SimuPhish co-founders Shubh Arya and Hritik Jain explain why continuous behavioural intelligence is essential for building workforce cyber resilience
As AI-driven threats become increasingly sophisticated, traditional security awareness training is proving inadequate for organizations in the Middle East. SimuPhish co-founders Shubh Arya and Hritik Jain advocate for a shift towards continuous Human Risk Management strategies that focus on behavioral intelligence to combat these evolving challenges. In a recent interview, they discussed the complexities of workforce cyber risk in the region, emphasizing the need for targeted interventions that adapt to the changing threat landscape.
The Shift to Continuous Human Risk Management
According to Arya, conventional security training often emphasizes knowledge transfer through courses and assessments, which does not adequately prepare employees for real-world threats. “Knowing what to do and making the right decision when faced with a convincing attack are very different things,” he stated. Continuous Human Risk Management allows organizations to model employee behavior, identify vulnerabilities, and implement interventions based on actual responses to threats. This approach is crucial as attackers continuously evolve their tactics, making it essential for organizations to assess and manage human risk continuously.
“The objective is not simply to create more security-aware employees, but to build a workforce that consistently demonstrates safer security behaviour.”
AI’s Role in Reshaping Cyber Risk
AI technologies are transforming the landscape of cyber threats, enabling attackers to craft highly convincing and personalized communications at unprecedented speeds. Arya noted that employees are now more likely to encounter messages in their native languages or urgent requests that appear to come from trusted sources, complicating the detection of deception. This shift necessitates a change in how organizations train their employees, moving from recognizing fixed warning signs to fostering a culture of verification and reporting.
The Middle East’s diverse workforce presents additional challenges, as organizations must cater to employees communicating in multiple languages and cultural contexts. Arya emphasized that security programs must reflect this diversity to be effective. “A security programme designed around one language or one type of employee cannot adequately reflect that environment,” he explained.
“The Middle East has an opportunity to move beyond compliance-driven awareness and become a leader in measurable, behaviour-driven cyber resilience.”
Leveraging AI for Cyber Resilience
Hritik Jain highlighted that AI is not just a tool for attackers but also a powerful ally for defenders. AI can analyze vast amounts of data, automate processes, and identify behavioral patterns, allowing organizations to respond more effectively to threats. However, he stressed that human behavior remains central to cybersecurity. Organizations must understand how employees react to increasingly convincing AI-generated attacks to enhance their defenses.
SimuPhish employs AI to support various stages of the Human Risk Management lifecycle, from creating realistic risk scenarios to capturing behavioral signals that help identify patterns across different departments and attack vectors. This intelligence enables organizations to tailor interventions based on individual employee risk profiles, moving away from a one-size-fits-all approach.
As organizations in the Middle East navigate the complexities of cybersecurity, the emphasis on continuous Human Risk Management and behavioral intelligence will be crucial in building a resilient workforce capable of withstanding AI-driven threats. For more insights, visit Tahawul Tech.
Follow Cyber Warriors Middle East for further regional cybersecurity developments.



