CEO Fraud Simulation
The question is not whether someone would fall for it. It is whether your approval chain would stop it if they did.
An authorized simulation that impersonates a named executive across voice, video, email, and SMS, and runs a payment request through your real approval process. It tests the callback rule, the verified number policy, the wire threshold, and the second approver. No funds move at any point, and no individual is named in the report. What you get back is whether the chain held.
Written to be forwarded to your CFO.
You cannot prevent CEO fraud you have never tested
The control exists, it is written down, and it has never once been run against something that was trying to get past it.
Recognition beats procedure
A verification step is designed for a stranger. It performs very differently against a voice the person has heard in every quarterly meeting for four years. Familiarity does not disable the rule, it just makes following the rule feel rude.
Urgency is the whole technique
An adversary does not need to defeat your controls. They need the request to arrive at 4:50pm on a Friday, tied to a deal that closes tonight, from someone who does not usually ask twice. The control is skipped, not broken.
Awareness training does not measure
A completed module tells you someone watched a video about wire fraud. It tells you nothing about what the payments team does when the request is in front of them and the callback number is the one printed in the email.
Five links, each one a control that is supposed to catch it
The simulation walks the sequence a real campaign walks, and reports which link held.
The instruction arrives
An email from a familiar name, or a Teams message, or a call. The request is plausible: an acquisition deposit, a supplier held on credit, a legal settlement. Your control here is whether the sender or caller identity is verified independently of the message itself.
Urgency and confidentiality are established
The deal is sensitive, the deadline is today, and the request is not to be discussed with the wider team. Your control is whether confidentiality framing is itself treated as a red flag, or whether it successfully removes the second pair of eyes.
A callback is offered, on the wrong number
The strongest link in most policies and the easiest to sidestep, because a callback offered by the requester feels like verification while being the opposite. Your control is whether the callback goes to the number in your directory or the number in the message.
The amount is set just where it needs to be
Sometimes above your threshold to see whether the second approver actually reviews or simply signs. Sometimes just below it, to establish whether your threshold is set where the risk is or where the paperwork is convenient.
Approval is granted, and we stop
The moment approval is given, the simulation ends and records it. No payment instruction is issued, no banking system is touched, no vendor record is altered. You get evidence that the chain would have paid, without anything having been paid.
Where the same pretext runs against the IT service desk for access instead of money, that is AI vishing simulation.
Coordinated, not parallel
Real executive impersonation does not pick a channel. It uses one to make the next one believable.
An approved executive voice holding a live conversation, handling a question and a moment of doubt in real time. This is usually the link that converts, because hearing the person is treated as proof of the person.
A synthetic executive appearing in a Teams or Zoom call, on camera, responding to what is said. The scenario finance teams are told to be alert to and have never seen, which is why being told about it does not help much.
The written trail a real campaign leaves: the initial instruction, the confirmation, the nudge when the payment has not appeared. Individually unremarkable, which is the point, because they are there to corroborate the call.
Public sources establish who signs, who pays, who is travelling, and which supplier relationship is real enough to invoke. The pretext is built from what an adversary could find, because that is exactly what an adversary would use.
The quieter variant, and the more expensive one. A supplier updating bank details through your normal channel, testing whether a change of account gets the scrutiny a new payment would have received.
Channels fire in an order chosen for effect, each one raising the credibility of the next, with timing tuned to your close calendar. Running them separately measures four things. Running them in sequence measures the one thing that happens in reality.
How the engagement runs
The executive impersonation scenario of OSES™, our orchestrated simulation framework. Same discipline on scoping, consent, and evidence as every other engagement, pointed at the approval chain rather than the inbox.
Every engagement runs under signed authorization, with written consent from each executive whose voice or likeness is used, assets destroyed at close, and client names absent from all public material. For the video channel on its own, see deepfake simulation, and for how the channels are orchestrated, see the OSES simulation platform.
If you are the CFO reading this
This is a controls test, not a security exercise, and it is closer to what your internal audit function already does than to anything in the security budget. It answers one question: if a payment instruction arrived from you, today, with everything an adversary could learn about your company behind it, would the chain that sits between the request and the money have stopped it? No funds move at any point. Nothing touches a banking system, no supplier record changes, and no member of your team is named, ranked, or singled out in anything we hand back. The finding is about the procedure, and the remediation is a change to the procedure. It typically takes one thirty minute scoping conversation from your side, and it produces a document your auditor and your board will both accept without translation.
CEO fraud prevention, measured as a process
Reported at the organizational and process level. No named individuals, no departmental leaderboards.
Process hold rate
The headline. How often the documented approval procedure was followed end to end when a request arrived under pressure from a recognized voice. This is the number that goes in front of the board, and it is a number about the process rather than about anyone's judgement.
The chain, link by link
Which control caught the request, which was skipped, and at which point. If verification failed because the callback used the number in the email, that is a policy fix with a date on it, not a training topic.
Evidence that travels
Written once for the security team, the audit committee, and the external auditor, with methodology, authorization record, and scope included. Nobody has to rewrite it before it leaves the building.
For how your result compares against the wider dataset, see the Social Engineering Risk Index.
Organizations where an instruction can become a payment
Anywhere authority is recognized by voice and money moves on request.
How these engagements play out
What a cloned voiceprint did to a verbal verification control, and what it revealed about the step-up path sitting behind it.
Read the case study Agentic AIAutonomous agents handling research, asset generation, and conversation with no human operator in the loop.
Read the case studyCommon questions
Is this the same as BEC testing?
Business email compromise testing usually means a spoofed email and a click metric. This includes that email, but the email is rarely what carries the request over the line. The voice call that follows it, or the video call that confirms it, is what makes the request feel verified. If the engagement only tested the inbox, it would miss the part your people would actually believe.
Do you actually move money?
No. Never, under any scope. The simulation stops at the moment of approval and records that the approval was granted. No payment instruction reaches a banking system, no vendor record is altered, and no account details are changed. The finding is that the chain would have paid, evidenced without paying.
Who needs to authorize this?
Signed authorization from an executive sponsor, plus written consent from every executive whose voice or likeness is used. In practice the sponsor is usually the CISO with the CFO informed, or the CFO directly. Finance staff are not told in advance, because a warned approval chain is not the approval chain you run on.
How do you scope which executives are impersonated?
We start from what a real campaign would find: who is publicly visible, who has recorded audio available, and who holds enough authority that a request from them would not be questioned. That shortlist goes to you, you approve or remove names, and only approved individuals are used.
How is consent and likeness handled?
Voice and face assets are generated only from material the individual has consented to in writing, used only inside the agreed engagement window, and destroyed at close. Nothing is retained for reuse, nothing is used for another client, and no client name or executive identity appears in our public material.
Find out whether the chain would hold
Thirty minutes. We will walk your approval path from instruction to payment and mark the links worth testing first.
If the exposure you are worried about is the help desk rather than the payment run, start with AI vishing simulation.
