Social Engineering Risk, by Industry
The pretext changes by sector. So does the process that fails.
A bank loses money through a payment approval. A hospital loses access through a helpdesk reset. A manufacturer loses a supplier relationship through a changed bank detail. Same cloned voice, three completely different failures. We scope each engagement to the workflow your sector actually runs, then report where verification held and where it did not.
Twelve sectors. One methodology. Evidence written for your regulator.
A generic simulation tests a generic organization
Which is not the one you run. Three things change the moment you scope to a sector.
The pretext is sector-specific
An attacker impersonating a portfolio manager sounds nothing like one impersonating a shift supervisor or a clinical director. Credibility comes from vocabulary, timing, and knowing which request is routine in your world. Generic templates skip all three, which is why they get reported and real attacks do not.
The failing process is sector-specific
Every sector has one workflow where authority moves faster than verification. In banking it is payment release. In healthcare it is credential reset. In manufacturing it is supplier bank details. Testing the wrong workflow produces a clean report and a false sense of security.
The regulator is sector-specific
GLBA, DORA, HIPAA, PCI DSS, and NIS2 all want evidence of independent testing, and they all want it in a different shape. Findings are written so the same engagement supports the audit conversation you are actually going to have.
Where each industry actually breaks
Twelve sectors, the process attackers aim at in each, and what we have published on it.
A cloned executive voice does not need to defeat a control if the process lets a phone call authorize the transfer. Treasury instruction, wire approval, and call centre verification are all still built on the assumption that a familiar voice is proof of identity.
Remote onboarding at volume, with a verification stack specified before generated faces and documents got good. Synthetic applicants clear KYC not because the control is weak but because it was written against a threat that no longer exists.
Claims intake and policyholder verification still treat a voice on a call as identity confirmation. Add broker instruction and third party administrators, and the number of people authorized to make a payout decision is larger than most carriers assume.
Small teams, high-value transfers, and a culture where an urgent partner instruction is treated as final. Client funds and escrow accounts move on authority rather than on process, which is exactly the condition synthetic voice exploits best.
Shift-based staffing means the person verifying identity almost never knows the person calling. Helpdesk credential resets and clinical system access requests are approved on plausibility, and vendor invoice changes arrive into a finance function stretched thin.
The compromise starts as a social engineering attack and ends in your customers' environments. Developer access, OAuth consent, and package publishing rights are granted by engineers who are trusted precisely because they move fast.
Distributed sites, thin security staffing, and a finance function that has never met most of its suppliers. A bank detail change on a genuine-looking invoice, backed by a follow-up call, remains one of the highest-yield attacks in the sector.
Attackers rarely go at operational technology directly. They call the corporate helpdesk, because it is the shortest route to anything that matters, and because vendor access requests are routine enough that nobody wants to be the one who slowed the outage response.
Time pressure is built into the operating model, and that is precisely what a synthetic voice call exploits. Freight release and dispatch instruction get approved because holding the load costs money and the caller sounded like the person who normally asks.
Public officials have more published voice and video than almost any other target group, which makes cloning trivial. Benefit disbursement, grant administration, and contractor onboarding then provide the payout path.
High turnover keeps the verification habit from ever settling, and franchise structures spread payment authority across sites that do not share a security function. Collaboration platforms and calendar invites carry implicit trust that email lost years ago.
Identity vendors need independent validation of what their liveness and document checks actually accept. Asset platforms are where the highest-effort attacks land first, because the transfer is irreversible and the executive is public.
Five functions, targeted in every sector
Whatever the vertical, the attack lands on one of these. What differs is the pretext used to reach it.
Same spine, scoped to your sector
Every engagement runs the OSES™ loop: measure risk against your real process, train for what the measurement found, then prove it changed on re-test. The sector determines the scenario and the target workflow, not the discipline behind it.
Every engagement runs under signed authorization with named approvers, an agreed window, and documented abort conditions. Reporting is organizational: no named individuals, no department leaderboards. Sector positioning comes from the Social Engineering Risk Index, computed from real engagement outcomes and documented in the published methodology.
What happened, and what changed after
Authorized engagements, written up with the findings intact. Client names never appear in our public material.
OSINT sourced enough public video to clone the CEO, then a spoofed number dropped a personalized synthetic voice message straight into voicemail without the phone ever being answered.
Read the case study Agentic AI · HRA CISO impersonation delivered through calendar invites, a channel that bypasses the filtering and inspection layers protecting email, combined with autonomous agents that adapted in real time.
Read the case study Agentic AI · Financial ServicesA cloned COO voice driving live agentic phone conversations into a bank branch, followed by an SMS asking for a login. Everyone who engaged got a two-minute training module on the spot, with no punitive measures.
Read the case study Hybrid · Technology ServicesA large IT service provider with high-value transactions in its business process, tested with a hybrid spear-phishing campaign carrying a cloned voice message from the CEO.
Read the case studyThe reading behind the scoping
Published analysis we use when building sector scenarios, including the findings that did not go our way.
Common questions
What actually changes between industries?
The pretext and the target process. A bank loses money through a payment approval, a hospital loses access through a helpdesk credential reset, and a manufacturer loses a supplier relationship through a bank detail change. The synthetic voice is the same in all three. The workflow it has to defeat is not, so the scenario, the target roles, and the success criteria are built around your sector's real process.
Do you have benchmarks for my sector?
Yes. The Social Engineering Risk Index computes sector medians from authorized engagement outcomes rather than from surveys, so you can see where your organization lands against its own vertical instead of against a general population average. Methodology is published in full.
Does the report name individual employees?
No. Findings are reported at the organizational and process level: which workflow was targeted, where verification held, and where it did not. We do not produce named individuals or department leaderboards, because the objective is a process fix rather than a list of people to blame.
Do you test systems as well as people and process?
Yes, and they are separate engagements. Orchestrated simulation targets people and the decision process behind them. Deepfake penetration testing submits synthetic faces, documents, video, and voiceprints through liveness, document verification, video KYC, and voice biometric controls to establish per-control acceptance rates. Banks, payments providers, and identity vendors often run both.
What if my sector is not listed?
The twelve listed sectors are where we run the most volume, not a restriction. Scoping starts from your process rather than your industry code, so any organization where a synthetic voice or video could move money, grant access, or release data is in scope.
How long does an engagement take?
Two to three weeks from scoping call to findings for a standard engagement, with the active simulation window usually a few days inside that. Programs that run the full measure, train, and prove cycle are typically scheduled quarterly so the re-test can show a delta.
Find out how your sector holds up
Thirty minutes. We will walk through the workflow in your industry that authority moves through fastest, and scope a simulation against it.
Or read the full assessment methodology.
