Skip to main content
    Insightful AI

    SMEs & Public Sector

    AI-enabled threats and cyber risk

    Train your staff to recognise deepfake fraud, voice cloning and AI-enhanced phishing, and leave with verification steps that do not depend on recognising a face or a voice.

    Duration
    Half day, 3.5 hours
    Delivery
    In-house or online
    Group size
    Up to 15 participants
    Price
    £895 ex VAT per session

    The threats your staff now face

    Finance teams authorise payments. Senior leaders are identifiable by voice and by face. Those are the targets.

    In 2024, a finance employee at the engineering firm Arup was persuaded to transfer approximately £20 million to fraudulent accounts after a video call that appeared to show colleagues. Those colleagues were not present. The call used pre-recorded deepfakes. No system was compromised. The fraud succeeded through social engineering alone.

    The National Cyber Security Centre (NCSC), in its assessment Impact of AI on Cyber Threat from Now to 2027 (7 May 2025), found that AI gives criminals a significant uplift in social engineering and will make attacks more frequent and harder to detect. The uplift is already present.

    Who this course is for

    Any organisation that handles money, sensitive data or client relationships has staff who need this course. The highest-risk roles are finance teams, operations staff, IT managers and senior leaders. A local authority finance department processing grant payments or an NHS trust managing procurement faces the same exposure as a private-sector business.

    Right for you ifNot right for you if
    Your finance team processes payments or clears invoices by phone or emailYour main concern is personal data handling and ICO compliance evidence (see Responsible AI and Data Protection)
    Staff use tools like ChatGPT or Copilot without clear safe-use rulesYou need AI policies and accountability structures built (see AI Governance for Organisations)
    Your annual cyber training was written before AI-generated attacks existedYou want to build AI literacy foundations first (start with AI Fluency for Organisations)
    You need documented evidence of training for your ICO accountability recordsYou are booking for a single person rather than a team
    Your senior leadership is publicly identifiable by voice, image or video

    What participants will be able to do

    • Recognise a deepfake video call and apply out-of-band verification before acting on any request from it
    • Identify AI-enhanced phishing (grammatically perfect, personalised emails that bypass standard filters) and verify through a second channel
    • Apply an out-of-band verification step when a phone call requests a payment or data transfer, regardless of how familiar the voice sounds
    • Use approved AI tools without pasting sensitive data, personal records or confidential client information into public-facing systems
    • Recognise a prompt injection attempt (criminals hiding instructions inside content an AI tool reads)
    • Follow the organisation's approved AI platforms and understand why unapproved tools create data leakage risk
    • Report a suspected attack through the right internal channel and preserve evidence of it
    • Apply a repeatable verification method in their day-to-day work, not just during the training session

    What the course covers

    Recognising attacks against the organisation

    How AI-enabled fraud works and what verification habits stop it. Deepfake video and image fraud, voice cloning, AI-enhanced phishing, social engineering at scale, synthetic identity attacks, and the process controls that provide defence: out-of-band verification, dual authorisation on payments, and approval steps that do not depend on identifying a face or a voice.

    Using AI tools safely

    What staff can and cannot do with tools like ChatGPT, Microsoft Copilot and similar platforms. Prompt injection, data leakage through AI queries, and the secure configuration and safe use of your approved AI tools. The NCSC has stated that prompt injection "may never be totally mitigated" (NCSC, 8 December 2025), which is why staff awareness sits alongside technical controls rather than below them.

    How the course is delivered

    Step 1: Discovery call

    A scoping call to understand your approved AI tools, sector, current policies and the specific roles attending. No two sessions cover the same scenarios.

    Step 2: Bespoke delivery

    Delivered in-house or online for groups of up to 15. Materials are written specifically for your organisation and sector. Larger teams are accommodated across multiple sessions.

    Step 3: Compliance documentation

    Every participant receives documented evidence of training completion meeting the ICO audit framework's expectations. All session materials are shared with the client after the course.

    What is included

    • A pre-course discovery call
    • Bespoke course materials written around your tools, sector and approved platforms
    • A method guide participants keep and use after the course
    • Documented evidence of training completion meeting ICO expectations
    • All session materials shared with the client afterwards
    • A follow-up call after the course, offered to every client
    • A certificate of completion on request, at no extra charge

    Regulatory alignment

    DSIT Code of Practice for the Cyber Security of AI

    The DSIT Code (31 January 2025, co-developed with the NCSC) is a voluntary code. Principle 1 states that an organisation's cyber security training "shall include AI security content". This course addresses both of Principle 1's requirements: the AI-specific threats staff face, and the safe use of AI tools within the organisation.

    UK GDPR and ICO accountability

    The accountability principle (Article 5(2)) requires organisations to demonstrate compliance with data protection law. The ICO's data protection audit framework expects all-staff training programmes with documented completion records. This course produces documented evidence meeting those expectations.

    EU AI Act Article 4 (AI literacy)

    For organisations with EU exposure, Article 4 has been in force since 2 February 2025 and creates a direct obligation to ensure that staff involved in AI operations possess sufficient AI literacy. For UK-only organisations, it reflects the direction that UK regulatory expectations are moving toward.

    Economic Crime and Corporate Transparency Act 2023

    For large organisations meeting at least two of three statutory thresholds (250+ employees, £36m+ turnover, £18m+ balance sheet), the Act's "failure to prevent fraud" offence makes staff training part of the reasonable procedures that form a defence.

    Why this course is different

    Our co-founder Ben Sefton spent 18 years as a Senior Forensic Investigator with Greater Manchester Police, working alongside national law enforcement on major crime investigations. Insightful AI has delivered AI training and awareness briefings to the National Crime Agency, the National Police Chiefs' Council, the North West Regional Organised Crime Unit, City of London Police, Lancashire Constabulary and Greater Manchester Police, among others.

    That background informs how this course is built: it shows staff how attacks are constructed and executed, not how they are described in a vendor threat summary. Insightful AI is listed on the UK Register of Learning Providers (UKPRN 10098807).

    Frequently asked questions

    Who should attend this course?
    Any member of staff who processes payments, handles client data or works with people whose identity could be impersonated should attend. Finance teams, operations staff, IT managers and senior leaders are the highest-risk groups. The session is appropriate for all staff and is particularly valuable for anyone who authorises transactions or holds access to sensitive systems.
    Do staff need any technical knowledge to follow it?
    No prior technical background is needed. The course explains how each attack type works in plain language, using scenarios drawn from the roles attending. It has been built for finance, operations and administration teams as well as IT staff.
    Will this be useful if we have not deployed AI tools ourselves?
    Yes. An organisation without AI systems is not exempt from attacks that use AI. Criminals deploy deepfake video, voice cloning and AI-generated phishing against any organisation that handles money or data, regardless of whether the target uses AI tools itself. The course also covers safe use of platforms like ChatGPT, which most staff are likely already using.
    How is this different from the annual cyber awareness training we already run?
    Most annual cyber awareness training teaches staff to spot spelling and grammar errors. AI removes those tells entirely. Phishing caused the breach in 84% of UK businesses that detected one (DSIT Cyber Security Breaches Survey 2024). This course addresses the specific attack types that have emerged from AI tools: voice cloning, deepfake video, AI-generated phishing and prompt injection.
    Does it cover how to use tools like ChatGPT and Copilot safely?
    Yes. The session covers two connected areas: recognising attacks against the organisation, and using AI tools without leaking sensitive data. The second area addresses prompt injection, what staff can and cannot share with AI platforms, and how to use your organisation's approved AI tools securely.
    Is the content tailored to our organisation?
    Yes. Before the session, we run a discovery call to understand which AI tools your organisation uses or has approved, your sector and your current verification processes. All course materials are written around that information. The session is built around the scenarios your staff will face, not general examples.
    What evidence do we receive for our records?
    Every participant receives documented evidence of training completion that meets the ICO's audit framework expectations. Under the UK GDPR accountability principle (Article 5(2)), your organisation must demonstrate that it maintains adequate training programmes. A certificate of completion is available on request at no extra charge.
    What does it cost, and is the price per person?
    The course costs £895 ex VAT per session, not per person. Up to 15 participants can attend for that price, under £60 per head. Larger teams are accommodated across multiple sessions. The price covers the discovery call, all bespoke course materials, documented training completion evidence, and a follow-up call after the session.

    Book a free discovery call

    A 30-minute call. We will ask about your team, the tools you use and what you need to demonstrate for your records, then confirm whether this course is the right fit or whether another in the programme is the better starting point.

    Book a free discovery call