Voice phishing has quietly overtaken email as the preferred entry point for attackers targeting organisations, and no amount of technical filtering closes that gap without genuine behaviour change. According to Google Cloud’s Mandiant M-Trends 2026 report, vishing accounted for 11 per cent of all confirmed initial access methods observed across more than 500,000 hours of frontline incident response in 2025, while traditional email phishing fell from 14 per cent to just 6 per cent over the same period. Behaviour change cybersecurity, particularly building employee recognition and reporting habits around voice-based attacks, is now a front-line discipline rather than a supplemental checkbox. The organisations that close this gap first are the ones that extend their human risk management programs beyond the inbox.
Why Voice Phishing Has Overtaken Email
Email phishing succeeds through volume: send enough convincing messages and someone will eventually click. Voice phishing operates on a fundamentally different logic. A caller can adapt to objections in real time, invoke authority and urgency simultaneously, answer questions a static email never could, and keep an employee engaged long enough to override their better instincts. That live, interactive quality is precisely what makes vishing effective against organisations that have invested in email filtering and anti-phishing training but given no equivalent attention to suspicious phone calls.
The Mandiant data underlines how concentrated this risk has become in cloud environments. When attackers specifically targeted cloud infrastructure, vishing was the single most common initial access method, accounting for 23 per cent of cloud-related compromises. Help desk impersonation is the dominant tactic: callers pose as employees, request password resets and MFA changes, and walk away with privileged credentials before any alert fires.
The 22-Second Problem
The Mandiant M-Trends 2026 report documents a figure that fundamentally reframes human risk response. In 2022, the average time between an initial-access broker gaining entry to a network and handing that access to a ransomware group was roughly eight hours. By 2025, according to the same report, that handoff had collapsed to 22 seconds. That compression changes what security training must accomplish. An employee’s decision on a suspicious phone call is no longer a recoverable mistake. It is a near-instantaneous gate between a secure organisation and a full compromise.
When the window shrinks to 22 seconds, every technical control downstream from the initial call becomes far less meaningful. The only intervention that consistently holds is preventing the call from succeeding in the first place, and that requires employees who know what a vishing attempt sounds like, who are practised at verifying caller identity through out-of-band channels, and who feel genuinely empowered to pause on any request that bypasses normal approval steps.
The Canadian Dimension
In June 2026, the Canadian Centre for Cyber Security (CCCS) issued a direct warning: frontier AI models are enabling threat actors to find and exploit vulnerabilities far faster than before, compressing defender response time from days or weeks to mere hours. AI-generated voices, real-time script adaptation, and spoofed caller ID now make vishing attempts indistinguishable from legitimate calls without a deliberate verification habit built into the organisation’s daily culture. The CCCS warning applies to every sector, but lands especially hard on Canadian nonprofits and public sector organisations where IT teams are stretched and formal security training cycles run annually at best.
In our work with Canadian organizations of all sizes, we consistently see that the single biggest predictor of how badly an incident damages an organization is not whether someone clicked, it is whether anyone reported it. A suspicious vishing call reported in the first minutes gives a security team the chance to lock down accounts before the 22-second clock expires. A suspicious call that goes unreported because an employee was uncertain, embarrassed, or simply unaware of the reporting process gives attackers everything they need to move at speed.
Building Behaviour Change That Holds
Effective behaviour change cybersecurity for voice phishing does not require rebuilding a training program from scratch. Three steps make an immediate difference. First, add at least one vishing-specific scenario to existing security awareness content. Employees who have experienced a realistic example of help desk impersonation are meaningfully better at identifying a real attempt when it arrives. Second, run a vishing simulation before the current training cycle closes. Baseline data on how many employees comply with identity-reset requests over the phone without verification tells you precisely where the behavioural gap sits.
Third, build a reporting channel that employees actually trust. The goal is not a zero-failure culture. It is a report-everything culture where a near-miss flagged in the first minutes protects the entire organisation. POPP3R’s managed phishing and vishing simulation programs are designed around that outcome, measuring reporting rates alongside click rates because a caught call that gets reported is intelligence, not just a saved credential. Canadian nonprofits and public sector organisations with constrained budgets can find a structured starting point in POPP3R’s Security101 program.