VishingGenerative AICyber Insurance

    June 6, 2026 · 8 min read · By José Vicente Chávez

    The perfect storm of human risk: three converging forces

    Leer en español

    An Unprecedented Convergence

    In the last 18 months, three independent forces converged to create an unprecedented situation in cybersecurity:

  1. Generative artificial intelligence democratized attacks that previously required specialized teams
  2. Massive high-profile breaches generated board-level awareness about human risk
  3. Cyber insurance became an economic catalyst forcing action
  4. Each of these forces alone would be significant. All three together create what can be described as a perfect storm for human factor in cybersecurity.

    Force 1: AI Democratized Sophisticated Attacks

    Three years ago, executing a convincing vishing attack required: a team of operators trained in social engineering, extensive manual research on the target, and the ability to improvise in real time during the call.

    Human risk is managed automatically.

    Turn human risk into your first line of defense.

    Book a demo

    Free demo · 30 minutes · No commitment

    Today, any attacker with internet access can:

    Clone a voice with a short audio sample

    Commercial voice cloning tools can generate a voice nearly indistinguishable from the original from a short sample. That audio can be extracted from a LinkedIn video, a podcast, a recorded presentation, or even a voice message.

    The result: phone calls where the CFO's "voice" requests urgent transfers, using the exact tone, cadence, and speech patterns of the real executive.

    Automatically generate contextualized pretexts

    Language models can analyze a company's public communications (press releases, social media, presentations) and generate specific pretexts for each organization.

    "Hi Maria, this is the CFO. I need you to process an urgent transfer related to the Chile expansion project we mentioned on Friday's call. The vendor is pushing and I need this out before close."

    Every element of that message can be automatically generated by analyzing public information.

    The Data Confirms Democratization

    Email did not get left behind in this wave: it got more dangerous. The Microsoft Digital Defense Report 2025 documents that AI-driven phishing is now three times more effective than traditional campaigns. And on top of that base, social engineering added fronts, because it now also arrives by voice and by SMS.

    That jump does not reflect that attackers became more numerous. It reflects that the barrier to entry dropped dramatically. Attacks that previously required specialized teams can now be executed by individuals with limited resources.

    Force 2: Boards Woke Up

    For years, human risk was a CISO concern that rarely reached the board agenda. The topic was too technical, too abstract, too difficult to quantify.

    The 2024 cases changed this.

    Snowflake: large-scale losses and a wide number of affected corporate customers. The vector was not an exotic technical vulnerability. It was a remote contractor without MFA who gave up their credentials.

    MGM Resorts: Las Vegas operations paralyzed for days and severe financial impact. The vector was a call to the helpdesk where the agent granted access after "verification" using public LinkedIn information.

    These cases have something in common that CEOs and boards can immediately understand: they were not technical failures. They were legitimate employees deceived who used valid credentials during normal hours, passing all technical defenses without generating a single alert.

    They are not the exception, they are the pattern. Cisco's 90-5-5 framework estimates that close to 90 percent of breaches involve a human factor.

    Zero Trust, MFA, DLP: all these defenses assume that "the user acts correctly without coercion or deception." When that assumption fails, technical defenses do not help.

    The shift in executive conversation

    For the first time in corporate history, "the human layer" is a board priority, not just a CISO concern.

    Before, the CISO had to convince the board that human risk mattered. Now, the board actively asks what is being done about it.

    This shift created budget and urgency that did not exist before. It also created an expectation: the CISO must now demonstrate they are effectively mitigating this risk, not just training employees.

    Force 3: Cyber Insurance as Catalyst

    The third force is economic and perhaps the most immediate: cyber insurance.

    In 2024, insurers drastically adjusted their requirements. They no longer accept "we completed annual training" as evidence of preparedness. They demand monthly evidence of continuous and documented preparedness.

    Requirements That Hardened

    Most insurers globally now require documented training as a coverage condition, and premiums rise severely after a breach.

    In Colombia the shift was just as marked. A large part of the market updated its requirements during 2024 to reject coverage or multiply the premium when the company cannot demonstrate documented monthly employee preparedness. The change did not arrive as a recommendation, it arrived as a renewal condition.

    What the insurer asks for is no longer a course certificate. It is periodic evidence of awareness testing, with granular reports showing who resisted and who did not.

    The economic catalyst

    Unlike "cybersecurity awareness" which can be ignored, the insurance impact is immediate and quantifiable.

    Companies that cannot produce the reports insurers require face a binary decision: they pay multiples of their previous premium for a fraction of coverage, or they go without coverage.

    This is a catalyst the CFO immediately understands. And a catalyst the CISO can use to justify investment in real human risk management.

    Accelerated Vulnerability

    These three forces converge in a context where exposure is growing rapidly.

    Compromised credentials: Credential dumps circulating on the dark web keep growing, and those of Colombian users are no exception. Every leaked credential is a free starting point for an attacker.

    Attack volume: Email is still the front door. According to CISA, more than 90 percent of successful cyberattacks begin with a phishing email, and Colombian organizations receive that volume like any other market.

    Employee behavior: Sharing work passwords remains a widespread practice in organizations across the region, and every shared password widens the surface an attacker can exploit.

    Organizational preparedness: Most Colombian SMBs with 100 to 500 employees have no CISO or dedicated security team, and only a minority of medium-sized companies in the country have any type of security training.

    When an attacker combines compromised credentials with password-sharing employees in organizations without a CISO, the window to react is minimal. Mandiant documents in its M-Trends 2026 that the handoff between initial access and the secondary actor executing the attack collapsed from more than 8 hours in 2022 to 22 seconds in 2025. Technical defenses only detect damage after it has already occurred.

    Why Technical Defenses Are Not Enough

    The fundamental assumption of technical tools is that "the user acts correctly without coercion or deception."

    When a finance manager receives a call with their CFO's cloned voice requesting an urgent transfer with specific context from a real project, the security system will see:

    • Legitimate user
    • Correctly authenticated
    • Appropriate permissions
    • Usual device
    • Normal business hours
    All defenses give green light because technically everything is correct.

    The only way to prevent compromise is for the employee to recognize and report the attack before delivering credentials, approving permissions, or authorizing transfers.

    This requires something technical defenses cannot provide: that the human at the critical moment makes the right decision.

    What This Means for the CISO

    The three converging forces create both pressure and opportunity.

    The pressure:

    • The board now asks about human risk specifically
    • The insurer demands documented monthly evidence
    • Attackers have more sophisticated and accessible tools
    • Time to act is limited (insurance renewal does not wait)
    The opportunity:
    • Budget exists that did not exist before
    • Executive urgency exists that did not exist before
    • Solutions exist that measure real risk instead of training activity
    • The CISO who demonstrates measurable results will have unprecedented credibility

    Questions the Board Will Ask

    In the next 12 months, boards will ask:

  5. How many of our employees have compromised credentials on the dark web right now?
  6. Which specific employees are vulnerable to what types of attack?
  7. What evidence do we have that our preparedness works? (Not completed the course. Demonstrated resistance under simulated attack.)
  8. What reports are we delivering to the insurer and are they sufficient?
  9. How do we compare to cases like MGM and Snowflake in terms of preparedness?
  10. The CISO who can answer these questions with specific and defensible data will have a completely different position than the CISO who can only report that most of the staff completed the training.

    The Window of Opportunity

    The convergence of these three forces creates a specific window of opportunity.

    For the first time there is:

    • Executive awareness of the problem
    • Budget available to address it
    • Economic catalyst (insurance) forcing action
    • Technology that allows measuring what was previously impossible to measure
    CISOs who recognize this window and act in the next 12 to 18 months will have the most significant defensive advantage of the decade.

    Those who continue with the previous model (generic annual training, activity metrics instead of risk metrics) will face questions they cannot answer from increasingly informed boards and increasingly demanding insurers.

    The perfect storm has already arrived. The question is what you are going to do about it.

    Sources and references

    • CISA, "4 Things You Can Do To Keep Yourself Cyber Safe". cisa.gov
    • Cisco, "The 90-5-5 Concept: Your Key to Solving Human Risk in Cybersecurity", May 27, 2025. blogs.cisco.com
    • Mandiant (Google Cloud), "M-Trends 2026 Report". cloud.google.com
    • Microsoft, "Microsoft Digital Defense Report 2025". microsoft.com

    Human risk is managed automatically.

    Turn human risk into your first line of defense.

    Book a demo

    Free demo · 30 minutes · No commitment