Cyber awareness training was built for the wrong world.

Applying the mental model I learned from my quantum physics lecturer.

By Aarti Samani | Keynote Speaker | Executive Trainer

AI Opportunities, Risks and Cyber Awareness Training

Key takeaways

  • Cyber awareness training is still teaching binary discrimination (safe versus unsafe, real versus fake) for a world that has gone probabilistic.
  • Cybersecurity is now entangled with geopolitics, supply chains, mental health, and narrative manipulation. Nothing is local any more.
  • Four principles from quantum physics map directly onto today’s cyber threat landscape: entanglement, superposition, observer effect, and non-linear time.
  • Mental health has become one input into cyber resilience, alongside skill, time, tools, and organisational permission.
  • Every person needs security instinct now. Most are still being taught hygiene.

Quantum physics was the subject I loved most at university. It was taught by Prof. Euan J. Squires at Durham, my favourite lecturer. Just as I was entering my final year and looking forward to learning more from him, Prof. Squires died very suddenly. We lost a brilliant mind. It was the saddest day of my time at Durham.

In teaching me quantum physics, he gave me something profound. A way of thinking and viewing the world. I did not go into a career in physics. I went into product, into business, into building companies. The principles Prof. Squires taught me became the lens I look through when I need to make sense of an environment that is complex, contradictory, and fast-moving.

The lens of quantum physics has come into daily use, as I look at what is happening in cybersecurity.

The view that follows is from inside the work I do at Shreem Growth Partners, where I train boards and executive teams on AI fraud, deepfake resilience, and cyber risk, and from the keynotes and executive sessions I teach at Cambridge and MITxPro.

Why is cyber awareness training failing?

Cyber awareness training is failing because it was built for a binary world that no longer exists.

Do not click suspicious links. Do not share your password. Look for the verified badge. The training assumed clean lines between safe and unsafe, internal and external, real and fake.

That world is gone.

State actors now operate through your supplier. A single supply chain compromise reaches hundreds of organisations. A synthetic candidate clears your hiring process and is now an employee with access to your systems. A piece of AI-generated content reshapes public opinion on an issue before anyone can authenticate it. The healthcare data you trusted to an app is now feeding decisions about your insurance, your employment, perhaps your future.

Cybersecurity is no longer a department. It is the texture of the world we live in.

Old cyber hygiene cannot navigate this environment. It was built for binary discrimination in a world that has gone probabilistic.

What we need now is security instinct: the trained capacity to be vigilant and to judge in real time. Building it requires a different kind of thinking.


Why apply quantum thinking to cybersecurity?

Quantum physics is useful for cybersecurity because it describes a world that does not move in straight lines, and the digital environment we operate inside has stopped behaving classically too.

Particles exist in many states. A single particle is many possibilities at once until something forces it into one. A wire transfer instruction in your queue is legitimate and fraud at once, until verification settles which.

Events separated by huge distances are linked. Once two particles are entangled, what happens to one happens to the other, instantly. The moment a vendor you trust is breached, you are inside the breach with them.

Observation is never neutral. It requires interaction, and interaction has consequences. The moment you respond to a perpetrator, a connection is established and fraud moves forward.

Time does not run only forward. Past and future shape each other. Today’s stolen data feeds tomorrow’s fraud, and today’s encrypted secrets will be read in a few years.

For decades, that was a description of subatomic physics. It is now also a description of the digital environment most of us live and work inside.

Four principles, all from quantum, that I find useful when I think about cybersecurity today, and that I keep returning to in the keynotes and executive sessions I teach.


1. What is entanglement in cybersecurity?

Entanglement in cybersecurity means that nothing is local. Cyber risk is connected to geopolitics, supply chains, your personal life, and your mental health.

In quantum physics, two particles can become entangled. After that, they are linked. What happens to one affects the other instantly, regardless of distance. The principle now describes how the digital environment behaves.

  • A compromise at one IT vendor (SolarWinds, 2020) reached around 18,000 organisations including the US Treasury and the Department of Justice.
  • A hostile state’s strategic objectives are pursued through an attack on a small business inside your supply chain.
  • Data you posted on an app years ago is being used to clone your voice and target your parents.

There are no isolated incidents any more. A breach you read about on the other side of the world has already touched a system you depend on. If you only see what arrives in your inbox, you are missing where the attack started and where it is going next.


2. What is superposition in cybersecurity?

Superposition in cybersecurity means one signal can carry many meanings at the same time, and only deliberate verification reveals which one is true.

In quantum physics, a system does not have a single state until it is observed. It exists as a probability across many possibilities. The same logic now applies to digital interactions.

  • A LinkedIn message can be a recruiter, a state intelligence officer mapping your network, or a fraudster gathering material. All three are common. You cannot tell from the message itself.
  • A nation state cyber operation can be deterrence, espionage, sabotage, or preparation for a future war, all at the same time, depending on who is reading it.
  • An AI agent contacting your customer service line can be a curious user, a competitor probing for information, or an attacker testing your defences.

The old training said: sense check the signal, then act. The signal is no longer enough. Intent has to be factored in. The work of reading and understanding the intent has become part of the job.


3. What is the observer effect in cybersecurity?

The observer effect in cybersecurity means that disclosure changes the outcome. What becomes visible is never neutral, and the act of revealing a cyber event reshapes what happens next.

In quantum physics, measurement is intervention. The act of measuring shapes what comes next. Cybersecurity now operates the same way.

  • Publicly attributing a cyber attack to a state actor changes the diplomatic response, the market response, and what the attacker does next.
  • A breach quietly contained has very different consequences from one publicly reported, even when the technical facts are identical.
  • The defensive techniques we publish become training material for the people designing the next attack.

There is no neutral observation here. Choosing what to disclose, when, and how, is a decision with consequences that reach far beyond the moment. This is one of the conversations I have most often with the boards I advise.


4. How does non-linear time apply to cybersecurity?

Non-linear time in cybersecurity means cyber operations run across multiple time horizons at once. The past resurfaces, and adversaries are already preparing for the 2030s using the data they steal today.

In quantum physics, time does not always run in a clean line. Past and future can influence each other. Events do not arrive in clean order. Cybersecurity now behaves the same way.

  • Adversaries are stealing encrypted data now, knowing they cannot read it yet, because they expect to break the encryption with quantum computers in the 2030s. The technique is called harvest now, decrypt later. It is happening today.
  • Stuxnet was designed and built years before it was used. State actors are placing capability now for moments that will matter in three or five years.
  • A breach from 2014 resurfaces in 2026 and the data inside it feeds a deepfake aimed at today’s CFO.

Cybersecurity happens at the speed of strategy, on horizons of decades. The news cycle is not where it lives. If your defence operates only in the present, you have already lost the time dimension of the game.


What does this mean for humans inside cybersecurity?

For humans, cyber awareness has to become security instinct. The verification work that used to be done by perimeters and policies now happens inside the person, and the person doing it needs more than rules. Security instinct depends on skill, organisational permission, tools, time, and cognitive steadiness, all working together.

Security instinct needs clarity. It needs the ability to hold several possible meanings at once. It needs the discipline not to jump at the first signal. It needs sitting with uncertainty long enough to verify. It needs being able to step back when you are tired, stressed, or in a hurry, and recognise that this is exactly the moment an attacker is looking for.

That capacity does not appear by accident. It is trained. It is permitted by organisational culture. It depends on tools and frameworks that make verification practical. It needs operational time and space; a team rewarded for speed over scrutiny breeds the exact conditions attackers exploit. And it needs cognitive and emotional steadiness, because a clouded mind cannot read intent.

Attackers know all of this. They time their approaches for when security instinct is at its weakest. The board member checking emails between back-to-back meetings. The finance manager under quarter-end pressure. The new hire who does not yet know what to question. Manufactured urgency, false authority, and emotional pressure work on people who lack the time, training, or space to verify.

This is what cyber resilience now means in practice: a population of humans with security instinct, alongside the stack of controls. Building that means investing in skill, in culture, in tooling, in time, and in the cognitive resilience of the people doing the work.

This is the lens I bring into the executive sessions I teach. You cannot raise a board’s cyber resilience without raising its capacity for verification, judgement, and pause.


What way of thinking does cybersecurity now need?

Cybersecurity now needs a way of thinking borrowed from quantum physics: probabilistic, interconnected, observer-aware, and operating across multiple time dimensions.

Cyber awareness, as it stands, will not survive this transition. It was a hygiene programme designed for a perimeter that is no longer there. What we need now is larger. A way of building the security instinct people need to navigate a world where signals are multi-valued, where everything is connected, where what we see changes what we get, and where past and future are both inside the present.

This is the way of thinking Prof. Squires gave me. The principles he taught reach far beyond waves and particles. They are about how to read a complex, contradictory, alive world. That world has now arrived inside cybersecurity. Inside business. Inside families. Inside ourselves.

Every person is navigating this world now. Whether they know it or not.

Most are still being taught hygiene.

What is security instinct?

Security instinct is the trained human capacity to operate safely in a digital environment shaped by AI. Where cyber hygiene relied on simple rules (do not click suspicious links, verify badges, check for the padlock), security instinct asks more.

It is the ability to read intent in messages and behaviour, spot how risk moves through the systems and people you depend on, recognise that what you disclose changes what happens next, and think across short and long timeframes.

Building it depends on skill, organisational permission to pause, tools and frameworks, time, and cognitive steadiness.

Why is the human now the verification layer in cybersecurity?


Because the digital environment has stopped behaving in ways that perimeter controls and rule-based training can navigate alone.

Signals carry multiple meanings at once. Adversaries operate through trusted vendors. Disclosures change outcomes. Old data resurfaces as new fraud.

The human reading each signal, deciding what to verify, and choosing what to disclose has become the active verification layer. Cyber resilience now depends on the security instinct of the people doing the work. That depends on skill, organisational permission, tools, time, and cognitive steadiness.

What replaces traditional cyber awareness training?

Cyber awareness training based on hygiene rules will need to evolve into training that builds security instinct: cognitive resilience, the ability to read intent in messages and behaviour, awareness of how risk moves through connected systems, and the discipline to pause when something is uncertain.

The shift is from rules to judgement, from perimeter thinking to network thinking, and from compliance to security instinct.

How do quantum physics principles apply to cybersecurity?


Four principles map directly.

1. Entanglement explains how a single supply chain compromise affects thousands of organisations.

2. Superposition explains how a digital signal can be multiple things at once until verified.

3. The observer effect explains how disclosure changes the outcome of a cyber event.

4. Non-linear time explains why adversaries are stealing data today to decrypt with quantum computers in the 2030s.

The mathematics of the quantum world increasingly describes the dynamics of the digital one.

Why is mental health now part of cybersecurity?

Because the human is the active verification layer in a probabilistic threat environment.

When mental health is poor, the cognitive capacities that security instinct requires are degraded: pattern recognition, the ability to pause, tolerance for uncertainty, and resistance to manufactured urgency.

Social engineering campaigns deliberately target people in moments of stress, fatigue, and emotional vulnerability. Mental health is an important input into security instinct, alongside skill, organisational permission, tools, and time.