Organisations should use automation to schedule campaigns, group users, track outcomes, and deliver immediate follow-up training. The programme should also adapt scenarios to current threats, including AI-generated voices and personalised lures. That reduces manual overhead while keeping the exercises realistic, repeatable, and useful for ongoing risk reduction.
Why This Matters for Security Teams
A scalable vishing programme is not just a training exercise, because voice-based social engineering now moves faster than manual security awareness teams can react. Organisations need repeatable campaigns, measurable outcomes, and immediate remediation without turning every exercise into a coordination project. That matters even more as attackers blend human persuasion with AI-generated voices and personalised pretexts, which are far easier to operationalise at scale than traditional phone scams.
Current guidance suggests treating vishing as a measurable control, not an occasional awareness event. That means targeting high-risk populations, tagging campaign results to job roles or business units, and automating follow-up content based on user behaviour. The broader identity risk picture reinforces why this is necessary: NHIs outnumber human identities by 25x to 50x in modern enterprises, and NHI Mgmt Group reports that only 5.7% of organisations have full visibility into their service accounts in the Ultimate Guide to NHIs — Why NHI Security Matters Now. The same operational blindness that affects NHIs shows up in awareness programmes when results live in spreadsheets instead of systems.
Security teams that rely on manual scheduling and ad hoc reporting usually end up measuring participation, not resilience. In practice, many security teams encounter repeat vishing failures only after a real callback-based social engineering incident has already succeeded, rather than through intentional programme design.
How It Works in Practice
The scalable model is built around automation, segmentation, and closed-loop remediation. Campaign orchestration should be scheduled in advance, pulled from identity and HR data, and distributed by role, geography, or business function. The platform should record outcomes automatically, such as call answered, number shared, call escalated, or reporting behaviour, then trigger the next step without analyst intervention.
That workflow is most effective when it is paired with threat-informed scenarios. Instead of generic “confirm your password” scripts, use lures that reflect current tactics, including executive impersonation, urgent vendor-payment calls, help desk impersonation, and AI-generated voice cloning. The point is not to maximise embarrassment; it is to measure whether people recognise social pressure, policy exceptions, and authority cues. NIST’s Cybersecurity Framework 2.0 supports this kind of continuous improvement because the control objective is not a one-time test, but a repeatable risk reduction process.
Practical teams also automate follow-up. A failed simulation should route the user into micro-training, while a reported attempt should reinforce the desired behaviour and feed metrics into dashboards for managers, security operations, and audit. Where possible, tie the programme to phishing and email-security telemetry so that phone-based and message-based lures inform each other. NIST’s NIST AI 600-1 GenAI Profile is useful here because AI-generated voice content changes the realism baseline, and the programme has to adapt to that shift rather than assume human callers are the only threat. For reference on why identity abuse is so persistent, see MGM Resorts Breach 2023 — Scattered Spider.
- Automate campaign assignment by role, region, and risk tier.
- Use scenario libraries that rotate based on current threat intelligence.
- Trigger training immediately after failure, not in a separate manual queue.
- Track reporting rates, repeat failures, and manager-level trends automatically.
- Feed outcomes into broader security awareness and incident response metrics.
These controls tend to break down in heavily centralised organisations with disconnected HR systems because the campaign logic cannot reliably target or update users in real time.
Common Variations and Edge Cases
Tighter automation often increases governance overhead, requiring organisations to balance realism and scale against privacy, legal review, and employee trust. The operational tradeoff is real: the more personalised the scenario, the more careful the review process must be, especially when voice cloning or executive impersonation is involved.
Best practice is evolving for these edge cases. There is no universal standard for how far to personalise vishing content, but most mature programmes keep a narrow approval path for sensitive scenarios and maintain a clear ban on collecting unnecessary personal data. Organisations should also separate training goals from disciplinary goals, or employees will stop reporting attempts and the metrics will become unreliable. The NIST IR 8596 Cyber AI Profile is relevant when AI-generated content is used in scenarios, because the programme needs controls for model risk, prompt safety, and output governance as well as awareness delivery. For the identity security context behind this kind of operational discipline, see Ultimate Guide to NHIs — Standards.
Another common edge case is organisations that overfit campaigns to a single business unit or incident theme. That creates short-term engagement but weakens long-term resilience, because attackers change pretexts faster than annual awareness calendars do. The better model uses small, frequent, automatically varied tests so the programme stays relevant without creating manual work for security staff.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Agentic AI Top 10, CSA MAESTRO and OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST AI RMF and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Agentic AI Top 10 | A1 | Adaptive, threat-informed simulations mirror runtime agentic risk. |
| CSA MAESTRO | GOV-02 | Governance of automated exercises needs clear ownership and policy. |
| NIST AI RMF | GOVERN | AI-generated voices require governance for safe, accountable use. |
| NIST CSF 2.0 | PR.AT-1 | Awareness and training are directly addressed by this function. |
| OWASP Non-Human Identity Top 10 | NHI-07 | Scalable programmes need lifecycle visibility and automation. |
Use dynamic scenarios and automated response loops to test decision-making under realistic attacker pressure.
Related resources from NHI Mgmt Group
- How should organisations roll out passkeys on Android without creating user friction?
- How should organisations modernise IGA without creating more manual work?
- How should organisations phase an IGA programme without creating more access drift?
- How do organisations reduce SaaS sprawl without creating more manual work?