Heimdal
article featured image

Contents:

Most of the cyber incidents landing on our desks these days start with someone believing a lie.

It’s not a brilliant piece of code that causes most breaches. A convincing email, a confident phone call, and a fake sense of urgency can make people hand over exactly what the attacker needs.

Last week I talked to Aran Dharmeratnam about that, although he’s not a cyber security person. He built a career in the physical world, in risk intelligence and private investigations.

The skill sitting at the centre of everything he does would stop half the incidents we deal with. Aran’s superpower is the ability to read people and anticipate their behaviour.

How Aran learned to read people

Aran didn’t learn this skill in a classroom. His first security role was as a door supervisor in Sheffield.

It was very much about learning to de-escalate or prevent trouble from getting in. It was about reading behaviour, reading body language.

Several years later, martial arts training around the world sharpened those instincts he now uses professionally.

That background is exactly why I wanted to talk to him.

While people working in cybersecurity spend their careers thinking about technical controls, Aran thinks about the human sitting in front of a screen or facing down a scammer. How can that person tell if they’re being played?

When clients come to Aran, most are dealing with something that’s already gone wrong. His method starts simply. He listens.

Sometimes it can be the most seemingly minute detail that they give you that’s incredibly impactful.

If the problem goes beyond what he can handle directly, he brings in specialists who can.

But the skill he teaches clients, the one he calls out as his own, is reading third-party deception. In a world where cyber incidents increasingly start with a scam rather than an exploit, that’s not a soft skill. That’s the actual perimeter.

The people doing social engineering aren’t amateurs, so it’s not that easy to recognise it. Aran says:

They can be very good at exploiting vulnerabilities. They can also be very good at doing their own intelligence gathering and looking for weaknesses, looking for gaps.

Human vulnerabilities vs. software flaws

People make mistakes. Aran thinks they’re “always going to have vulnerabilities”, just like software. If any software needs patches to become safer, why not accept the same is true for humans?

Aran locates the real risk in what he calls the grey area between cyber and physical security. His example was simple:

Someone has their phone stolen and then their data gets accessed.

A second version of the same gap is:

Someone reading a stranger’s emails off a laptop screen over their shoulder on a train.

Neither needs a single line of malicious code, both exploit the same flaw, a person not being aware of what’s happening around them.

Aran’s suggestion for patching this kind of vulnerability is training risk awareness.

How to train that radar yourself

So how do you actually build Aran’s superpower rather than just admire it from a distance?

He says training starts before any research or reading. The first thing you need to do is sharpen your own instincts.

Develop your own intuition. The human body’s an incredibly powerful awareness mechanism.

This skill isn’t something exotic that only a few chosen ones can develop. It’s something most people already have but have quietly stopped using.

To reconnect with it, observe the moments that push you to lower your guard. Look for the details that create a sense of urgency or false familiarity. When you get that feeling, treat it as a reason to slow down and dig deeper before acting.

The second half of building that instinct is deliberate exposure. Aran’s advice was to develop a genuine, ongoing interest in security. If you don’t do this already, start reading about emerging threats.

As Aran told me,

The more people immerse themselves in their own security and the world around them, the better they’re going to be.

That won’t necessarily turn them into risk analysts, but it will help them recognise fraud patterns.

Why risk awareness matters more than any tool

None of the above replaces technical controls. But it addresses the part of the attack surface no software update can patch.

If your team and your clients can tell when they’re being manipulated, like an urgency that doesn’t add up, a request that skips the normal process, they’ll be able to avoid a breach.

Even if they won’t become immune to manipulation, risk awareness training can make them quicker to spot it and recover from it.

The technical stack is still the foundation.

But if the incidents we’re seeing are increasingly powered by a lie rather than an exploit, the sharpest tool in the box is the one Aran’s spent his whole career building. It’s the ability to read a person and know when something’s off.

If you liked this article, follow us on LinkedIn, Reddit, X, Facebook, and Youtube.

Author Profile

Adam is the Cybersecurity Advisor at Heimdal. With over 15 years in law enforcement, where he served as a Detective Sergeant leading Covert Operations and Cyber Crime teams, Adam transitioned to cybersecurity in 2016. Known for simplifying complex topics, Adam leverages his investigative and communication experience to engage leaders and end users alike, driving stronger cyber resilience.

CHECK OUR SUITE OF 11 CYBERSECURITY SOLUTIONS

SEE MORE