Financial servicesEvery control held. The voice on the call was not.

Four-eyes approval, a payment threshold, a callback policy — and a finance team that did exactly what it was trained to do. In the Arup case the deception survived a video call and moved $25.6 million across fifteen transfers. The defence that works is not a sharper ear. It is a process step that does not care how convincing the caller is.

Verizon DBIR 2026, Financial and Insurance (52) · 3,809 incidents, 1,300 with confirmed disclosure
DORA · NIS2 · GDPR · ISO 27001 · EU data residency (Frankfurt)
Payment approval chain
Simulated — product demonstration
Invoice received
Matched to an open purchase order
Four-eyes approval
Two approvers, both above threshold
Voice confirmation — CFO
Voice cloned from three seconds of audio.
Callback to the number on file
Verified out of band, against a contact we already held
Outcome€2,400,000 · approvedHeld · verified out of band
Illustrative sequence. The Arup and Ferrari cases are cited in the sources below. No real counterparty, account or brand appears.
Payment approval chain
Simulated — product demonstration
Invoice received
Matched to an open purchase order
Four-eyes approval
Two approvers, both above threshold
Voice confirmation — CFO
Voice cloned from three seconds of audio.
Callback to the number on file
Verified out of band, against a contact we already held
Outcome€2,400,000 · approvedHeld · verified out of band
Illustrative sequence. The Arup and Ferrari cases are cited in the sources below. No real counterparty, account or brand appears.
Human risk in financial services

NOUSEC gives financial entities the evidence DORA asks for and the simulations the current fraud actually uses. DORA Article 13(6) makes ICT security awareness programmes and digital operational resilience training compulsory modules for all employees and senior management, and Article 5(4) obliges the management body to keep its own ICT-risk knowledge current. NOUSEC runs simulations across eight channels — including voice and deepfake video at the Enterprise tier — verifies completion server-side rather than accepting a browser's word for it, and reports per-module effectiveness as a correlation with real click rate.

What the data says

Your sector, in its own numbers.

65%[1]
of breaches in Financial and Insurance (52) involve the human element
20%[1]
phishing as an initial access vector in the sector — second only to vulnerability exploitation at 22%
88%[1]
of actors in the sector are external; 98% of motives are financial
$3.05bn[6]
reported business email compromise losses in 2025, across 24,768 complaints

Verizon's dataset is contributed casework, not a representative sample of all breaches; industry figures are for prioritisation.

The argument

The control worked. That was the problem.

Every published deepfake-fraud case of the last two years was stopped — or not stopped — by a process step, never by someone's ear.

Three published deepfake-fraud cases, the channel used, what was asked, and the outcome
CaseChannelWhat was askedOutcome
Arup, Feb 2024Multi-person video call15 transfers~US$25.6m paid[7]
Ferrari, Jul 2024Voice call impersonating the CEOUrgent confidential dealStopped — the employee asked a question only the real CEO could answer[8]
LastPass, Apr 2024Voice deepfake over WhatsAppContact outside normal channelsStopped — the employee reported it[9]

The two that were stopped have nothing to do with detection. Nobody heard a synthetic artefact. One employee ran a verification step the attacker could not pass; the other noticed that the channel was wrong and reported it rather than replying.

That is a process control and a reporting culture, and both are trainable. Neither is improved by telling people to listen harder — the honest position, which we teach, is that on the hardest pairs you cannot tell by ear.

So the training target is not perception. It is: verification through a channel you already hold, an escalation path for vendor bank-detail changes, and an organisation where saying “no” to the CEO is safe.

We simulate this. Voice and deepfake video campaigns are Enterprise-tier and delivered white-glove with our team, not self-serve from the console.
Who we have to reach

Finance, treasury, and the people who can move money.

Reach in this sector is not a coverage problem — almost everyone has a mailbox. It is a targeting problem: the smallest populations carry the largest single-transaction risk, and they need a different campaign from everyone else.

Highest value, smallest population

Payments and treasury

The highest-value target and the smallest population. Deserves spear-phishing and callback (TOAD) simulation, not the same annual module as everyone else.

Trained to be helpful

Relationship and client-facing staff

Trained to be responsive and helpful, which is the exact behaviour a pretext exploits. Adaptive path assigns by measured failure, not by role assumption.

A personal obligation

The management body

DORA Art. 5(4) is a personal obligation on them, and NIS2 Art. 20(2) makes board training mandatory where the entity is in scope of both. Completion evidence for the board has to be as defensible as everyone else's.

What you have to evidence

The article, and the artefact that answers it.

The fourth column is the only one that mentions the product, and it names a mechanism rather than an intention.

Instruments, articles, what each requires, and the NOUSEC mechanism that evidences it
InstrumentArticleWhat it requiresHow NOUSEC evidences it
DORA (EU) 2022/2554, applies since 17 Jan 2025[4]Art. 13(6)ICT security awareness programmes and digital operational resilience training as compulsory modules for all employees and senior management, complexity proportionate to the role.Adaptive assignment by measured failure; audit-adjusted compliance scorecard; per-role campaign scoping.
DORAArt. 5(4)The management body actively keeps its ICT-risk knowledge current through regular, proportionate training.A separate board cohort with its own completion evidence and certificates.
NIS2 (EU) 2022/2555[3]Art. 21(2)(g)Basic cyber hygiene practices and cybersecurity training as a minimum mandatory measure.Server-side completion gate — evidence of training taken, not training assigned.
GDPR (EU) 2016/679Art. 39(1)(b)Staff awareness-raising and training inside the DPO's monitoring remit.Policy acknowledgement with version tracking; SIEM export.
ISO/IEC 27001:2022[5]Cl. 7.2 / 7.3, A 6.3Competence, awareness, and information security awareness, education and training.Certificate public verification page; audit log.
BDDK TürkiyeRegulated banking obligations for entities reporting in Türkiye.Selectable per tenant alongside the frameworks above.

Regulatory summaries are for orientation, not legal advice. Scope and classification depend on your member state's transposition. The completion gate and compliance scorecard start at Essentials; policy acknowledgement, certificate public verification and the Human Risk Score at Professional; audit log and SIEM export at Enterprise.

Product proof

The four mechanisms this page rests on.

Server-side completion gate

A video is complete at ≥ 90% unique-second watch coverage, computed on our servers. Accrual pauses when the tab is hidden.
Security awareness training

Eight simulation channels

Email, QR, USB, SMS, WhatsApp, callback, voice and deepfake video — the last four at Enterprise, delivered white-glove.
Phishing simulation

A score that shows its working

0–100, published methodology, never rendered without its component breakdown — including to the person being scored.
Human Risk Score

Directory and email sync

Cohorts follow your directory, so a board cohort and a treasury cohort stay accurate without a spreadsheet.
Integrations

Related reading: deepfake voice attacks on finance teams, and the glossary entries for CEO fraud, invoice fraud and business email compromise. Our own posture is on Trust and Security.

What this will not do.
NOUSEC does not detect a deepfake in a live call, and we will not sell you a detector. There is no reliable consumer-grade way to do that today, and a false sense of detection is worse than none. What we do is train and measure the process controls that hold regardless — and teach, honestly, that the hardest audio pairs cannot be distinguished by ear.

Questions

What a CISO or a DPO in a financial entity asks first.

Does NOUSEC satisfy DORA's training requirement?

DORA Art. 13(6) requires ICT security awareness and digital operational resilience training as compulsory modules for all employees and senior management, proportionate to role. NOUSEC provides the assignment, the delivery, the server-side completion evidence and the exportable record. Whether your overall programme satisfies your supervisor is a matter for your supervisor.

Can you simulate a deepfake voice call?

Yes, at the Enterprise tier, delivered white-glove with our team rather than self-serve from the console.

How do you prove someone actually did the training?

A video is complete at ≥ 90% unique-second watch coverage, computed server-side. Accrual pauses when the tab is hidden. A forged completion request returns 403.

Will this show us which training reduced real risk?

Per module, we publish the Pearson correlation between completion and real phishing click rate — and suppress it below ten data points rather than showing a number the sample cannot support.

Does anything get installed on a trader's or a treasurer's device?

No. No endpoint agents. The report button is an optional mail-client add-in.

Receipts

Every figure on this page, and where it came from

Last reviewed: 11 August 2026. Regulatory citations are checked against the consolidated text at EUR-Lex on each review.

  1. 2026 Data Breach Investigations Report
    Verizon Business — industry section, p. 84 for Financial and Insurance (NAICS 52). Corpus: 31,000+ incidents, 22,000+ confirmed breaches, 145 countries, Oct 2024 – Nov 2025 · 2026
    Used for: Financial and Insurance (52) — 3,809 incidents and 1,300 with confirmed disclosure; 65% human element; 20% phishing against 22% vulnerability exploitation; 88% external actors and 98% financial motive.
  2. Directive (EU) 2022/2555 (NIS2)
    Official Journal of the European Union, OJ L 333, 27.12.2022 · 2022
    Used for: Articles 20(2) and 21(2)(g).
  3. Regulation (EU) 2022/2554 (DORA)
    Official Journal of the European Union — applicable from 17 January 2025 · 2022
    Used for: Article 13(6) on compulsory awareness and resilience training modules, and Article 5(4) on the management body's own knowledge.
  4. ISO/IEC 27001:2022 and ISO/IEC 27002:2022
    International Organization for Standardization — 3rd edition · 2022
    Used for: Clauses 7.2 and 7.3; the title of Annex A control 6.3.
  5. Internet Crime Report 2025
    FBI Internet Crime Complaint Center (IC3) · 2026
    Used for: Business email compromise — 24,768 complaints and US$3,046,598,558 in reported losses.
  6. Arup confirms it was the victim of a $25 million deepfake fraud
    CNN — reporting on the Arup case, February 2024 · 2024
    Used for: US$25.6m paid across 15 transfers after a deepfake video call.
  7. Ferrari executive foils deepfake attempt by asking the caller a question
    Fortune — reporting on the Ferrari attempt, July 2024 · 2024
    Used for: The attempt stopped by a verification question only the real executive could answer.
  8. Attempted audio deepfake call targets LastPass employee
    LastPass company blog · 2024
    Used for: A CEO voice deepfake delivered over WhatsApp, which the employee reported rather than acting on.

Bring the payment you nearly made.

We will run the scenario against your own approval chain, on a call, not in a deck.

GDPR native · EU data residency (Frankfurt) · No endpoint agents · Pricing