Blog

July 3, 2026

The weakest link is cognitive

SecurityMentalismSpeaking

I teach social engineering awareness using mentalism. The overlap with security is not a metaphor.

I am a practising mentalist. I also deliver corporate sessions on social engineering and cognitive vulnerability, and enterprise lectures on communication and decision-making that use the same material.

People assume the mentalism is the hook and the security content is the substance. It is closer to the reverse.

The same mechanism, different intent

A mentalism effect does not usually work because of hidden technology. It works because attention is a limited resource that can be directed, because memory reconstructs rather than replays, and because people commit to the first plausible explanation and stop looking for a second one.

A social engineering attack works for exactly those reasons. The pretext is plausible, the urgency narrows attention, and the target reaches the first explanation that fits and acts on it. Nothing is broken. Everything works as designed. The design just includes a person.

This is why the sessions land. I am not using magic as a metaphor for manipulation. I am demonstrating the actual mechanism on the actual audience, and then explaining what just happened to them.

Why demonstration beats warning

Standard awareness training tells people to be careful and shows them a phishing email with a spelling mistake. Everyone nods. Everyone believes they would have caught it. Then the real attempt arrives with no spelling mistake, at 4pm on a Friday, from a name they recognise.

The gap is not knowledge. It is that nobody believes it would work on them.

You cannot close that gap with a slide. You can close it by doing it to them, in a room, with no stakes, and letting them feel the specific sensation of having been certain and wrong. That sensation is the entire training. Everything after it is detail.

What it changed about how I build

Two things carried over into the development work.

Friction is a design decision with security consequences. Every step you remove makes the flow smoother for the user and for the attacker. The interesting question is never how to remove all friction, it is which single moment deserves to be slow on purpose.

Users do not read. Not because they are careless, but because reading everything is not a viable strategy for a person with a job. They scan for the shape of what they expect. If your warning looks like the twelve dismissable notices before it, it is decoration. Interfaces get trusted on pattern, not on content, which is precisely what the attacker is counting on.

The honest caveat

I am not a security engineer. I do not do penetration testing, I do not audit infrastructure, and I would not claim either.

What I do is the human layer, which is the layer that most reliably fails and the one most training handles worst. It is an unusual thing for a developer to have on the CV, and it is the part of my work that most changes how I think about the rest of it.