Financial services
The roles attackers actually target
Treasury, payments and the executive assistant calendar are where the money moves, so that is where the effort goes. Simulations for these teams use the tradecraft aimed at them: vendor-change notices, wire-fraud requests and a cloned voice on a Friday afternoon.
- 3
- channels for exec teams
- Tier 5
- executive spear-phishing
- PCI 12.6
- evidence included
Threat model
Payment fraud is a people process
Almost every large loss runs through a person approving something that looked routine. The scenarios here mirror that: a supplier bank-detail change, an urgent settlement, a call from a number that resolves to the CFO.
- Vendor-change and settlement-request lures
- Synthesised-voice calls with a branching script
- Callback fraud and IT-helpdesk impersonation
Governance
Evidence your regulator and your auditor both accept
PCI DSS 12.6 awareness evidence, per-department grading for the three-lines-of-defence conversation, and an append-only log that satisfies internal audit without a manual reconciliation.
- PCI DSS 12.6.3 register
- Per-desk and per-function grading
- Board-ready quarterly trend
- Susceptibility rate10
- Credential-submit rate8
- Repeat-clicker rate8
- Time-to-click6
- Report rate9
- Real-threat response7
- Training completion6
- Multi-channel exposure7
- Department risk5
- Tenure / onboarding risk5
Questions
Asked on every first call
The ones that decide whether a first call turns into a second one.
1 questions
Can you test our executive team without embarrassing anyone?
Yes, and it is the usual request. Executive results can be scoped so only the CISO sees them, and nothing in the platform publishes an individual's failures to colleagues. The tier-five scenarios are the point; the disclosure model is configurable.
Keep reading
Related
Run a treasury-team scenario
We will build a vendor-change lure against a nominated test group on the call.