TL;DR: AI-generated voice clones are making vishing harder to spot, and Living Security Human Risk Management Platform argues that simulation data can turn human susceptibility into a measurable risk signal. The practical shift is from awareness-only training to behaviour-led intervention, because voice phishing now bypasses many technical controls and directly targets identity verification and trust.
NHIMG editorial — based on content published by Living Security Human Risk Management Platform: Vishing Attack Simulation... Why Run a Vishing Attack Simulation for Employees?
By the numbers:
- 70% of companies have been targeted by fraudulent phone calls.
Questions worth separating out
Q: How should security teams reduce vishing success against privileged users?
A: Security teams should harden the workflows that vishing targets first: password resets, MFA resets, help desk overrides, and privileged support requests.
Q: Why does DNS redundancy matter for identity and access programmes?
A: DNS underpins service reachability for SSO, authentication endpoints, SaaS access, and workload connectivity.
Q: What do organisations get wrong about voice phishing simulations?
A: They often stop at pass or fail scores.
Practitioner guidance
- Implement executive impersonation verification Require a second, out-of-band verification path for any request that changes credentials, payments, or privileged access when the request arrives by phone.
- Tie simulation results to identity risk scoring Correlate vishing outcomes with role, privilege, and account recovery exposure so the highest-risk users receive targeted interventions first.
- Protect account recovery and reset workflows Add stricter validation for password resets, MFA resets, and help desk approvals because these are common vishing end goals.
What's in the full article
Living Security Human Risk Management Platform's full article covers the operational detail this post intentionally leaves for the source:
- Simulation planning guidance for tailoring scenarios to employee roles and risk profile
- Examples of targeted micro-training triggered by specific vishing behaviours
- Program design advice for correlating simulation outcomes with identity and threat intelligence
- Recommendations for measuring behavioural change over repeated simulation cycles
AI voice cloning and vishing simulations: are your controls keeping up?
Explore further
AI voice cloning has turned vishing into an identity verification problem. The article is right to frame the threat as more than awareness failure, because the attacker is no longer just asking for trust. The attacker is attempting to fake identity context well enough to trigger privileged actions, credential disclosure, or policy exceptions. That creates an identity-adjacent attack surface that IAM teams cannot ignore, especially where help desks, finance teams, and executives can change account state. Practitioner conclusion: voice-based verification must be treated as part of identity governance, not a soft-skills issue.
A question worth separating out:
Q: Who should own vishing response when the attack targets credentials or approvals?
A: Ownership should be shared across security awareness, IAM, help desk operations, and fraud or finance controls, because the attack can cross all of them. If a phone call can change access or move money, the response cannot sit in one team alone.
👉 Read our full editorial: Vishing simulations are becoming essential against AI voice fraud