Social Engineering / Voice Phishing (Vishing)
Operation Silver Tongue
At 11:40 PM, an IT helpdesk analyst receives an urgent call from someone claiming to be the CFO, locked out of his account before an early-morning board call. Under pressure, the analyst resets MFA and registers a new device. Within the hour, SOC flags an anomalous login to the CFO's account from an unrecognized device and location.
Setting: Solstice Financial Group, a mid-size wealth management and fintech firm (~450 employees) handling client trading accounts and wire transfers
Objectives
- Verify and contain a compromised executive account before an attacker can reach financial or client systems.
- Determine whether client data or firm funds were actually exposed, not just at risk.
- Meet regulatory disclosure obligations accurately and on time.
- Close the identity-verification gap that let a phone call bypass MFA in the first place.
Four Roles, Four Vantage Points
Each participant sees only what their role would realistically know — the exercise is as much about getting the right information to the right person in time as it is about the technical response.
Chief Information Security Officer
You are the CISO. Your focus is incident command, executive/board communication, and coordinating the response across IT and compliance.
SOC Incident Commander
You are the SOC Lead. Your focus is detecting anomalous account activity, correlating helpdesk and authentication logs, and scoping the blast radius.
Chief Compliance Officer
You are the GRC Chief. Your focus is regulatory notification obligations, client disclosure, and audit trail integrity.
VP of IT Operations
You are the VP of IT Operations. Your focus is the helpdesk identity-verification process, MFA/credential controls, and closing the access gap that let this happen.
Five Acts
4
Financial & Regulatory Fallout
A Real Decision, Illustrated
This is the actual first decision the Chief Information Security Officer faces in Act 1 — no two playthroughs go the same way after this.
How do you direct the initial response?
-
Immediately suspend the CFO's account and all its access grants, waking him to confirm by a pre-established out-of-band channel.
Access is cut fast, but the real CFO is understandably rattled to be locked out of his own account at midnight.
-
Ask SOC to monitor the account's activity for a few minutes first to gather evidence of malicious intent before suspending it.
You gain a clearer picture of intent, but the account remains active and able to act during that window.
What You Get At The End
Every completed run generates an After-Action Report — executive summary, full decision timeline, performance scoring mapped to NIST CSF 2.0, and a concrete improvement plan. See a sample report (PDF).