Attackers don't hack your systems. They hack your decisions.
CEO fraud, fake IT support, cloned voices, changed bank details: the attacks that succeed bypass your tools by targeting one person deciding alone, fast and under pressure. Our method: cognitive controls.
A cognitive control is a verifiable rule that neutralises a manipulation, wherever one person decides alone and under pressure.
The problem isn't what your teams know. It's what they do under pressure.
Classic training barely moves the needle.
Across 19,500 employees followed for eight months, training embedded in phishing simulations reduced the click rate by only 2%, and mandatory annual training showed no significant effect.
Ho et al., IEEE Symposium on Security and Privacy, 2025.
Knowing how to spot it is not enough.
Our pre-registered randomised controlled trial, run with 502 participants, found no effect of awareness alone. We published it because it grounds our method.
Académie Nexus, pre-registration DOI 10.5281/zenodo.20403018.
What stops the attack is a rule.
In the publicly documented deepfake CEO frauds, what stopped the attack was never detecting the fake. It was a verification outside the channel under attack.
The documented cases (in French) →Five psychological levers, five cognitive controls.
Every attack on people relies on a handful of mechanisms. Each one is neutralised by a simple rule, written into your procedures and verifiable in an audit.
| Lever | What the attacker says | The cognitive control |
|---|---|---|
| Authority | "This is the CFO, I'm in a meeting." | Any sensitive request from an executive is confirmed through a channel already known, never the one the message came from. |
| Urgency | "It has to be done before 5 pm." | Above a written threshold, a pause rule applies, whatever the urgency claimed. |
| Familiarity | "You know my voice, it's me." | A voice or a face is never authentication: a verification question or a call back on a known number. |
| Emotion | "Your account will be locked within the hour." | Any lock-out threat goes through the official internal support, never the link or number received. |
| Isolation | "It's confidential, don't tell anyone." | The right, and the duty, to tell a second person is written down for every sensitive operation. |
Four steps, each with its deliverable.
Map the exposed decision moments
Wherever one person decides alone, fast and under pressure: payments, bank-detail changes, access resets, requests from management, recruitment. Interviews with the teams concerned and a review of procedures.
Format : Two days of interviews and a workshop
DeliverableA map of exposed moments, ranked by severity.
Install the cognitive controls
For each exposed moment, a verifiable rule: second channel, pause, thresholds, verification question, the right to speak up. Written with your teams to fit into your security management system.
Format : One 3-hour workshop per process
DeliverableAn auditable register of cognitive controls.
Train decisions under pressure
Realistic simulations: a call with a cloned voice, a fake executive on a messaging app, fake IT support. Then a review of the levers pulled and the control that should have applied, never putting anyone at fault.
Format : Half a day per team
DeliverableA collective debrief and adjusted instructions.
Measure what matters
Not just the click: controls applied, time to verify, number of reports, requests rightly refused.
Format : Measurement points at three and six months
DeliverableA human-factor dashboard.
For your executives
Executives are the first identities impersonated and the first targets. A 3-hour module for management bodies: how they are manipulated, which controls to approve, how to track their application. The NIS2 directive (article 20) requires the management bodies of covered entities to follow training; its French transposition is under way.
Who it is for
- CISOs and security teams who want to treat the human factor as a risk, with controls.
- IT departments, executive management and leadership committees.
- Risk, compliance and finance functions exposed to fraud.
- Human resources, for recruitment and onboarding.
Are you a cybersecurity company wanting to offer this to your clients? We deliver it with you.
What sets us apart
- A method grounded in research, including our own published negative results.
- Doctoral research on the mechanisms of information manipulation: the same levers, at the scale of a society.
- A training organisation: the programme fits into your skills development plan. The quality certification was issued for the following category of actions: training actions.
- Three working languages: French, English, Arabic.
What this programme is not
Not a phishing-simulation platform.
It complements one: the platform measures the click, we install the rules that protect the decision.
Not employee surveillance.
Simulations are designed with your staff representatives and debriefed without sanctions.
Not technical training.
No IT skills are required from participants.
Download the full presentation.
Two pages: the five levers and their controls, the four-step method, the executive module, the proposed pilot. The download link arrives by email.
