MEET THE TEAM AT BLACK HAT - DEF CON 2026 Learn More

Beyond Awareness: Why Social Engineering Is a Control Design Problem

Awareness training isn't enough. In this session, Alethe Denis shifts the focus from how attackers deceive people to why business systems still allow impact when deception succeeds. Drawing from real red team experience, she breaks down where defenses actually fail and what to do about it.

User awareness training has long been treated as the foundation of social engineering defense. But real-world attacks continue to succeed, even in organizations with mature training programs, phishing simulations, and security-conscious employees.

In this session, Alethe Denis, Senior Security Consultant II at Bishop Fox, shifts the conversation from how attackers deceive people to why business systems still allow impact when deception succeeds. Building on the themes explored in Tactics of Deception, this virutal session moves beyond the mechanics of persuasion and focuses on the workflows, identity signals, and control gaps that allow social engineering to become a compromise path.

Drawing from hands-on red team experience, Alethe will break down where defenses actually fail: over-trusted help desk processes, weak verification paths, low-friction approval workflows, exposed SaaS integrations, and escalation points where employees are forced to make security decisions without enough support. She’ll also examine how modern attackers are using AI, deepfakes, voice phishing, and targeted pretexting to increase the scale and realism of these attacks.

More importantly, this session focuses on what organizations can do about it. Attendees will learn how to rethink social engineering defense as a control design problem, where the goal is not to prevent every employee mistake, but to ensure one persuaded person cannot create disproportionate business impact.

Alethe will also discuss how red team assessments can validate whether controls hold up under real-world pressure, including scenarios involving AI-enabled deception, help desk impersonation, executive pretexts, and workflow abuse.

If your organization is ready to move beyond awareness training and build defenses that reduce actual impact, this session will offer a practical, field-tested perspective on what needs to change.


Microsoft Teams image 23

About the speaker, Alethe Denis

Senior Security Consultant

Alethe Denis is a Senior Security Consultant at Bishop Fox. She is best known for social engineering, open-source intelligence (OSINT), and performing security assessments and trainings for both the private and public sectors with emphasis on critical infrastructure organizations. Alethe was awarded a DEF CON Black Badge at DEF CON 27 for Winning the 10th annual Social Engineering Capture the Flag (SECTF) contest. Using both OSINT and Social Engineering skills, she compromised her target Fortune 500 company using just a telephone. She, along with her teammates, received a bronze, silver, most valuable OSINT, and black badge award from a series of TraceLabs capture-the-flag contests, including first place in

She’s a frequent conference speaker and podcast guest, including speaking at DerbyCon, BsidesSF and ConINT, as well as an appearance on the TraceLabs, Layer 8 Conference, and Darknet Diaries podcasts.

Alethe is always focused on giving back to the information and cybersecurity community, including her work conducting free Security Awareness Trainings and hosting workshops for people who want to get into the cybersecurity industry.