(TL04) (INCYBER) Youna CHOSSE-BENTABED

(TL04) (INCYBER) Youna CHOSSE-BENTABED

🎙 Youna Chosse-Bentabed 👥 7K 📅 April 15, 2026 ⏱ 23 min 👁 45 📄 expert opinion 🧭 2026-08-13
Available in: English (current) Français

Keywords

social engineeringhuman riskcybersecurityphishingAI threats

Summary

In this talk at the INCYBER Forum Europe 2026, Youna Chosse-Bentabed discusses the transition from exposure to resilience in cybersecurity, emphasizing the human factor as the primary attack surface. She illustrates how attackers exploit cognitive biases and social engineering techniques, referencing the famous dress illusion and the Hong Kong deepfake case where a finance director was tricked into transferring $25 million. She explains the dual-system theory of Kahneman, highlighting that 95% of decisions are made by the fast, intuitive System 1, which attackers target. She introduces frameworks like MICE and Cialdini’s principles of persuasion, showing how they are used in both intelligence and marketing. She then demonstrates a practical social engineering attack, from reconnaissance using OSINT and LinkedIn to creating a fake domain and credential harvesting. She emphasizes the importance of human risk management, distinguishing between compliance and maturity, and proposes a maturity staircase from awareness to resilience. She also addresses the impact of AI in industrializing threats and the need for a positive security culture. The talk concludes with a Q&A session where she discusses data leaks and the importance of cyber hygiene.

184 words

Critical Evaluation

Value of the Information & Strength of the Argument

The talk provides valuable insights into the human aspects of cybersecurity, offering a clear explanation of social engineering techniques and their psychological underpinnings. The speaker effectively uses real-world examples, such as the deepfake fraud and the dress illusion, to illustrate complex concepts. The argumentation is persuasive, emphasizing the need to shift from a negative security posture (fear of clicking) to a positive one (ability to respond). However, the talk is largely based on the speaker’s expertise and anecdotal evidence, with limited rigorous scientific backing. The practical demonstration of an attack is compelling but could benefit from more detailed mitigation strategies.

Scientific Rigor, Source Quality, Title Accuracy

The speaker references established frameworks like Kahneman’s dual-system theory and Cialdini’s principles, which are well-known in psychology and persuasion literature. She also mentions the MICE framework used by intelligence agencies. However, specific sources for statistics (e.g., 80% of breaches involve human factor, 180 days to detect) are not cited. The title is minimal and does not convey the content’s depth, but it is not misleading. The talk is an expert opinion rather than a peer-reviewed presentation, so the scientific rigor is moderate. The description provides links to the INCYBER forum and LinkedIn, which are relevant but not direct sources for the claims made.

218 words

Title / Content Match

The title is minimal, only indicating the speaker's name and event, but the content matches the expected topic of cybersecurity and human factors.

Quality & Reliability

7/10

The speaker demonstrates practical expertise in social engineering and human risk management, with concrete examples and references to established frameworks (Cialdini, Kahneman). However, some claims lack precise citations and the presentation is largely anecdotal.

Key Moments

Cited Sources

Concurring Sources

Contribution & Novelties

The talk provides a practical, human-centric perspective on cybersecurity, emphasizing the need to treat human risk with the same rigor as technical risk. It offers a maturity staircase model for building a positive security culture, which is a valuable framework for organizations. The demonstration of a social engineering attack using OSINT and domain squatting is a concrete illustration of the threat.

Pour aller plus loin :

112 words

Radar Profile

The radar profile shows balanced scores across information quantity, quality, technical level, and reliability, indicating a well-rounded presentation. The slightly lower technical level reflects the focus on human aspects rather than deep technical details.

Reliability 7/10

💬 No comments were provided for analysis.