Cyberdise AG

Blog – EN

Zeitenwende in Social Engineering: Why Vishing Is Your Next Line of Defense

Vishing calls using AI-cloned voices bypass even the strongest security culture. Why a realistic vishing simulation is becoming the new line of defense — and how to make your team genuinely resilient on the phone.

Picture this: your phone rings. The display shows your CEO’s name. When you pick up, you hear her exact voice, clear and crisp. She’s at the airport, in a hurry, and asks you to approve a multi-factor authentication (MFA) prompt right now so she can log in to an urgent board meeting.

Would your employees comply? In most organizations, the honest answer is: “Maybe” (read: yes). This is exactly the reaction a realistic vishing simulation makes visible — before a real attacker does.

Are You a Boss? A Good One? And What That Means for Your Cybersecurity

Do you know the hidden risks of your own authority? Cybersecurity doesn’t end with firewalls; it begins with corporate culture. An insight into the mechanisms of how a lack of psychological safety drastically prolongs response times during cyber incidents – and how modern leadership changes the game.
I only started reading genuinely interesting non-fiction books once I was tasked with leadership responsibilities. Since then, a few works have fundamentally shaped me and influenced my entire life. Today, let’s look at two of my most important non-fiction books and the impact they had on me. On top of that, I find it fascinating that, in my opinion, both also have a massive impact on an organization’s cybersecurity when they become part of the company’s core management literature.

Creating ClickFix Exercises with Cyberdise Behavioral Defense Engineering

Cybercriminals have become remarkably good at bypassing technical security controls. Rather than exploiting software vulnerabilities, many modern attacks exploit something much easier: human behavior.
One of the fastest-growing examples is ClickFix. Instead of asking users to click a malicious attachment, attackers guide them through what appears to be a legitimate troubleshooting or verification process. The victim ultimately executes the malicious action themselves.
For security awareness teams, this represents an important shift. Traditional phishing exercises are still valuable, but they no longer cover the full spectrum of modern social engineering. Organizations increasingly need a ClickFix simulation that prepares employees for these interaction-driven attacks before they encounter them in production. This article shows how to create one in Cyberdise Awareness — from scenario selection to delivery and measurement.

A Paradigm Shift in Cybersecurity: CYBERDISE Establishes “Behavioral Defense Engineering” to Combat AI-Driven Threats

For years, the global cybersecurity industry has been fighting the right problem with the wrong methods. While traditional security awareness programs have focused on theoretical knowledge transfer for two decades, measurable organizational risk remains consistently high. A joint study by CYBERDISE and the Lucerne University of Applied Sciences and Arts (HSLU) scientifically confirms what practice has long shown: more knowledge does not automatically translate into secure behavior when employees are targeted by real, psychologically optimized attacks.

The Next Giant Leap: Why It Is Time to Redefine Human Cybersecurity

There are defining moments in the evolution of a company that change everything. Today is one of those days for us at CYBERDISE. We’ve been very close to the market for the past three years. Even when we started, we knew that the awareness industry was heading in a direction we didn’t fully understand back then.

We now clearly understand the market’s needs and pains and know exactly where to go next. Following intensive development and extensive market analysis, we are making a monumental shift forward: we are transitioning from traditional security awareness to Behavioral Defense Engineering (BDE).

Microsoft Defender Attack Simulator: Strengths, Weakness and the Reality of Security Awareness

Microsoft Defender for Office 365 includes its own phishing simulation and awareness platform called Attack Simulation Training. Because it is deeply integrated into Microsoft 365, many organizations automatically assume it is the logical choice for phishing simulations and employee awareness.
And honestly: in some areas, Microsoft Defender Attack Simulator is very good.
But there is also another side that organizations should understand before replacing specialized awareness platforms completely.
This article is intentionally balanced. There are clear advantages — but also structural limitations that become visible very quickly in larger or more mature security environments.

AI: The World’s Greatest Pentester — And Why It Has to Be This Way

What happens when software is no longer attacked only by humans, but by synthetic actors that think differently than we do?

Claude developer Anthropic made headlines last week with the internal release of a new model called Mythos. It is said to be exceptionally good at finding bugs and vulnerabilities in software. Due to these capabilities, Anthropic is refraining from a public release for now and instead aims to work with large tech companies and governments to prevent misuse.

It remains unclear how realistic and actually exploitable many of these vulnerabilities are… at least for humans.