Beyond email: why smishing, vishing and quishing belong in every programme
Attackers moved channels years ago. An email-only programme measures your office workers and calls it an organisation.
By SafeLoop Research
Ask a security team which channels they test and the answer is usually email. Ask which channels their incidents came through and the answer is broader — a text message about a delivery, a phone call from the service desk, a QR code on a parking notice.
Three channels, three different failure modes
Smishing
SMS carries no headers to inspect, no sender to hover over and no gateway in front of it. For frontline and field staff it is often the only channel they read within the hour, which makes it both the highest-risk and the least-tested surface in most organisations.
Vishing
Synthesised voice has removed the accent-and-grammar tells people were implicitly relying on. The defence is procedural rather than perceptual: a verification step that does not depend on recognising a voice.
Quishing
A QR code moves the attack onto a personal device, outside your managed browser and your URL protection. Printed lures on invoices, posters and parking notices are effective precisely because the physical medium confers legitimacy.
What changes when you measure all four
Two things, consistently. First, the organisation-wide number gets worse, because you have stopped excluding the population with the least coverage. Second, the number becomes actionable, because it now describes everybody you are responsible for.
Our depot staff had never been in the programme at all. They were the highest-risk group we had and we had no data on them because they have no mailbox.
Security lead, logistics operator, 6,100 people
Doing it without alienating people
- Tell the workforce the programme covers SMS and calls before it does — surprise is not a control.
- Never use distressing pretexts: no fake redundancies, no bonus announcements, no medical results.
- Keep individual results private, and keep the reporting path identical across channels.
Keep reading
Related articles
The 2026 human risk benchmark: what 4.6 million simulations show
Phish-prone rates fall from 33.2% to 4.2% over twelve months — but two-thirds of that lands in the first ninety days.
Read article →Why quarterly phishing tests fail, and what monthly-per-person fixes
Sending one campaign to everybody every three months optimises for administrative convenience. Here is what changes when you pace per person instead.
Read article →Deliverability is the hard part nobody advertises
A simulation sitting in quarantine produces a flattering number and teaches nobody. What actually has to be configured, and why.
Read article →