Report by Dune

CISOs on the Emerging Threats Redefining User Cyber Risk

16 FINDINGSPublished Sep 4, 2025
View Original Report →

Key Findings

59% of CISOs at enterprises fear voice phishing (vishing).

EnterprisesPhishingVishing

0% of surveyed enterprises simulate threats in encrypted messaging apps.

Enterprises

Only 27% of CISOs at enterprises simulate SMS phishing.

EnterprisesPhishingSmishing

64% of enterprises faced off-channel attacks in the past year.

Enterprises

Concern for attacks coming from collaboration tools and encrypted messaging is 38% at enterprises.

Enterprises

71% of CISOs at enterprises worry about SMS phishing (smishing).

EnterprisesPhishingSmishing

Just 15% of CISOs at enterprises test voice phishing.

EnterprisesPhishingVishing

Only 12% of CISOs at enterprises believe their current Security Awareness Training (SAT) program is sufficient.

EnterprisesSecurity awareness program

64% of surveyed enterprises confirmed social engineering attacks via encrypted or informal channels in the past 12 months.

EnterprisesSocial engineering

Testing for collaboration tools and encrypted messaging plummets to single digits or zero at enterprises.

Enterprises

91% of enterprises say tailoring phishing simulations by both role and behavior is essential.

EnterprisesPhishing

Just 18% of enterprises tailor phishing simulations by both role and behavior.

EnterprisesPhishingSecurity awareness training

Only 15% of enterprises simulate vishing.

EnterprisesPhishingVishing

Only 27% of enterprises test smishing.

EnterprisesPhishingSmishing

100% of enterprises test email phishing.

EnterprisesPhishing

AI-personalized phishing now drives 300% more user interaction than traditional, templated variants.

EnterprisesPhishingAI