Skip to content

Financial services

The roles attackers actually target

Treasury, payments and the executive assistant calendar are where the money moves, so that is where the effort goes. Simulations for these teams use the tradecraft aimed at them: vendor-change notices, wire-fraud requests and a cloned voice on a Friday afternoon.

3
channels for exec teams
Tier 5
executive spear-phishing
PCI 12.6
evidence included
HOW THIS WORKFORCE IS REACHEDEmail88%Voice46%SMS22%TRADECRAFT AIMED AT THEMWire fraud, vendor-change notices, cloned CFO voice24%5%Globex Financial · 4,200 people · two quarters

Threat model

Payment fraud is a people process

Almost every large loss runs through a person approving something that looked routine. The scenarios here mirror that: a supplier bank-detail change, an urgent settlement, a call from a number that resolves to the CFO.

  • Vendor-change and settlement-request lures
  • Synthesised-voice calls with a branching script
  • Callback fraud and IT-helpdesk impersonation
EmailSpear-phishing, BEC
SMSSmishing
VoiceVishing, deepfake
QRQuishing

Governance

Evidence your regulator and your auditor both accept

PCI DSS 12.6 awareness evidence, per-department grading for the three-lines-of-defence conversation, and an append-only log that satisfies internal audit without a manual reconciliation.

  • PCI DSS 12.6.3 register
  • Per-desk and per-function grading
  • Board-ready quarterly trend
A90–100Resilient
B80–89Solid
C70–79Uneven
D60–69Exposed
F≤59Critical
01

Susceptibility

What people fall for

32/40
  • Susceptibility rate10
  • Credential-submit rate8
  • Repeat-clicker rate8
  • Time-to-click6
02

Resilience

What they do about it

22/30
  • Report rate9
  • Real-threat response7
  • Training completion6
03

Exposure

Surface their role carries

17/30
  • Multi-channel exposure7
  • Department risk5
  • Tenure / onboarding risk5
Ten factors, each weighted out of ten. Count the cells — the grade is arithmetic you can check, not a length you have to trust.

Questions

Asked on every first call

The ones that decide whether a first call turns into a second one.

1 questions

Can you test our executive team without embarrassing anyone?

Yes, and it is the usual request. Executive results can be scoped so only the CISO sees them, and nothing in the platform publishes an individual's failures to colleagues. The tier-five scenarios are the point; the disclosure model is configurable.

Run a treasury-team scenario

We will build a vendor-change lure against a nominated test group on the call.

See your human risk in 20 minutes

Book a demo and we’ll run a sample campaign against a test group.