TL;DR: AI-generated voice cloning is making vishing more scalable and more convincing, exposing the limits of compliance-based awareness programmes, according to Living Security Human Risk Management Platform. The practical shift is from generic training to behaviour-focused Human Risk Management that ties simulations, verification protocols, and risk signals to role-specific interventions.
NHIMG editorial — based on content published by Living Security Human Risk Management Platform: Voice Phishing Awareness Training That Changes Behavior
By the numbers:
- some reports indicating a nearly 450% increase in vishing incidents
Questions worth separating out
Q: How should organisations defend against AI-powered vishing attacks?
A: They should combine realistic simulations, role-specific training, and strict verification rules for requests involving credentials, money, or access.
Q: Why do vishing attacks bypass many awareness programmes?
A: They succeed because live conversation creates urgency, authority pressure, and social discomfort in a way email does not.
Q: What do security teams get wrong about phone-based phishing?
A: They often treat phone calls as a low-tech nuisance instead of an identity risk.
Practitioner guidance
- Implement mandatory callback verification for high-risk requests Require an independently verified callback or secondary channel before any password reset, payment approval, privileged change, or vendor bank-detail update proceeds.
- Run role-based vishing simulations for exposed teams Target finance, help desk, executive assistants, and new hires with realistic simulations that mirror the pressure and language attackers use.
- Tie human risk signals to identity workflows Feed simulation results, reporting behaviour, and exposure data into IAM and HRM workflows so high-risk users receive additional guidance, approval friction, or step-up verification.
What's in the full article
Living Security Human Risk Management Platform's full article covers the operational detail this post intentionally leaves for the source:
- Step-by-step guidance for building a vishing awareness programme that changes behaviour rather than just completing training.
- Examples of realistic simulation design for high-risk roles such as finance, help desk, and executive support.
- Practical phone protocols and verification rules that employees can follow when a request feels urgent or suspicious.
- How Human Risk Management ties behavioural signals to intervention decisions across identity and threat data.
AI voice cloning and vishing: is your training keeping up?
Explore further
AI voice cloning has turned vishing into an identity governance problem, not just an awareness problem. When the attacker can convincingly impersonate a known person, the issue shifts from message filtering to verification of intent. That creates a gap between who appears to be calling and who is actually authorised to request action. For IAM and fraud teams, the important conclusion is that trusted voice is no longer a reliable control boundary.
A question worth separating out:
Q: Who is accountable when a vishing attack leads to account takeover?
A: Accountability usually spans identity operations, service desk ownership, and security governance because the failure often sits in the recovery process, not the login prompt. Teams should review who approves resets, who audits enrolments, and who owns containment when a legitimate session is abused.
👉 Read our full editorial: AI voice cloning is exposing the limits of vishing training