An Unprecedented Convergence
In the last 18 months, three independent forces converged to create an unprecedented situation in cybersecurity:
Each of these forces alone would be significant. All three together create what can be described as a perfect storm for human factor in cybersecurity.
Force 1: AI Democratized Sophisticated Attacks
Three years ago, executing a convincing vishing attack required: a team of operators trained in social engineering, extensive manual research on the target, and the ability to improvise in real time during the call.
Human risk is managed automatically.
Turn human risk into your first line of defense.
Book a demoFree demo · 30 minutes · No commitment
Today, any attacker with internet access can:
Clone a voice with a short audio sample
Commercial voice cloning tools can generate a voice nearly indistinguishable from the original from a short sample. That audio can be extracted from a LinkedIn video, a podcast, a recorded presentation, or even a voice message.
The result: phone calls where the CFO's "voice" requests urgent transfers, using the exact tone, cadence, and speech patterns of the real executive.
Automatically generate contextualized pretexts
Language models can analyze a company's public communications (press releases, social media, presentations) and generate specific pretexts for each organization.
"Hi Maria, this is the CFO. I need you to process an urgent transfer related to the Chile expansion project we mentioned on Friday's call. The vendor is pushing and I need this out before close."
Every element of that message can be automatically generated by analyzing public information.
The Data Confirms Democratization
Email did not get left behind in this wave: it got more dangerous. The Microsoft Digital Defense Report 2025 documents that AI-driven phishing is now three times more effective than traditional campaigns. And on top of that base, social engineering added fronts, because it now also arrives by voice and by SMS.
That jump does not reflect that attackers became more numerous. It reflects that the barrier to entry dropped dramatically. Attacks that previously required specialized teams can now be executed by individuals with limited resources.
Force 2: Boards Woke Up
For years, human risk was a CISO concern that rarely reached the board agenda. The topic was too technical, too abstract, too difficult to quantify.
The 2024 cases changed this.
Snowflake: large-scale losses and a wide number of affected corporate customers. The vector was not an exotic technical vulnerability. It was a remote contractor without MFA who gave up their credentials.
MGM Resorts: Las Vegas operations paralyzed for days and severe financial impact. The vector was a call to the helpdesk where the agent granted access after "verification" using public LinkedIn information.
These cases have something in common that CEOs and boards can immediately understand: they were not technical failures. They were legitimate employees deceived who used valid credentials during normal hours, passing all technical defenses without generating a single alert.
They are not the exception, they are the pattern. Cisco's 90-5-5 framework estimates that close to 90 percent of breaches involve a human factor.
Zero Trust, MFA, DLP: all these defenses assume that "the user acts correctly without coercion or deception." When that assumption fails, technical defenses do not help.
The shift in executive conversation
For the first time in corporate history, "the human layer" is a board priority, not just a CISO concern.
Before, the CISO had to convince the board that human risk mattered. Now, the board actively asks what is being done about it.
This shift created budget and urgency that did not exist before. It also created an expectation: the CISO must now demonstrate they are effectively mitigating this risk, not just training employees.
Force 3: Cyber Insurance as Catalyst
The third force is economic and perhaps the most immediate: cyber insurance.
In 2024, insurers drastically adjusted their requirements. They no longer accept "we completed annual training" as evidence of preparedness. They demand monthly evidence of continuous and documented preparedness.
Requirements That Hardened
Most insurers globally now require documented training as a coverage condition, and premiums rise severely after a breach.
In Colombia the shift was just as marked. A large part of the market updated its requirements during 2024 to reject coverage or multiply the premium when the company cannot demonstrate documented monthly employee preparedness. The change did not arrive as a recommendation, it arrived as a renewal condition.
What the insurer asks for is no longer a course certificate. It is periodic evidence of awareness testing, with granular reports showing who resisted and who did not.
The economic catalyst
Unlike "cybersecurity awareness" which can be ignored, the insurance impact is immediate and quantifiable.
Companies that cannot produce the reports insurers require face a binary decision: they pay multiples of their previous premium for a fraction of coverage, or they go without coverage.
This is a catalyst the CFO immediately understands. And a catalyst the CISO can use to justify investment in real human risk management.
Accelerated Vulnerability
These three forces converge in a context where exposure is growing rapidly.
Compromised credentials: Credential dumps circulating on the dark web keep growing, and those of Colombian users are no exception. Every leaked credential is a free starting point for an attacker.
Attack volume: Email is still the front door. According to CISA, more than 90 percent of successful cyberattacks begin with a phishing email, and Colombian organizations receive that volume like any other market.
Employee behavior: Sharing work passwords remains a widespread practice in organizations across the region, and every shared password widens the surface an attacker can exploit.
Organizational preparedness: Most Colombian SMBs with 100 to 500 employees have no CISO or dedicated security team, and only a minority of medium-sized companies in the country have any type of security training.
When an attacker combines compromised credentials with password-sharing employees in organizations without a CISO, the window to react is minimal. Mandiant documents in its M-Trends 2026 that the handoff between initial access and the secondary actor executing the attack collapsed from more than 8 hours in 2022 to 22 seconds in 2025. Technical defenses only detect damage after it has already occurred.
Why Technical Defenses Are Not Enough
The fundamental assumption of technical tools is that "the user acts correctly without coercion or deception."
When a finance manager receives a call with their CFO's cloned voice requesting an urgent transfer with specific context from a real project, the security system will see:
- Legitimate user
- Correctly authenticated
- Appropriate permissions
- Usual device
- Normal business hours
The only way to prevent compromise is for the employee to recognize and report the attack before delivering credentials, approving permissions, or authorizing transfers.
This requires something technical defenses cannot provide: that the human at the critical moment makes the right decision.
What This Means for the CISO
The three converging forces create both pressure and opportunity.
The pressure:
- The board now asks about human risk specifically
- The insurer demands documented monthly evidence
- Attackers have more sophisticated and accessible tools
- Time to act is limited (insurance renewal does not wait)
- Budget exists that did not exist before
- Executive urgency exists that did not exist before
- Solutions exist that measure real risk instead of training activity
- The CISO who demonstrates measurable results will have unprecedented credibility
Questions the Board Will Ask
In the next 12 months, boards will ask:
The CISO who can answer these questions with specific and defensible data will have a completely different position than the CISO who can only report that most of the staff completed the training.
The Window of Opportunity
The convergence of these three forces creates a specific window of opportunity.
For the first time there is:
- Executive awareness of the problem
- Budget available to address it
- Economic catalyst (insurance) forcing action
- Technology that allows measuring what was previously impossible to measure
Those who continue with the previous model (generic annual training, activity metrics instead of risk metrics) will face questions they cannot answer from increasingly informed boards and increasingly demanding insurers.
The perfect storm has already arrived. The question is what you are going to do about it.
Sources and references
- CISA, "4 Things You Can Do To Keep Yourself Cyber Safe". cisa.gov
- Cisco, "The 90-5-5 Concept: Your Key to Solving Human Risk in Cybersecurity", May 27, 2025. blogs.cisco.com
- Mandiant (Google Cloud), "M-Trends 2026 Report". cloud.google.com
- Microsoft, "Microsoft Digital Defense Report 2025". microsoft.com
Human risk is managed automatically.
Turn human risk into your first line of defense.
Book a demoFree demo · 30 minutes · No commitment
