What We Find
When the Simulation Runs
Findings from enterprise engagements: which orchestrated sequences work, which departments give way first, and why the click was never the number that mattered.
The Sequences That Work Best
Ranked by what people did, not by what they opened. Every one of these is a handoff between channels rather than a single message.
Deepfake Video, then Agentic Email
Deepfake Call, then Agentic SMS
Deepfake Call, then Calendar Invite
Note the gap between the two columns. Across all three sequences, roughly a third of the people who clicked did not go on to do the thing that would have caused a loss. A click rate counts both groups the same way.
Click Rate Is the Wrong Measure
The most useful thing we can tell you from three years of engagements is that the industry's default metric does not describe the risk.
A click tells you a person touched something. It does not tell you whether money moved, whether a credential was reset, or whether anyone in the building noticed. In the engagements where something consequential happened, three things failed at once: the tooling did not catch it, the process did not hold, and a person took the wrong action. A click metric captures the third one, partially, and only when a link exists.
Across a sample of voice campaigns covering roughly 900 targets, the weighted mean action rate was 14.5%, ranging from 0% in the strongest organizations to about 35% in the weakest. There was no link anywhere in those campaigns. A phishing platform would have reported nothing at all.
A moment, on one channel
The step after the moment
Did they act, push back, or report?
Depending on the path, a person is the first line of defense, the last, or the only one. We measure what they did with the request and how fast they raised it, not whether they could spot a rendering artifact.
Did the procedure hold under pressure?
Callback rules, approval thresholds, identity checks at the helpdesk. This is where consequential failures actually occur, and it is different in every organization, which is why generic testing and generic training both miss it.
Did anything in the stack see it?
These sequences land inside trusted communication platforms and travel through the seams between security tools. Each tool works as designed and nobody owns the gap. That gap is where the attack surface has moved.
Procedural Verification
It is unglamorous, it is cheap, and it is the single thing that separates the organizations that hold from the ones that do not. Four steps carry most of the value.
None of these require a single person to correctly identify a deepfake.
What the Benchmark Shows
Aggregate figures are context, not a benchmark. The number that matters to you is how your organization compares to your own peer vertical.
Department Exposure
Finance runs 63% above the company average. It is also the function where a single wrong action moves money, which is why department-level reporting beats a single organizational number.
Training Impact
Reported honestly: training cuts susceptibility by roughly a third and then stops. The remaining 8% is not a training problem. It is a process problem, and no amount of additional awareness content closes it.
Detection Reality
The headline finding: average accuracy sits below a coin flip, and it gets worse as generation quality improves. Any control that depends on a person telling real from synthetic is a control with a declining success rate.
A Chain That Walks Around the Controls
Adversaries are not defeating link protection. They are arriving somewhere it does not apply.
Voicemail Drop, then SMS
This chain exploits voicemail transcription on mobile to sidestep link protection entirely. The voicemail manufactures prior contact, so the SMS that follows arrives inside a conversation the target believes they already started.
Why It Works
The voicemail does the credibility work before any request is made. By the time the message arrives, the target is not evaluating a stranger, they are continuing a conversation.
The handset treats the thread as established contact, so protections written for unsolicited inbound links do not apply the same way.
The lesson is not that people should scrutinize voicemail transcripts more carefully. It is that a request to move money or credentials should require verification regardless of how established the thread feels.
Find Out Where Your Process Breaks
Thirty minutes. We walk through a real OSES™ engagement, scenario design through findings, and you decide whether your process would have held.
