Categories: Web and IT News

CISOs Face Widening Gaps in Defending Multi-Channel Social Engineering Threats, Dune Security Finds

Security teams are sounding the alarm: 64% of enterprises faced off-channel attacks in the past year, but most still train only for email-based attacks.

As social engineering attacks evolve to exploit encrypted messaging, SMS, collaboration tools, and voice calls, enterprises remain stuck preparing users only for email threats, according to new data from Dune Security. This mismatch leaves organizations vulnerable, even as high-profile breaches highlight the risks.

Drawing from Dune Security’s 2025 Insider Threat Intelligence Report, including survey data from leading enterprise CISOs (Chief Information Security Officers) and behavioral telemetry from its simulation engines, concern outpaces action across vectors. For instance, 71% of CISOs worry about SMS phishing (smishing), yet only 27% simulate it; 59% fear voice phishing (vishing), but just 15% test it. Testing for collaboration tools and encrypted messaging? It plummets to single digits or zero, despite 38% concern for attacks coming from these channels.

Marketing Technology News: MarTech Interview with Miguel Lopes, CPO @ TrafficGuard

Key findings include:
• Only 12% of CISOs believe their current Security Awareness Training (SAT) program is sufficient.
• 0% of surveyed enterprises simulate threats in encrypted messaging apps, even as 64% confirmed social engineering attacks via encrypted or informal channels in the past 12 months.
• Just 18% of organizations tailor phishing simulations by both role and behavior, though 91% say this is essential.
• While 100% of enterprises test users over email, only 15% simulate voice-based phishing (vishing) attacks, and just 27% test over SMS (smishing).
• AI-personalized phishing now drives 300% more user interaction than traditional, templated variants.

“Attackers are exploiting the blind spots where enterprises aren’t even looking,” said David DellaPelle, Co-Founder and CEO of Dune Security. “Legacy SAT programs are limited to yesterday’s email threats while real breaches now start in high-trust, low-visibility channels like encrypted messaging, SMS, voice call, and deepfake-based impersonation.”

Forward-thinking security teams are now shifting away from checkbox training toward behavior-based simulation, real-time visibility, and adaptive remediation. Dune’s latest data confirms that legacy awareness programs fail not due to lack of effort, but because they miss where risk actually
lives: in untested channels and unmonitored user behavior.

Marketing Technology News: Time to Start Holiday Marketing is Now

“Traditional solutions simply can’t keep up with evolving threats or the way people actually work,” said Dune Security Senior Manager of Engineering and AI, Kyle Ryan.

“Our platform proactively red-teams our customers’ organizations, using the same social engineering attack modalities that hackers are deploying in the wild. We hyper personalize testing, training, and control guardrails to each employee’s role, level, industry, strengths, and weaknesses, empowering them to protect both themselves and their organizations in real time.”

The 2025 Insider Threat Intelligence Report draws on survey responses from industry-leading enterprise CISOs, combined with proprietary simulation and behavioral analytics from Dune Security’s platform. The report details attack channel trends, readiness gaps, and the behavioral triggers most likely to lead to compromise.

The post CISOs Face Widening Gaps in Defending Multi-Channel Social Engineering Threats, Dune Security Finds first appeared on PressReleaseCC.

CISOs Face Widening Gaps in Defending Multi-Channel Social Engineering Threats, Dune Security Finds first appeared on Web and IT News.

awnewsor

Recent Posts

Where Was the Light Measured? NuYOU360 Publishes Its Irradiance Testing Positions and Asks the Red Light Therapy Industry to Do the Same

“An irradiance number with no measurement position attached is not a specification. It is decoration.…

3 hours ago

Projet Chez Soi Launches a French-Language Platform to Help Readers Plan and Navigate Home Improvement Projects

Projet Chez Soi launches a French-language editorial platform focused on renovation planning, property diagnostics, project…

6 hours ago

Maison En Devenir Launches a French-Language Resource for Planning the Costs, Performance and Future of the Home

Maison En Devenir launches a French-language editorial platform providing practical information on renovation costs, permits,…

9 hours ago

Après les Clés Launches a Practical French-Language Resource for Home Renovation, Costs, Permits and Financial Support

Après les Clés launches a French-language editorial platform helping homeowners and property buyers navigate renovation…

9 hours ago

Iver Jewelry Brings Nature-Inspired Engagement Rings to Couples Seeking Something Personal

Botanical design details, meaningful gemstone choices, and made-to-order personalization give couples a more expressive path…

9 hours ago

GemsMagic Expands the Possibilities of Personalized Gemstone Engagement Rings

Colored gemstone choices, nature-inspired settings, personalized ring design, bridal sets, and ring enhancers give couples…

9 hours ago

This website uses cookies.