Human-centric cyber threats have long posed a serious issue for organizations. After all, humans are often the weakest link in the cybersecurity chain. Unfortunately, when artificial intelligence came into the mix, it only made these threats even more dangerous.
So, what can be done about these cyber threats now?
That’s precisely what we asked Tom Vazdar, the chair of the Enterprise Cybersecurity Master’s program at the Open Institute of Technology (OPIT), and Venicia Solomons, aka the “Cyber Queen.”
They dedicated a significant portion of their “Cyber Threat Landscape 2024: Navigating New Risks” master class to AI-powered human-centric cyber threats. So, let’s see what these two experts have to say on the topic.
Human-Centric Cyber Threats 101
Before exploring how AI impacted human-centric cyber threats, let’s go back to the basics. What are human-centric cyber threats?
As you might conclude from the name, human-centric cyber threats are cybersecurity risks that exploit human behavior or vulnerabilities (e.g., fear). Even if you haven’t heard of the term “human-centric cyber threats,” you’ve probably heard of (or even experienced) the threats themselves.
The most common of these threats are phishing attacks, which rely on deceptive emails to trick users into revealing confidential information (or clicking on malicious links). The result? Stolen credentials, ransomware infections, and general IT chaos.
How Has AI Impacted Human-Centric Cyber Threats?
AI has infiltrated virtually every cybersecurity sector. Social engineering is no different.
As mentioned, AI has made human-centric cyber threats substantially more dangerous. How? By making them difficult to spot.
In Venicia’s words, AI has allowed “a more personalized and convincing social engineering attack.”
In terms of email phishing, malicious actors use AI to write “beautifully crafted emails,” as Tom puts it. These emails contain no grammatical errors and can mimic the sender’s writing style, making them appear more legitimate and harder to identify as fraudulent.
These highly targeted AI-powered phishing emails are no longer considered “regular” phishing attacks but spear phishing emails, which are significantly more likely to fool their targets.
Unfortunately, it doesn’t stop there.
As AI technology advances, its capabilities go far beyond crafting a simple email. Venicia warns that AI-powered voice technology can even create convincing voice messages or phone calls that sound exactly like a trusted individual, such as a colleague, supervisor, or even the CEO of the company. Obey the instructions from these phone calls, and you’ll likely put your organization in harm’s way.
How to Counter AI-Powered Human-Centric Cyber Threats
Given how advanced human-centric cyber threats have gotten, one logical question arises – how can organizations counter them? Luckily, there are several ways to do this. Some rely on technology to detect and mitigate threats. However, most of them strive to correct what caused the issue in the first place – human behavior.
Enhancing Email Security Measures
The first step in countering the most common human-centric cyber threats is a given for everyone, from individuals to organizations. You must enhance your email security measures.
Tom provides a brief overview of how you can do this.
No. 1 – you need a reliable filtering solution. For Gmail users, there’s already one such solution in place.
No. 2 – organizations should take full advantage of phishing filters. Before, only spam filters existed, so this is a major upgrade in email security.
And No. 3 – you should consider implementing DMARC (Domain-based Message Authentication, Reporting, and Conformance) to prevent email spoofing and phishing attacks.
Keeping Up With System Updates
Another “technical” move you can make to counter AI-powered human-centric cyber threats is to ensure all your systems are regularly updated. Fail to keep up with software updates and patches, and you’re looking at a strong possibility of facing zero-day attacks. Zero-day attacks are particularly dangerous because they exploit vulnerabilities that are unknown to the software vendor, making them difficult to defend against.
Top of Form
Nurturing a Culture of Skepticism
The key component of the human-centric cyber threats is, in fact, humans. That’s why they should also be the key component in countering these threats.
At an organizational level, numerous steps are needed to minimize the risks of employees falling for these threats. But it all starts with what Tom refers to as a “culture of skepticism.”
Employees should constantly be suspicious of any unsolicited emails, messages, or requests for sensitive information.
They should always ask themselves – who is sending this, and why are they doing so?
This is especially important if the correspondence comes from a seemingly trusted source. As Tom puts it, “Don’t click immediately on a link that somebody sent you because you are familiar with the name.” He labels this as the “Rule No. 1” of cybersecurity awareness.
Growing the Cybersecurity Culture
The ultra-specific culture of skepticism will help create a more security-conscious workforce. But it’s far from enough to make a fundamental change in how employees perceive (and respond to) threats. For that, you need a strong cybersecurity culture.
Tom links this culture to the corporate culture. The organization’s mission, vision, statement of purpose, and values that shape the corporate culture should also be applicable to cybersecurity. Of course, this isn’t something companies can do overnight. They must grow and nurture this culture if they are to see any meaningful results.
According to Tom, it will probably take at least 18 months before these results start to show.
During this time, organizations must work on strengthening the relationships between every department, focusing on the human resources and security sectors. These two sectors should be the ones to primarily grow the cybersecurity culture within the company, as they’re well versed in the two pillars of this culture – human behavior and cybersecurity.
However, this strong interdepartmental relationship is important for another reason.
As Tom puts it, “[As humans], we cannot do anything by ourselves. But as a collective, with the help within the organization, we can.”
Staying Educated
The world of AI and cybersecurity have one thing in common – they never sleep. The only way to keep up with these ever-evolving worlds is to stay educated.
The best practice would be to gain a solid base by completing a comprehensive program, such as OPIT’s Enterprise Cybersecurity Master’s program. Then, it’s all about continuously learning about new developments, trends, and threats in AI and cybersecurity.
Conducting Regular Training
For most people, it’s not enough to just explain how human-centric cyber threats work. They must see them in action. Especially since many people believe that phishing attacks won’t happen to them or, if they do, they simply won’t fall for them. Unfortunately, neither of these are true.
Approximately 3.4 billion phishing emails are sent each day, and millions of them successfully bypass all email authentication methods. With such high figures, developing critical thinking among the employees is the No. 1 priority. After all, humans are the first line of defense against cyber threats.
But humans must be properly trained to counter these cyber threats. This training includes the organization’s security department sending fake phishing emails to employees to test their vigilance. Venicia calls employees who fall for these emails “clickers” and adds that no one wants to be a clicker. So, they do everything in their power to avoid falling for similar attacks in the future.
However, the key to successful employee training in this area also involves avoiding sending similar fake emails. If the company keeps trying to trick the employees in the same way, they’ll likely become desensitized and less likely to take real threats seriously.
So, Tom proposes including gamification in the training. This way, the training can be more engaging and interactive, encouraging employees to actively participate and learn. Interestingly, AI can be a powerful ally here, helping create realistic scenarios and personalized learning experiences based on employee responses.
Following in the Competitors’ Footsteps
When it comes to cybersecurity, it’s crucial to be proactive rather than reactive. Even if an organization hasn’t had issues with cyberattacks, it doesn’t mean it will stay this way. So, the best course of action is to monitor what competitors are doing in this field.
However, organizations shouldn’t stop with their competitors. They should also study other real-world social engineering incidents that might give them valuable insights into the tactics used by the malicious actors.
Tom advises visiting the many open-source databases reporting on these incidents and using the data to build an internal educational program. This gives organizations a chance to learn from other people’s mistakes and potentially prevent those mistakes from happening within their ecosystem.
Stay Vigilant
It’s perfectly natural for humans to feel curiosity when it comes to new information, anxiety regarding urgent-looking emails, and trust when seeing a familiar name pop up on the screen. But in the world of cybersecurity, these basic human emotions can cause a lot of trouble. That is, at least, when humans act on them.
So, organizations must work on correcting human behaviors, not suppressing basic human emotions. By doing so, they can help employees develop a more critical mindset when interacting with digital communications. The result? A cyber-aware workforce that’s well-equipped to recognize and respond to phishing attacks and other cyber threats appropriately.
Related posts
2025 has come to a close, with 2026 already underway. There are many exciting events ahead and future milestones to aim for and look forward to. But it’s also the ideal time to look back over the last 12 months, exploring the most notable achievements we’ve made, lessons we’ve learned, and important moments to reflect on as the new year continues for OPIT’s staff, students, and broader community.
1. Student Commitment
Studying isn’t always easy. It involves long days, and even long evenings sometimes, with a seemingly never-ending series of tasks to accomplish and goals to aim for. It can take a lot out of even the most hard-working and dedicated individuals.
Yet, despite the hardships and challenges, OPIT students demonstrated remarkable resilience, continuous curiosity, and indefatigable determination throughout 2025. Looking back on the year, students at all levels of the OPIT community should feel proud and celebrate their accomplishments.
2. Podcast Launch
2025 saw a lot of new arrivals at OPIT, with fresh projects and innovations arriving on the scene. Chief among them was the OPIT EDGE Podcast, an exciting addition to the institute’s ever-expanding multimedia offerings.
There have already been several episodes of the podcast for students and technology enthusiasts in general to enjoy, with the first episode of this student-driven project involving an in-depth discussion with industry expert Matteo Zangani on the potential of quantum AI technology.
3. Success Stories
While many new students have joined the OPIT ranks in 2025 and will also do so in 2026, others have now achieved their educational objectives and are already moving on to the next exciting steps and chapters in their personal and professional lives.
There are so many inspiring success stories from the last 12 months, it’s impossible to list them all. But just one notable example has to be Maria Brilaki, who recently concluded her Master’s in Responsible AI, defending a powerful thesis related to non-invasive glucose monitoring through near-infrared spectroscopy and machine learning.
4. Graduation in Malta
2025 was a big year of firsts for OPIT, including the institute’s first official graduation ceremony, which took place on March 8 at a grand ceremony in Malta, honoring the achievements of dozens of applied data science and AI graduates.
The hybrid event was open to both in-person and virtual attendees, bringing together members of the OPIT community from across the world. It was a huge moment for the graduates themselves and a thrilling milestone for OPI – a testament to all the hard work that has gone into building this institute.
5. OPIT AI Copilot
Artificial intelligence is the technology of the moment, and OPIT isn’t just dedicated to teaching the next-generation of technology leaders how to work with AI responsibly and efficiently; it’s also interested in harnessing the powers and potential of AI to improve its educational offerings, too.
This culminated in the development and release of OPIT AI Copilot in 2025. This groundbreaking AI tool now provides real-time, personalized learning support, along with contextual assistance, and is available on a round-the-clock basis for students to turn to, as and when they feel the need.
6. Hackathons
2025 also saw OPIT students and faculty take more active roles in various events, including hackathons. In November, for example, OPIT got involved with the 6th edition of the ESCP Hackathon, with several students entering as developers.
This was an exciting and unique opportunity for those students to meet up in person, put the skills they’ve honed during their time at OPIT to the test in a challenging environment, and learn from one another. OPIT will surely participate in more hackathons in the years to come, so stay tuned for more details on upcoming events and how you can play your part.
7. Strengthening Collaboration
From day one, OPIT has focused on building a strong network of established technology and business partners, opening doors and providing opportunities for both education and employment for its students.
This continued throughout 2025, with OPIT strengthening its connections with a number of world-leading organizations, including Accenture, AWS, Hype, Buffetti, and more. Through events like hackathons, career fairs, and more, OPIT makes the most of its ever-expanding and increasingly impressive professional network.
8. Online Career Fair
Another big first for 2025 was the inaugural OPIT Online Career Fair, an event that was held on November 19 and 20, with more than a dozen established and emerging companies from around the world in attendance, including the likes of Deloitte, Tinexta Cyber, Datapizza, RWS Group, Planet Farms, and Nesperia Group.
The only nature of this event ensured that students all enjoyed equal access, no matter where they were based, and everyone was able to hear from industry experts and enjoy the unique array of opportunities on offer, forging their own connections and learning more about brands they might like to work with or for in the future.
9. Education Innovation
OPIT has always been about innovating, delivering newer and smarter ways to learn for students across the globe, no matter their background, budget, or social class. And the institute has continually innovated over the course of 2025, helping students learn skills and broaden their knowledge efficiently and intuitively.
As we enter 2026, OPIT’s innovation is set to be on full display once more, with no less than two new courses for new applicants to choose from: AI-Driven Software Development (Elective) and Business Intelligence and Decision Making (Elective).
10. The Power of the OPIT Community
Perhaps the crowning achievement for OPIT in 2025 was the demonstrable success of not just individual students or faculty members, but the entire OPIT community, as a whole. Everyone, from alumni to new students and seasoned staff members, played their part in the institute’s success, paving the way for more great things and major milestones in 2026 and beyond.
As OPIT Rector and former Italian Minister of Education, Francesco Profumo, puts it:
“What inspires me most is the mindset of our students: forward-looking, responsible, and driven by a desire not just to succeed, but to contribute. Their dedication reminds us why education remains one of the most powerful forces for shaping the future.”
Bring talented tech experts together, set them a challenge, and give them a deadline. Then, let them loose and watch the magic happen. That, in a nutshell, is what hackathons are all about. They’re proven to be among the most productive tech events when it comes to solving problems and accelerating innovation.
What Is a Hackathon?
Put simply, a hackathon is a short-term event – often lasting just a couple of days, or sometimes even only a matter of hours – where tech experts come together to solve a specific problem or come up with ideas based on a central theme or topic. As an example, teams might be tasked with discovering a new way to use AI in marketing or to create an app aimed at improving student life.
The term combines the words “hack” and “marathon,” due to how participants (hackers or programmers) are encouraged to work around-the-clock to create a prototype, proof-of-concept, or new solution. It’s similar to how marathon runners are encouraged to keep running, putting their skills and endurance to the test in a race to the finish line.
The Benefits of Hackathons
Hackathons provide value both for the companies that organize them and the people who take part. Companies can use them to quickly discover new ideas or overcome challenges, for example, while participants can enjoy testing their skills, innovating, networking, and working either alone or as part of a larger team.
Benefits for Companies and Sponsors
Many of the world’s biggest brands have come to rely on hackathons as ways to drive innovation and uncover new products, services, and opportunities. Meta, for example, the brand behind Facebook, has organized dozens of hackathons, some of which have led to the development of well-known Facebook features, like the “Like” button. Here’s how hackathons help companies:
- Accelerate Innovation: In fast-moving fields like technology, companies can’t always afford to spend months or years working on new products or features. They need to be able to solve problems quickly, and hackathons create the necessary conditions to deliver rapid success.
- Employee Development: Leading companies like Meta have started to use annual hackathons as a way to not only test their workforce’s skills but to give employees opportunities to push themselves and broaden their skill sets.
- Internal Networking: Hackathons also double up as networking events. They give employees from different teams, departments, or branches the chance to work with and learn from one another. This, in turn, can promote or reinforce team-oriented work cultures.
- Talent Spotting: Talents sometimes go unnoticed, but hackathons give your workforce’s hidden gems a chance to shine. They’re terrific opportunities to see who your best problem solvers and most creative thinkers at.
- Improving Reputation: Organizing regular hackathons helps set companies apart from their competitors, demonstrating their commitment to innovation and their willingness to embrace new ideas. If you want your brand to seem more forward-thinking and innovative, embracing hackathons is a great way to go about it.
Benefits for Participants
The hackers, developers, students, engineers, and other people who take part in hackathons arguably enjoy even bigger and better benefits than the businesses behind them. These events are often invaluable when it comes to upskilling, networking, and growing, both personally and professionally. Here are some of the main benefits for participants, explained:
- Learning and Improvement: Hackathons are golden opportunities for participants to gain knowledge and skills. They essentially force people to work together, sharing ideas, contributing to the collective, and pushing their own boundaries in pursuit of a common goal.
- Networking: While some hackathons are purely internal, others bring together different teams or groups of people from different schools, businesses, and places around the world. This can be wonderful for forming connections with like-minded individuals.
- Sense of Pride: Everyone feels a sense of pride after accomplishing a project or achieving a goal, but this often comes at the end of weeks or months of effort. With hackathons, participants can enjoy that same satisfying feeling after just a few hours or a couple of days of hard work.
- Testing Oneself: A hackathon is an amazing chance to put one’s skills to the test and see what one is truly capable of when given a set goal to aim for and a deadline to meet. Many participants are surprised to see how well they respond to these conditions.
- Boosting Skills: Hackathons provide the necessary conditions to hone and improve a range of core soft skills, such as teamwork, communication, problem-solving, organization, and punctuality. By the end, participants often emerge with more confidence in their abilities.
Hackathons at OPIT
The Open Institute of Technology (OPIT) understands the unique value of hackathons and has played its part in sponsoring these kinds of events in the past. OPIT was one of the sponsors behind ESCPHackathon 6, for example, which involved 120 students given AI-related tasks, with mentorship and guidance from senior professionals and developers from established brands along the way.
Marco Fediuc, one of the participants, summed up the mood in his comments:
“The hackathon was a truly rewarding experience. I had the pleasure of meeting OPIT classmates and staff and getting to know them better, the chance to collaborate with brilliant minds, and the opportunity to take part in an exciting and fun event.
“Participating turned out to be very useful because I had the chance to work in a fast-paced, competitive environment, and it taught me what it means to stay calm and perform under pressure… To prospective Computer Science students, should a similar opportunity arise, I can clearly say: Don’t underestimate yourselves!”
The new year will also see the arrival of OPIT Hackathon 2026, giving more students the chance to test their skills, broaden their networks, and enjoy the one-of-a-kind experiences that these events never fail to deliver. This event is scheduled to be held February 13-15, 2026, and is open to all OPIT Bachelor’s and Master’s students, along with recent graduates. Interested parties have until February 1 to register.
Have questions?
Visit our FAQ page or get in touch with us!
Write us at +39 335 576 0263
Get in touch at hello@opit.com
Talk to one of our Study Advisors
We are international
We can speak in: