TL;DR: AI-powered vishing is making voice phishing more convincing, scalable, and adaptive than traditional awareness training can absorb, according to Living Security Human Risk Management Platform. The practical shift is toward automated simulations that measure real employee behaviour under pressure and connect human-risk data to identity and access decisions.
NHIMG editorial — based on content published by Living Security Human Risk Management Platform: What Is Automated Vishing... Why You Need Automated Vishing Security Testing Now
By the numbers:
- Phone-based scams are not just more sophisticated; they are also more frequent, with some reports showing a surge of over 400% in just one year.
- Research shows that organisations running regular simulations can achieve up to 90% attack recognition rates.
- Studies show that 33% of employees still disclose sensitive information during a vishing attack.
Questions worth separating out
Q: How should security teams handle voice-based social engineering in identity programmes?
A: They should treat voice-based social engineering as an access-risk control problem, not just a training issue.
Q: Why do AI-generated vishing calls create more risk than traditional phone scams?
A: AI-generated calls are harder to detect because they can mimic trusted voices, adapt their script in real time, and scale across many targets without the limitations of a human caller.
Q: How do organisations know if vishing controls are actually working?
A: They know by measuring behaviour under pressure, not by counting training completions.
Practitioner guidance
- Measure disclosure behaviour, not just awareness completion Track whether users reveal passwords, MFA codes, or remote-access details under scripted pressure, then segment results by department, privilege level, and business process so remediation targets the highest-risk roles first.
- Connect simulation outcomes to identity controls Use vishing-test results to inform step-up verification, help-desk callback procedures, and extra scrutiny on password reset and account recovery requests for privileged users.
- Prioritise phishing-resistant authentication for exposed workflows Where vishing can lead to credential disclosure, reduce dependence on codes that can be spoken over the phone and tighten recovery paths around accounts with administrative or financial reach.
What's in the full article
Living Security Human Risk Management Platform's full blog post covers the operational detail this post intentionally leaves for the source:
- Scenario design for AI-generated voice clones and adaptive script variations in simulation programmes
- Behavioural scoring logic that distinguishes disclosure, hesitation, escalation, and reporting patterns
- How to correlate human-risk results with identity and access data for prioritised interventions
- Examples of targeted micro-training and policy nudges triggered by simulation outcomes
Automated vishing testing: are your voice attack controls keeping up?
Explore further
Voice attacks are now an identity problem, not only a training problem. The article shows that attackers are targeting the human decision point that sits in front of credentials, MFA, and help-desk workflows. Once a caller persuades a user to share a code or approve a reset, the event becomes an identity compromise path, not merely a communications incident. For IAM and PAM teams, that means voice-channel risk belongs in the same governance conversation as phishing-resistant authentication and privileged workflow protection.
A question worth separating out:
Q: Who is accountable when a vishing attack leads to account takeover?
A: Accountability usually spans identity operations, service desk ownership, and security governance because the failure often sits in the recovery process, not the login prompt. Teams should review who approves resets, who audits enrolments, and who owns containment when a legitimate session is abused.
👉 Read our full editorial: Automated vishing testing reveals the limits of awareness training