – use a trusted VPN if needed
- Secure devices with auto-lock, strong passcodes, or biometric authentication
- Monitor accounts for unusual activity and enable login alerts.