Cyberdise AG

Zeitenwende in Social Engineering: Why Vishing Is Your Next Line of Defense

Published Date:

A hand reaching for an office desk phone showing an incoming "CEO" call with an AI voice waveform, surrounded by icons for voice calls, SMS and AI — symbolizing AI-powered vishing attacks.
Zeitenwende in attack vectors: technology is becoming secure — humans are the new target.

Picture this: your phone rings. The display shows your CEO’s name. When you pick up, you hear her exact voice, clear and crisp. She’s at the airport, in a hurry, and asks you to approve a multi-factor authentication (MFA) prompt right now so she can log in to an urgent board meeting.

Would your employees comply? In most organizations, the honest answer is: “Maybe” (read: yes). This is exactly the reaction a realistic vishing simulation makes visible — before a real attacker does.

At Cyberdise, we often talk about how leadership and culture shape cybersecurity. Yet even the strongest security culture faces a massive paradigm shift. Attackers no longer hide only behind text-based emails; they call your team directly, armed with AI-powered voice clones that are indistinguishable from trusted managers or partners.

This is vishing (voice phishing). To counter this psychologically potent threat, we have to bring the defense directly to the phone lines.

The Blind Spot in Modern Awareness Training

For years, cybersecurity training focused heavily on the inbox. Companies simulated phishing emails and (hopefully) taught colleagues to spot suspicious URLs.

But while technical filters have become excellent at catching most spam, they can’t scan a live conversation in real time the same way. Attackers know this. They deliberately exploit human factors like authority, urgency and trust. On top of that, attacks now combine several channels: imagine an SMS from the CEO arriving 15 minutes before the vishing call — “Calling you shortly, need your help.”

When psychological pressure is then applied on the phone, theoretical knowledge often isn’t enough. Employees need behavioral resilience. They have to know how to verify callers safely, without letting panic take over.

Behind the Scenes: Realistic Vishing Simulations as a Learning Method 

To train these scenarios safely, modern simulation modules recreate exactly these high-pressure situations. It’s not just about whether someone picks up, but how the interaction unfolds. An effective risk-prevention system is defined by the following:

Cyberdise platform screenshot showing the configuration of a conversational AI vishing simulation — the "HR Payroll Direct Deposit Update" scenario with persona, success criteria and the AI caller's system prompt.
Figure 1: Configuring a conversational AI vishing exercise in Cyberdise Awareness: scenario, persona, success criteria and call behavior.
  • Behavior-based analysis: A successful vishing simulation measures at which point a manipulation takes hold. The goal is to identify the critical moments where sensitive information is at risk or unauthorized actions are triggered.
  • Technical stability and scalability: Running such training requires precise coordination of system resources. Intelligent scheduling and awareness of technical capacities (such as concurrency limits) ensure the simulations run smoothly and deliver clean, meaningful data for security analysis.
  • Regulatory compliance: The (apparent) use of false identities in telephony is strictly regulated in most countries. Little wonder that, unlike CYBERDISE, most other security-awareness platform vendors offer no vishing-simulation capability at all — or only a rudimentary one with very little flexibility.

Analyzing these interactions gives security teams deep insight into the psychological patterns that could make an attack succeed, and shows where targeted training needs to start.

Why Europe Can’t Ignore Vishing

For companies in Europe, vishing is no longer optional — it’s a regulatory necessity.

With the implementation of the NIS-2 Directive and the requirements of DORA in the financial sector, realistic testing of cyber risks is now legally required. And the old argument “we won’t be attacked because we don’t speak English” no longer holds. Modern AI tools let attackers launch fluent vishing attacks in virtually any national language at the push of a button.

Meaningful Policy Implementation, Leadership and Omnichannel Behavioral Defense Engineering

Good leadership ensures that regulations and policies are implemented sensibly and to the right degree across the organization. BDE Omnichannel then enables the targeted operationalization of multi-channel vishing exercises — personalized, targeted, and with very little effort for the security team. The real — and in the age of AI, psychologically optimized — conversational phone attacks by criminals are turned by our product into real-time vishing simulations. This way, we train safe behavioral habits on the phone right in the stressful workday.

Vishing is the new frontier of social engineering. It’s time to build a defense that is truly designed for it.

Awareness doesn’t stop attacks. Behavior does. Speed contains.

So Long, Palo

PS: Our next “Vishing Deep Dive” webinars: 30 July and 2 September, 4:00 PM (Zurich time).

Check out last weeks article about Leadership in Cybersecurity

Frequently Asked Questions

 

What is a vishing simulation?

A vishing simulation is a controlled training format in which employees receive a realistic but harmless voice-phishing call, to test and train how they respond to urgency, authority pressure and impersonation on the phone. Unlike a classic email phishing test, the reaction is observed and evaluated in a real, high-pressure live conversation.

 

How is vishing different from classic phishing?

Phishing arrives via email or text and can be caught by technical filters before a human even has to react. Vishing happens as a live phone call, where psychological pressure (urgency, authority, trust) is built in real time and filters barely help — here, only the called person’s behavior counts.

 

How do I recognize a vishing call?

Typical warning signs are unusual urgency, the build-up of pressure or panic, a request for immediate action (e.g. approving an MFA prompt or releasing data), and a phone number or voice that feels familiar but is untypical in context. If you feel pressured or manipulated, end the call and call back through an independent, known channel to verify the identity.

 

Why are AI voice clones a new danger for companies? 

Modern AI tools can convincingly reproduce an executive’s voice from just a few seconds of audio — for example from a social-media video. This enables CEO-fraud-style calls that are almost indistinguishable from the real person, so the classic “I recognize the voice” trust heuristic no longer works reliably.

 

Are vishing simulations legally permissible in Germany and Switzerland?

Vishing simulations touch on telephony regulations, e.g. regarding the (apparent) use of others’ identities or phone numbers, and must therefore be designed to be legally compliant. Reputable providers run such exercises transparently, pseudonymized and in line with the respective national rules, rather than simply spoofing caller IDs.

 

What role do NIS-2 and DORA play in vishing simulations?

NIS-2 obliges affected sectors, and DORA the financial sector, to test cyber risks realistically and regularly, including social-engineering scenarios. Because vishing specifically targets the human factor, training against telephone attacks is increasingly part of the demonstrable duty of care for companies in these regulated areas.

 

How often should a company run vishing simulations?There is no single mandatory frequency, but common practice in security-awareness programs is regular, recurring execution — often quarterly or combined with other channels such as SMS and email — so that safe behavior on the phone becomes a trained habit rather than a one-off learning experience.

Enjoyed reading? Subscribe to our blog!

    [recaptcha]