NOUSEC gives financial entities the evidence DORA asks for and the simulations the current fraud actually uses. DORA Article 13(6) makes ICT security awareness programmes and digital operational resilience training compulsory modules for all employees and senior management, and Article 5(4) obliges the management body to keep its own ICT-risk knowledge current. NOUSEC runs simulations across eight channels — including voice and deepfake video at the Enterprise tier — verifies completion server-side rather than accepting a browser's word for it, and reports per-module effectiveness as a correlation with real click rate.
Your sector, in its own numbers.
The control worked. That was the problem.
Every published deepfake-fraud case of the last two years was stopped — or not stopped — by a process step, never by someone's ear.
| Case | Channel | What was asked | Outcome |
|---|---|---|---|
| Arup, Feb 2024 | Multi-person video call | 15 transfers | ~US$25.6m paid[7] |
| Ferrari, Jul 2024 | Voice call impersonating the CEO | Urgent confidential deal | Stopped — the employee asked a question only the real CEO could answer[8] |
| LastPass, Apr 2024 | Voice deepfake over WhatsApp | Contact outside normal channels | Stopped — the employee reported it[9] |
The two that were stopped have nothing to do with detection. Nobody heard a synthetic artefact. One employee ran a verification step the attacker could not pass; the other noticed that the channel was wrong and reported it rather than replying.
That is a process control and a reporting culture, and both are trainable. Neither is improved by telling people to listen harder — the honest position, which we teach, is that on the hardest pairs you cannot tell by ear.
So the training target is not perception. It is: verification through a channel you already hold, an escalation path for vendor bank-detail changes, and an organisation where saying “no” to the CEO is safe.
Finance, treasury, and the people who can move money.
Reach in this sector is not a coverage problem — almost everyone has a mailbox. It is a targeting problem: the smallest populations carry the largest single-transaction risk, and they need a different campaign from everyone else.
Payments and treasury
The highest-value target and the smallest population. Deserves spear-phishing and callback (TOAD) simulation, not the same annual module as everyone else.
Relationship and client-facing staff
Trained to be responsive and helpful, which is the exact behaviour a pretext exploits. Adaptive path assigns by measured failure, not by role assumption.
The management body
DORA Art. 5(4) is a personal obligation on them, and NIS2 Art. 20(2) makes board training mandatory where the entity is in scope of both. Completion evidence for the board has to be as defensible as everyone else's.
The article, and the artefact that answers it.
The fourth column is the only one that mentions the product, and it names a mechanism rather than an intention.
| Instrument | Article | What it requires | How NOUSEC evidences it |
|---|---|---|---|
| DORA (EU) 2022/2554, applies since 17 Jan 2025[4] | Art. 13(6) | ICT security awareness programmes and digital operational resilience training as compulsory modules for all employees and senior management, complexity proportionate to the role. | Adaptive assignment by measured failure; audit-adjusted compliance scorecard; per-role campaign scoping. |
| DORA | Art. 5(4) | The management body actively keeps its ICT-risk knowledge current through regular, proportionate training. | A separate board cohort with its own completion evidence and certificates. |
| NIS2 (EU) 2022/2555[3] | Art. 21(2)(g) | Basic cyber hygiene practices and cybersecurity training as a minimum mandatory measure. | Server-side completion gate — evidence of training taken, not training assigned. |
| GDPR (EU) 2016/679 | Art. 39(1)(b) | Staff awareness-raising and training inside the DPO's monitoring remit. | Policy acknowledgement with version tracking; SIEM export. |
| ISO/IEC 27001:2022[5] | Cl. 7.2 / 7.3, A 6.3 | Competence, awareness, and information security awareness, education and training. | Certificate public verification page; audit log. |
| BDDK Türkiye | — | Regulated banking obligations for entities reporting in Türkiye. | Selectable per tenant alongside the frameworks above. |
Regulatory summaries are for orientation, not legal advice. Scope and classification depend on your member state's transposition. The completion gate and compliance scorecard start at Essentials; policy acknowledgement, certificate public verification and the Human Risk Score at Professional; audit log and SIEM export at Enterprise.
The four mechanisms this page rests on.
Server-side completion gate
Eight simulation channels
A score that shows its working
Directory and email sync
Related reading: deepfake voice attacks on finance teams, and the glossary entries for CEO fraud, invoice fraud and business email compromise. Our own posture is on Trust and Security.
Questions
What a CISO or a DPO in a financial entity asks first.
Every figure on this page, and where it came from
Last reviewed: 11 August 2026. Regulatory citations are checked against the consolidated text at EUR-Lex on each review.
- 2026 Data Breach Investigations ReportVerizon Business — industry section, p. 84 for Financial and Insurance (NAICS 52). Corpus: 31,000+ incidents, 22,000+ confirmed breaches, 145 countries, Oct 2024 – Nov 2025 · 2026Used for: Financial and Insurance (52) — 3,809 incidents and 1,300 with confirmed disclosure; 65% human element; 20% phishing against 22% vulnerability exploitation; 88% external actors and 98% financial motive.
- Directive (EU) 2022/2555 (NIS2)Official Journal of the European Union, OJ L 333, 27.12.2022 · 2022Used for: Articles 20(2) and 21(2)(g).
- Regulation (EU) 2022/2554 (DORA)Official Journal of the European Union — applicable from 17 January 2025 · 2022Used for: Article 13(6) on compulsory awareness and resilience training modules, and Article 5(4) on the management body's own knowledge.
- ISO/IEC 27001:2022 and ISO/IEC 27002:2022International Organization for Standardization — 3rd edition · 2022Used for: Clauses 7.2 and 7.3; the title of Annex A control 6.3.
- Internet Crime Report 2025FBI Internet Crime Complaint Center (IC3) · 2026Used for: Business email compromise — 24,768 complaints and US$3,046,598,558 in reported losses.
- Arup confirms it was the victim of a $25 million deepfake fraudCNN — reporting on the Arup case, February 2024 · 2024Used for: US$25.6m paid across 15 transfers after a deepfake video call.
- Ferrari executive foils deepfake attempt by asking the caller a questionFortune — reporting on the Ferrari attempt, July 2024 · 2024Used for: The attempt stopped by a verification question only the real executive could answer.
- Attempted audio deepfake call targets LastPass employeeLastPass company blog · 2024Used for: A CEO voice deepfake delivered over WhatsApp, which the employee reported rather than acting on.