Vishing Defense, a Regulatory Priority

Regulators (FBI, CISA, NY DFS), identify vishing as a distinct cyber risk.

In short: a vishing breach without voice-specific safeguards risks maximum regulatory exposure; a vishing breach with documented voice protections positions the organization for possible relief under the law.

Executive Summary

Vishing has emerged as a high-impact, AI-enhanced social engineering threat, bypassing traditional defenses and causing costly breaches.  70% of organizations were targeted in 2024, with 25% suffering compromise.

Regulators, including the FBI, CISA, and NY DFS, now identify vishing as a distinct cyber risk, and Public Law 116-321 ties breach penalties to documented “recognized security practices” in place for at least 12 months.

Deploying a Voice Firewall aligns with NIST and HICP frameworks, blocks vishing and other malicious calls at the network edge, strengthens compliance posture, and provides critical “good faith” evidence to reduce regulatory and legal exposure.

Vishing: A Social Engineering Tactic Wreaking Havoc

As a company dedicated to protecting the integrity of enterprise voice communications, Mutare is sounding the alarm over the mounting threat of cyber-criminal infiltration into business telephony networks via voice phishing (vishing). This evolving threat tactic has morphed from the common phone scam into a highly lethal weapon of choice for cybercriminal enterprises exploiting the immediacy, anonymity, and psychological power of the person-to-person telephone call to crack the enterprise cybersecurity defense shield.

Vishers are masters at manipulating their human targets into divulging protected information or credentials that can lead to devastating data breaches, account takeover, ransomware attacks and more. In fact, a reported 70% of industries withstood this form of voice-based attack in 2024. And of those, approximately 25% suffered a security breach as a result.

As vishing gains recognition as a uniquely potent social engineering tactic, it clearly requires better definition, recognition, and a targeted strategy to mount an effective defense.

Mis-Understood, and Under-Estimated

Yet, understanding vishing as a singular threat vector has been slow to infiltrate the general consciousness of the cybersecurity community. “Voice phishing” has often been miscast as easily-detected scams (think Nigerian prince or bogus extended car warranty offers). Or, it is lumped under the umbrella of “social engineering” or simply “phishing” without clearly distinguishing how it differs from email or web-based schemes. As such, recommended strategies to combat voice-based attacks often fall along conventional lines:

  1. Provide more employee training
  2. Institute Multi-Factor Authentication
  3. Assume your IT systems or IVR call tree will naturally filter out unwanted callers.

Unfortunately, none of these defenses work against the relentless, and increasingly sophisticated, cybercriminal apparatus perpetrating today’s AI-enhanced voice-based threats; despite common security protocols, vishing attacks and related breaches continue to rise unabated.

The FBI, CISA, USPS and Others are Sounding the Alarm!

It is clear that complacency, reinforced by misperceptions, is leaving organizations defenseless, not only against the damages vishing attacks may inflict on their operations, but also against the legal consequences should the attack lead to a data breach. Just ask MGM Resorts, the entertainment giant that recently settled a $45 million class action lawsuit on top of nearly $100 million in damages resulting from its 2023 vishing-perpetrated ransomware attack. MGM just one of a growing list of high-profile organizations that have recently fallen victim to vishing schemes.

Nevertheless, there are strong signs of progress in public awareness as evidenced by a series of alerts from  the Federal Bureau of Investigation (FBI), the Cybersecurity and Infrastructure Security Agency (CISA) and even the US Postal Service, all specifically calling out “vishing” as a singularly dangerous form of social engineering that requires serious, focused attention. Likewise, in a recent Industry Letter addressing statewide financial organizations and affiliates, the New York State Department of Financial Services (NY DFS) warns of the imminent threat posed by criminal agents utilizing the power of AI in their cyberattacks, calling out vishing specifically as one of the most potent AI-enhanced attack vectors.

Acceptance is the First Step in Protection

This is important. Because recognizing that vishing is a real, unique threat puts every organization in a better position to implement purpose-built tools and strategies that constitute an effective defense.

Doing so not only protects the organization against voice-based cyber-intrusions, but also against the full punitive impact of litigation and fines should those organizations suffer a data breach and be held accountable to government regulators or class action litigants who claim defendants did not do enough to institute “reasonable” cybersecurity measures to protect customer data.

Public Law 116-321 May Hold the Key

Regulators, too, are also acknowledging the implications of an increasingly complex landscape of cybercriminal activity across multiple channels and adjusting their own compliance requirements accordingly.

Aleksandra Vold, Healthcare Incidence Response Attorney for Chicago-based law firm BakerHostetler, and Dawn Morgenstern, Chief Privacy Officer for healthcare cybersecurity software and services provider Clearwater, discuss in a Clearwater podcast the nuances of Public Law 116-321 as it applies to Office of Civil Rights (OCR) security breach investigations.

 As an amendment to the  Health Information Technology for Economic and Clinical Health (HITECH) Act, Public Law 116-321 requires the department of Health and Human Services to take into consideration the extent to which the investigated entity has used “recognized security practices” in their cybersecurity strategies. A positive evaluation may result in significant relief in the form of reduced fines and audits for those organizations that can clearly document adherence to best practices standards, guidelines, and frameworks, such as those promulgated by NIST (National Institute of Standards and Technology), HHS, or other statutory authorities.

The sticking point, notes Vold, is defining what constitutes a “recognized security practice,” noting that when filling out their OCR reports, clients are “putting everything they can into their response,” then asking, “is that normal?” The fact is, she says, “Noone really knows. OCR investigations can really go down whatever hole they want to, looking for information.”

“OCR investigations can be onerous,” agrees Morgenstern, adding that when it comes to asserting a position of compliance, “No organization will ever be 100%. Never. But the more you can provide, the better.”

An Evolution in Risk Management

Which brings us back to how protection of the voice channel fits into a comprehensive cyber-defense strategy. While not calling out vishing explicitly, technical solutions for call analysis and filtering easily aligns with NIST Cybersecurity Framework recommendations for “Access Control,” Security Monitoring” and “Threat Detection and Response.”

Likewise, within the HICP Framework, phishing, social engineering, and endpoint protection are covered under “Communication Protection” and “Access Management” practices. As these frameworks continue to evolve in line with the changing threat landscape and heightened awareness, it seems inevitable that inclusion of protective measures for the voice channel are just a matter of time.

Organizations, however, may not have that time to wait. Note that OCR investigations are looking for proactive, rather than reactive, cyber-defense postures.  Any measures that are documented as part of an OCR investigation have to have been in place for at least 12 months in order to qualify for regulatory relief. In light of the strength and velocity of today’s voice-based cyber attackers, implementing a voice firewall solution sooner than later is both reasonable and prudent, not only as an effective shield, but also as a powerful piece of “good faith” evidence for regulators to consider.

Yes, You Can Protect Your Voice Systems (and the people they touch)

When added to an organization’s overall cyber-defense ecosystem, Mutare’s purpose-built, enterprise-grade Voice Firewall provides the highest level of voice threat protection possible, utilizing multiple layers of call analytics and filtering technologies. While easily detecting and removing the vast majority of disruptive robocalls and voice spam calls at the onset, the Mutare Voice Firewall solution is also unmatched in its ability to detect the markers of voice phishing activity and remove or deflect those callers before they are able to reach, and potentially breach, a human endpoint. Mutare Voice Firewall closes the hole that exists in an organization’s cybersecurity defense shield and is an indispensable component in the optimal, multi-layered cyber-defense program.

Click Here to learn how the Mutare Voice Firewall protects your operations, your people, and your stakeholders from the damages and regulatory fallout of voice-based attacks, or sign up for a free Assessment of your organization’s voice traffic risks.