All articles
Share

The Cognitive Defense Network: What Studying an Organization's Nervous System tells us about Defense

July 21, 2026
Human factors
July 21, 2026
Jordan Schoenherr
Scientist
Title
SHARE
SHARE
SHARE

Organizations leave themselves undefended by ignoring the nervous system of company decision-making: security decision-making.

Employees and managers are disempowered, helpdesk services are outsourced, and the decisions that determine whether an attack succeeds are not viewed as a collective system.

Breaches don't start with code. Code is created, modified, influenced, and defended by people. Exploits are the symptom of the accumulated technical and psychological debt organizations face by adopting technologies that are imperfect, producing unwarranted trust in their employees. The root cause of breaches are failures of individual and collective decision-making that accumulates over time and becomes embedded within technological infrastructure, policy gaps, and security practices.

Security teams have spent decades developing the technological and conceptual foundations of the security stack: layered, complementary controls including endpoint, network, identity, and the cloud. Each hardens the attack surface at a different level. While gaps persist, the logic is sound: no single control is sufficient. Effective defense requires depth and breadth of coverage.

Just as organizations build a technical security stack, they also operate a cognitive defense network. This layered system of human perception, judgment, collective decision-making, and organizational structure determines how security policies are implemented, reactions to social engineering attacks, and how incidents are recognized, escalated, and resolved.

Attackers have developed their own stack in a distributed network. Organizations must map their human attack surface and the defense network that relies on judgment of its employees. Each employee: help desk agent, SOC analysts, financial approvers, represents a node in an organization where critical decisions are made every moment. These nodes are numerous, distributed, and rarely understood as an organization's human attack surface. Even with the adoption of AI in the SOC, these nodes remain the point where a well-crafted call or message reaches a person without being detected by most tools.

Circuit 1: Perception: What Gets Noticed

Before we can decide, we must attend. Decisions must have a sound evidence base to produce accurate, reliable results that can separate signal from noise. Detection without recognition produces noise, not security.

Signals come in many forms: anomalies, attack patterns, and vulnerabilities. But even when a system ‘detects’ a signal, humans must recognize and respond to it. For practitioners, many of these patterns are intuitive: their years of training have sensitized them to the dynamic environments of their organizations' attack surface.

NIST and similar frameworks give organizations a shared vocabulary for identifying threats. This helps organizations and teams coordinate and compare risks. But these frameworks also influence perception. By directing attention to certain features, they can also obscure others. By promoting alerts, this implicitly signals to a SOC analyst that other information is less informative and in need of triage. When threats don’t easily fit into these categories, they can create the illusion of understanding where none exist. If applied erroneously, statistics can hide these flaws and increase confidence.

This illusion has consequences beyond the practitioner level. Recent research from MIT Sloan found that boards systematically mistake regulatory compliance for actual security. This failure becomes clear when you examine how compliance frameworks work at the perceptual nodes. They don't just organize information, they focus attention on a subset of signals. By directing attention, we create blind spots.

Social engineering attacks thrive in the spaces left behind. Phishing training and tests focus employees’ attention on email, leaving them desensitized to voice-based attacks over calls. Calls have voices on the other end, infused with familiar emotions, requests, and urgency. If they seem genuine or at least plausible, they can be convincing enough when time and attention are limited. No mental rule is triggered.

In early 2026, attackers called employees at hundreds of organizations, impersonating IT staff and directing them to branded credential harvesting sites using the pretext of a routine MFA update. No suspicious link or emails were required. It looked like a legitimate IT workflow.

Training presents these scenarios as clean and obvious. When employees are focused on questionable links or poorly worded emails, they can fail to scrutinize requests for help. Lessons are often so laughable or overused that they frustrate or bore busy employees. AI deepfakes are often presented as either too obvious to miss or too sophisticated to catch. In either case, they pass through an organization’s perceptual filter undetected.

Circuit 2: Judgments: How we Decide

If perception makes anomalies visible, judgment determines what follows. This requires mental effort regardless of an employee’s expertise. In real-time voice calls, employees have very little time to respond. Requests take seconds, responses in milliseconds. They draw from the limited repertoire of alternatives: accept, reject, escalate. Escalation opens up an employee's judgments to a larger social network, one that can result in peer and supervisor judgement resulting from false positives, reallocated resources, and delays.

There is an inherent asymmetry in the relationship between agents and callers. Agents appear to have control: they hold the access that callers want and need. But their decisions are based on assisting others, a position where saying ‘no’ is unnatural. In these situations, the caller controls the pace of the conversation. They have far more degrees of freedom in terms of what they can ask, how they can ask it, and how long they are willing to stay on the line. An employee can pause for a moment, put the caller on hold, or hang up. For help desk agents whose job is to assist others, all of these responses can create frustration in fulfilling their main goal.

In voice calls, agents must balance the demands of helping the caller and assessing social engineering. All of this happens in a mental workspace that has limited resources. They must gather the available perceptual cues and weigh them. Often below their awareness, a calculus is playing out: if most people make a genuine request, then most cues are benign. Even deception and persuasion are common: use urgency, jump to the front of the queue. This looks like noise that can be attributed to a task or personality, not the role of social engineer.

When familiar social cues are present and the majority of callers are legitimate, helping remains the dominant response. No other options are perceived. No choice was recognized as having been made, they are fulfilling their role and following the script. In September 2023, attackers called MGM Resorts' IT help desk, identified a real employee on LinkedIn, assumed their identity, and requested a credential reset in a call that lasted 10 min. The attackers walked away with administrator access to MGM's Okta and Azure environments, causing ~$100 million in operational losses.

This is not a failure of training and cannot be resolved by better training. It is a structural feature of how human judgment unfolds under time pressure and asymmetric information. As a species, we’ve adapted for collaboration and quick decisions.

Figure 1. Circuits of the collective cognitive defence network.

Groups survive and thrive by distributing tasks, with each individual developing their own competencies. Organizations are successful to the extent that they can develop formal and informal social networks that specialize in critical internal and external operations.

As tasks become more distributed, individuals focus their attention more narrowly, creating more efficient workflows and distributed awareness. If tasks and reporting structures are not clearly defined, organizations become inefficient and can miss critical windows for action, reduce morale and team cohesiveness, and push the burden of ad hoc security judgment onto whichever employee happens to answer next.

If operational awareness is distributed, it depends on trust. Trust is maintained through direct interaction with co-workers or indirect reputational and role information: if a manager is slow to reply to employees, employees will adopt workarounds to attain the resources they need, adopting shadow IT and forming informal networks over time.

Agents on the Frontline. These webs of trust are social engineers’ prime targets. When a helpdesk agent receives a call, they must assume that the caller is making a good faith request. Verification procedures ensure that these biases don’t override security policies. But this only works up to a point. Policies often contain incomplete and inconsistent information, employees are left to decide how to respond in the moment.

In environments where urgency and exceptions are everywhere, shortcuts are the norm. In hospitality, customers need to enjoy their stay now. In finance, funds need to be transferred to make a purchase now. In healthcare, a patient’s well-being needs to be protected now. These tasks require effectively distributing workload.

Managers in the Middle. Supervisors are central nodes in any working group. Despite their relative position of authority, they are both empowered and disempowered. They have the ability to authorize and revoke access, but they serve the organization’s needs and goals. Unless their role involves security, they likely aren’t aware of how policies and procedures translate into practice.

As their staff grows and turns over, their attention becomes divided between tasks and employees, their knowledge becomes more indirect. If their employee needs access to do their job, they grant it. When they receive a request, they trust their onboarding team. Verification is only required in the absence of trust.

Weeks before the MGM breach, attackers used the same playbook against Caesars Entertainment. The one critical difference was that they targeted an outsourced IT support vendor rather than an internal help desk. Caesars noted that the attackers accessed its customer loyalty database and paid ~$15 million to stop the stolen data from being released.

As sources of authority, managers and help desk agents are rarely questioned. For most employees, the social and financial capital required to do so is simply too high. If a manager calls with a request, it must be fulfilled. If an agent calls with an urgent reset, employees could lose access. The threatened disruption of organizational workflow is too great.

As central nodes in an organization’s social network, they are the boundary between the periphery and the deep assets attackers’ seek. An email address and a company signature are sometimes all the legitimacy a request requires. If attackers can succeed in business email compromises or successfully impersonate these central figures, they can exploit the role-based trust, without breaching a technical control. Organizational climates defined by closed, directive leadership will make this worse: dissent gets suppressed before it reaches people who can act on it, a type of groupthink (Table 1).

Groupthink Symptom Description Cybersecurity Structure Examples in Real Incidents
Illusion of invulnerability Excess optimism that reads past survival as proof of safety, blinding the group to warning signs. Leadership assumes repeated audit or advisory warnings as routine rather than urgent, given that no major incident has occurred. A 2016 House Oversight Committee report attributed the 2014–2015 OPM breach that exposed records of more than 20 million people, to “a failure of culture and leadership,” citing Inspector General warnings about weak authentication that had gone unaddressed since 2005.
Mindguards A trusted insider filters out information that might disrupt the group's confidence, before it reaches the people who need to act on it. An internal warning gets raised and contained. It is not escalated to the board, investors or regulators who have the authority or duty to respond. The SEC's 2023 complaint against SolarWinds and its CISO cited internal presentations from 2018 describing the company's network as “not very secure” and in “a very vulnerable state.” Investors were not informed before the 2020 breach.
Diffusion of responsibility (illusion of unanimity) Silence is interpreted as agreement. When no one objects loudly, everyone assumes someone else handles the situation. An alert passes through a chain of staff, or a vishing attempt is reported to a help desk agent. Each recipient assumes the next person will act, no action is taken. Target's FireEye system issued repeated urgent alerts in the weeks before a 2013 breach. Its Bangalore team passed them to Minneapolis. However, a Senate Commerce Committee analysis found the alerts were never acted on.
Collective rationalization The group reframes a decision that would otherwise look indefensible, so it can proceed without confronting the concern directly. A security incident gets relabeled internally, using language that sidesteps the disclosure duties the real event would trigger. Uber's then-CSO arranged a $100,000 payment to the 2016 breach's hackers through the company's bug bounty program instead of disclosing it. A jury convicted him of obstruction, which the Ninth Circuit upheld in 2025.

Circuit 4: Organizational Culture and Boundaries

Collective decision-making might start in groups, but it is shaped by organizational size and structure. If leaders have done their job correctly, organizations take on lives of their own with formal and informal networks.

As organizations grow, specialized groups emerge, each with their own goals, vocabularies, and priorities. Security culture rarely dominates. Annual reports focus on KPIs like revenue, growth, and operational efficiency. Breaches and social engineering tactics are not signals that are understood by an organization's internal communication channels. When they are viewed, they are perceived as failures of technology, training, and teams. However, in many of these cases the ultimate cause is an organizational culture that doesn’t support cybersecurity.

Funding tends to be allocated only once a breach has occurred, with adaptation following from the last attack, not a future attack. Cybersecurity economics represents a delicate balance of paying enough to keep a company safe while not interfering with service delivery, production, and profitability. Innovation and enforcement in cybersecurity and helpdesk services are often outsourced. Businesses become dependent on the level of protection their provider offers.

Consider recent high-profile breaches. Organizations have grown large enough to outsource help desk services entirely. They care about employee support and customer service, but have determined it is more efficient to hold those functions elsewhere. As those operations shift away from direct organizational oversight, they carry the cognitive security stack with them. This creates new vulnerabilities in every layer of it.

The 2025 Marks & Spencer breach makes this concrete. Attackers impersonating employees called M&S's outsourced IT help desk provider (TCS), and manipulated password reset processes to gain access. The breach cascaded across contactless payments, online retail, and supply chain operations simultaneously, suspending online sales for weeks and costing an estimated £300 million (~$395 million USD) in lost operating profit. M&S ended its contract with TCS in July 2025, though both companies say the decision predated the attack. The entry point was the boundary between the core organization and a trusted third-party where oversight was limited due to trust. These points represent vulnerabilities in the cognitive defense system between organizations.

Integrating and Defending Your Cognitive Defense Network

If social engineering is a continuous problem, organizations need a continuous solution. They need to understand where vulnerabilities exist in their workflows not just in their systems. The hardware and software that define the technical security stack are in service of a cognitive stack that most organizations have never mapped.

The incidents reviewed above share a common factor that many analyses miss. The employees at MGM's help desk, at Caesars' vendor, at M&S's outsourced IT provider, at the hundreds of organizations contacted by attackers in early 2026 did not transparently fail. They fulfilled their role and objective for what their organizations trained them to do. Patching their knowledge with sporadic phishing training or brief social engineering courses cannot fill the expertise gap.

Rather than blaming employees, we need to consider the tasks and environments that decision-making takes place within. Organizations need to audit their cognitive defense system in the same way they do other vulnerabilities. Even when smart employees are hired, they must recognize that knowledge is domain-specific: blaming employees for responding to social engineering is equivalent to blaming a misconfiguration firewall. There is no human firewall, because it was never configured.

Assessing organizational situational awareness requires a critical examination of each circuit. This requires auditing each based on key questions to close any gaps that are apparent.

Closing Circuit 1 (Organizational Perception): The perception circuit determines what your organization notices. An audit of this circuit must show what categories of threat are your frameworks not designed to detect? NIST, ISO 27001, and similar standards direct attention toward classifiable, loggable events. Voice-based social engineering does not produce these unless detection technologies can identify these features. If your threat detection vocabulary has no category for vishing, pretexting, or impersonation by voice, your perception circuit has a structural blind spot that no amount of SOC tooling will close.

Questions CISOs must ask: detection and blind spots
  • When did your organization last conduct a vishing simulation, and what did the results reveal about which roles or employees lacked situational awareness?
  • What signals from call interactions, help desk tickets, and access requests are currently being discarded as noise?

Closing Circuit 2 (Judgment). The judgment circuit determines what employees do once a signal has been perceived. Training records will not have this contextual depth. Auditing this circuit requires understanding the structural conditions in which your high-exposure employees make decisions. Organizations must consider time pressure, role orientation, and the cost of escalation.

Questions CISOs must ask: escalation cost and employee options
  • What is the social and professional cost for a helpdesk agent who escalates a call that turns out to be legitimate? Are false positives and false negatives perceived the same way?
  • What realistic options does an employee have when they suspect a call is suspicious but cannot confirm it? Do they have the ability to record and escalate the case systematically, or must they identify their own workarounds?

Closing Circuit 3 (Collective Decision-Making). The collective circuit determines how trust flows through your organization and where it becomes a liability. Auditing this circuit requires mapping the trust relationships that your operations depend on, and identifying which of those relationships social engineers are most likely to target.

Questions CISOs must ask: authority, verification, and urgency
  • Which roles in your organization carry implicit authority that employees are unlikely to challenge? These are your highest-value impersonation targets.
  • What verification is required when a manager, IT staff member, or executive makes an access request? If the answer is "none, because we trust them," that is a structural vulnerability, not a cultural one.
  • Where do your verification procedures break down under operational urgency? In hospitality, healthcare, finance, and any environment where "now" is a legitimate operational demand, urgency is a social engineering amplifier that policy has not neutralized.
  • What happens organizationally when an employee refuses a request from a more senior figure and turns out to be wrong? If the cost of a false positive is career-relevant, verification will not happen consistently.

Closing Circuit 4 (Organizational Structure). The structural circuit determines where your cognitive defense network fragments. Auditing of this circuit requires mapping every organizational boundary where security accountability transfers, partially or entirely, to a party outside direct oversight. Each of those boundaries is a potential entry point.

Questions CISOs must ask: vendors and breach history
  • Which of your security-relevant functions have been outsourced, and do those vendors operate under the same identity verification procedures as your internal teams?
  • What is your organization's breach history, and does it show a pattern across subsidiaries, vendors, or acquired entities? A pattern is a structural signal, not a coincidence.

Mapping the Human Circuits. Realistically, no organization has the resources to map out and defend its human circuits in their entirety. That kind of distributed situational awareness is unlikely to ever be achieved. The audit questions are provided as a means to sharpen focus on decision priorities to identify the critical vulnerabilities. Where these gaps are largest, organizations must allocate resources or limit which employees and vendors are authorized to perform these functions.

While you have ignored these gaps, assume attackers have already conducted a thorough analysis. The above attacks were the result of reconnaissance against organizations whose cognitive defense networks vulnerabilities were predictable because they were unmapped.

AI can be used to analyze critical channels when human resources are scarce. But humans must still identify the critical processes and workflows. This means identifying the signals Circuit 1 can discard: requests that route around a vishing blind spot, verification steps skipped due to urgency, callers who match a known social engineering script. The decision on what to do with those signals will occur in Circuit 2. Organizations require situational awareness for tactical and strategic superiority. Mapping yours is not a cultural initiative, a training program, or a showpiece for a board. It requires the same scrutiny and deliberation that organizations use to plan their business strategies and the technical attack surface.

What is feature engineering

In practice, feature engineering is both science and a bit of witchcraft. It often involves both iteration and experimentation to uncover hidden patterns and relationships within the data. For instance, a data scientist might transform raw sales data into features such as average purchase value, purchase frequency, or customer lifetime value, which can significantly boost the performance of a churn prediction model. By thoughtfully engineering features, practitioners can provide machine learning models with the most informative inputs, ultimately leading to better accuracy and more robust predictions.

What’s more?

  • Incorporate more and more data sources
  • Feature engineering platform

What is data engineering

As we mentioned above, feature engineering is certainly a subset of data engineering. It involves the ingestion of data from a source, applying a series of transformations, and making the final result available to be queried by a model for training purposes. You can construct feature engineering pipelines to resemble data engineering pipelines, having schedules, specific source and sink destinations, and availability for querying. However, this configuration would only really apply once you have surpassed the experimentation stage and determined a need for a consistent flow of new feature data.

What is feature engineering

Image description

1. Functions

Functionally, there is nothing to differentiate data vs features - data points (link). Where feature engineering and data engineering really differ is in the objectives and motivations for constructing the pipelines. In general, data engineering serves a broader, more unified purpose than feature engineering. Data engineering platforms are constructed to be flexible and universal, ingesting various types and sources of data into a unified storage location where any number of transformations and use cases can be applied. The intent of a well constructed fact table or gold layer in a data lake is to provide a single source of truth that answers many different questions, produces many reports, and can be consumed by many downstream customers.

2. Practise

And in practice, an organization’s data engineering team will be responsible for the curation and maintenance of all data pipelines, not just those that relate to machine learning. These pipelines may power BI dashboards used by C-Suite, auditing reports that feed payroll, or event logs that show a user’s history of actions within the application.

Feature engineering, on the other hand, serves a specific purpose, finding the tailored inputs and columns that will generate the best predictive results for a machine learning model. Data scientists and machine learning engineers are not tasked with developing a universal data model that will ingest all data points throughout an organization, they just need to select, curate, and clean the data needed to power their models.

3. Machine learning

Now, as machine learning teams grow and begin to incorporate more and more data sources into their models, their feature engineering platform may start to resemble a larger data engineering platform in the tools and methodologies they employ. But, the intent is not to establish flexible data models that can be used throughout the organization - it is simply to power their machine learning models.

Enter your contact info and we'll be in touch soon

Oops! Something went wrong while submitting the form.