Select Language

Choose your language

株式会社ヤグラ

Select Language

Choose your language

株式会社ヤグラ

Select Language

Choose your language

Insight

Why Once-a-Year Lectures Fall Short: Why Security Training Needs "AI Agents"

Attackers now use generative AI to mass-produce text, voice, images, and spoofed sites at low cost. Defenders cannot keep pace with this speed by relying solely on manual targeted email training and alert verification. Since multi-channel attacks spanning email, SMS, phone, social media ads, and spoofed sites are now the norm, training must also shift to a self-sustaining, autonomous system. From a practical standpoint, this article outlines the overall picture and implementation steps of "AI agent-driven security training" that should be at the core of this strategy.

AI SOCとは? 仕組み・従来型SOCとの違い

What Has Changed: Threat "Quality" and "Speed"

The major shift over the past few years is the update frequency and the diversity of attack channels. Sophisticated lures—such as natural Japanese emails, voice cloning mimicking executives, and fake landing pages via ad platforms—now appear in connected sequences. Traditional training, which operates on the premise of "spotting a single email," fails to cover these real-world touchpoints.

Meanwhile, annual or semi-annual mass classroom training, or regular simulations where everyone receives the same content, makes learning easily buried in daily tasks and difficult to retain. As a result, an asymmetry is created: attacks are multi-faceted and highly frequent, while training is single-faceted and low frequency, leaving organizations on the defensive.

Why Traditional Training Fails to Work

The premise of traditional design was "simultaneous, periodic, and one-size-fits-all." However, human learning is context-dependent, and retention is strongest immediately after an experience. While awareness peaks right after annual training, it fades within weeks, leaving users unprepared for new tactics. Furthermore, relying "only on email simulations" leaves growing blind spots in daily operations, such as SMS, voice, ads, and fake sites. A redesign is needed to bridge gaps in frequency, context, and channels.

The Solution: AI Agent-Driven Security Awareness Architecture

The practical solution is a system where humans define policy and governance, while AI agents handle daily operations. It consists of the following five elements.

3-1. Multi-Channel Targeted Simulations

Simulate actual attacks using connected scenarios across email, social media ads, SMS, fake websites, and voice. Collect behavioral data—such as clicks, inputs, and reports—at each stage to gain a multi-dimensional understanding of organizational weaknesses.

3-2. Individual Optimization Using OSINT

Leverage public information—such as department, job title, SaaS tools used, and public profiles—strictly within company policy to create realistic "lures" tailored to the business context. Excessive profiling is unnecessary; the key is the realism that makes it feel "highly plausible" to the user's specific role.

3-3. Automated Delivery and Instant Micro-Learning

Deliver 30-to-90-second learning modules within the same day based on behavioral signals such as failures, non-reports, or delayed reports. Keep the frequency high, the burden low, and repeatedly reboot awareness. The agent monitors training history and behavior to automatically adjust the difficulty, channel, and timing of the next simulation.

3-4. Risk Visualization Dashboard

Focusing solely on "click rates" leads to incorrect improvements. Visualize reporting rates (Real Threat Reporting), Time to Report (TTR), and repeat offender trends by department, role, and period to evaluate defense maturity based on "detecting, sharing, and reducing recurrence."

3-5. Operational Integration (SIEM / EDR / SOAR Integration)

Awareness training must speak the same language as security operations. Downstream, high-risk groups identified through training can trigger enhanced monitoring in EDR. Upstream, the latest real-world cases detected by the SOC are reflected in the following week's training materials. Integrating training into daily operations turns learning into actionable defense.

KPI Design: From Click Rates to "Report Economics"

To capture outcomes quickly and accurately, adopt leading indicators.

  • Reporting Rate: Are employees proactively reporting suspicious activity?

  • TTR (Time to Report): How fast can the initial response begin?

  • Recurrence Trend: Re-click rates and missed-threat biases at individual and departmental levels.

  • Departmental Risk Skew: Identifying vulnerable zones caused by business characteristics.

While click rates remain important as an outcome, a culture of "detect fast, share fast" dramatically limits the blast radius of any attack.

Security AI Agent Implementation Roadmap

Speed is critical for deployment. Yagura recommends a 90-day PoC approach to deliver quick wins with a minimum viable configuration. Here is an operational example:

Phase A (Weeks 0–2): Design

Select a target group of 100 to 300 employees. Adopt three KPIs: reporting rate, TTR, and recurrence trends. Set up three channels (email, SMS, and voice) and secure consensus on sending domains/lines, voice synthesis consent, and the operational scope of OSINT.

Phase B (Weeks 3–8): Operation

Deliver instant micro-learning immediately after failures while adjusting difficulty, channels, and timing on a weekly basis. Use the dashboard to identify departmental skews and repeat offenders, sharing insights with managers and the CSIRT.

Phase C (Weeks 9–12): Institutionalization

Establish upstream integration (SOC detection to training materials) and downstream integration (high-risk segments to EDR enhanced monitoring). Reflect these in SOPs and training policies, then report PoC performance metrics and institutionalization plans to executive management.


Common Concerns and Answers

Are the costs too high?

Annual events seem cheap, but the expected cost of breach continues to rise due to high-frequency, multi-channel attacks. By enabling a "continuous, personalized, and automated" approach via agents, the investment is recovered by reducing both management overhead and expected breach costs.

Will it cause user backlash or fatigue?

Resistance decreases when learning is short, immediate, and highly relevant to work. Building a positive feedback loop through the visualization of successful reports and praise-based operations is key.

Is operations too complex?

By using templated scenarios, approval flows, and designing human intervention only for exceptions, the "human-in-the-loop, AI-driven" system runs seamlessly.

Tips: Designing the Culture

Human defense requires praising reports. Designing systems that lead to pride rather than shame—such as "Fastest Reporter Awards," sharing high-quality alerts, and visualizing lessons learned from mistakes—creates a chain reaction of early detection. Organizations that quickly recycle real cases into training materials will outpace the update speed of attackers.

Conclusion: From

ヤグラAIセキュリティ

丸わかり資料を

無料でダウンロード

生成AI時代に求められるサイバー環境の変化や

サービスの概要資料についてお送りいたします。

ヤグラAIセキュリティ

丸わかり資料を

無料でダウンロード

生成AI時代に求められるサイバー環境の変化やサービスの概要資料についてお送りいたします。

ヤグラAIセキュリティ

丸わかり資料を

無料でダウンロード

生成AI時代に求められるサイバー環境の変化やサービスの概要資料についてお送りいたします。