Académie Nexus

The risk missing from your risk map.

Deepfake CEO fraud, smear campaigns, forged press releases, influence operations: these incidents cost money, can be prevented and can be measured. A programme for risk managers, and a ready-to-integrate offer for the insurers, brokers and prevention platforms that support them.

A complete risk category, ready to integrate into your offer.

Your clients already trust you with their climate, cyber and geopolitical risks. Information risk is handled with the same logic: measure the exposure, train the teams, prevent through controls, respond with a protocol. We supply all four building blocks.

Train

Modules for your academy

The six modules of the programme below, deliverable as webinars, e-learning modules or workshops, in French and English, in Arabic on request. Delivered to your clients under your brand or co-branded.

Measure

A published country indicator

The Epistemic Security Score, a composite index of structural information resilience, computed for the twenty-seven EU member states and published with a persistent identifier. A complementary layer to your geopolitical risk analysis.

Prevent

A controls review

A grid of verifiable controls to run with your clients like a prevention visit: a designated decision-maker and deputy, a written alert chain, a second channel for sensitive requests, thresholds for any public response.

Respond

Expertise on call

In-house masterclass, crisis simulation, the first-24-hours protocol and support in qualifying an incident, for the clients who need it.

Integration models: content licence for your academy, per-engagement delivery to your clients, listing as a partner. The content and method are ours; the client relationship stays yours.

Download the full presentation

Not just a communication issue.

It costs money, directly.

In January 2024, an employee of Arup's Hong Kong subsidiary made fifteen transfers, about 25 million dollars, after a video call in which every other participant was a deepfake.

The documented cases (in French)

It ranks among the major global risks.

The World Economic Forum ranks misinformation and disinformation as the second most severe global risk over two years (Global Risks Report 2026).

It no longer targets states alone.

The operations documented by VIGINUM, France's national vigilance service, impersonate French media and target companies, elected officials and institutions.

What foreign information interference is (in French)

It cuts across the rest of the risk map: cyber through social engineering, geopolitical risk through state operations, fraud through executive impersonation, reputation through coordinated smears, markets through forged press releases.

Awareness is not enough. Controls are.

In the publicly documented deepfake CEO frauds, what stopped the attack was never detecting the fake. It was a verification outside the channel under attack.

Our pre-registered randomised controlled trial, run with 502 participants, found no main effect of cognitive inoculation alone. We publish this negative result because it grounds our method: defence has to be procedural and structural, not only educational.

So every module of the programme ends with a control to put in place, not only with something to know.

Six modules for risk managers.

For risk, internal control, audit and security functions, and for finance departments. Each module stands alone; together they form a full track.

  1. Mapping information risk

    A taxonomy of scenarios: executive impersonation by voice or face, coordinated smears, forged press releases and fake media outlets, state influence operations, internal rumours. Adapted by sector and by country of operation.

    Control put in place

    Information scenarios recorded in the risk map, with an owner for each scenario.

  2. Measuring exposure

    Exposed executives, markets and countries, live controversies, the fault lines hostile actors exploit. Reading the Epistemic Security Score for countries of operation within the European Union.

    Control put in place

    An exposure sheet per entity or per country of operation.

  3. The human factor against the synthetic threat

    Voice and video deepfakes, CEO fraud, supplier impersonation. Why detecting the fake fails, and why verification works.

    Control put in place

    A mandatory second channel for any sensitive request, with written thresholds.

  4. Detecting and qualifying

    Monitoring, weak signals, coordinated behaviour. Telling an information incident from background noise, without overreacting.

    Control put in place

    A written alert chain and a four-question qualification sheet.

  5. The first 24 hours

    Qualify without responding, decide against a grid, act and document. An incident simulation under realistic conditions, then a review of the decisions taken.

    Control put in place

    A designated decision-maker, a deputy, and one exercise a year.

  6. Governance, compliance and insurance

    Reporting to the board. The obligations that bear on the subject: transparency of AI-generated content, reporting to platforms. The questions to ask your insurer or broker about how existing policies apply. The limits to respect regarding freedom of expression.

    Control put in place

    An annual board review and a review of cover with the insurer or broker.

Each module is delivered as a 90-minute webinar, an e-learning module or a half-day workshop. The full track runs over two days in-house.

  • Insurers, brokers and prevention platforms, for their corporate clients.
  • Risk, internal control and audit functions.
  • Security departments, and finance departments exposed to fraud.
  • Risk committees and audit committees.

Not a pricing model.

Information risk does not yet have a reliable historical loss series. The Epistemic Security Score measures a country's structural resilience; how your models use it is your call.

Not global coverage.

The country indicator currently covers the twenty-seven EU member states. The modules apply anywhere.

Not a technical cybersecurity offer.

It complements one, on the human and informational side that technical tools do not cover.

No counter-influence.

We teach how to understand and counter manipulation, never how to practise it. The limits of freedom of expression, anchored in Article 10 of the European Convention on Human Rights, are part of the programme.

Doctoral research, published results.

The programme is led by Elie Abousaab, Academic Director of Académie Nexus, doctoral candidate at the Centre for Diplomatic and Strategic Studies (Paris), where his thesis examines the mechanisms of information interference targeting France and the European Union.

  • Epistemic Security Score, 27 EU member states: DOI 10.5281/zenodo.20837003
  • Randomised controlled trial on cognitive inoculation, 502 participants, pre-registration: DOI 10.5281/zenodo.20403018
For executive committees: the Epistemic security track

Download the full presentation.

Two pages: the four building blocks, the six modules and their controls, the proposed pilot. The download link arrives by email.

All fields are required except phone.

You are
What interests you
Timeframe