Insider Threat: Vishing Attacks and MFA Prevention
This memo-format paper examines vishing — a voice-based phishing attack — as a significant insider threat to corporate organizations. It provides background on how vishing exploits internal stakeholders to obtain sensitive information, potentially costing organizations tens of thousands to millions of dollars annually. The paper analyzes two primary countermeasures: multi-factor authentication (MFA) and restricted VPN connections. It compares both approaches on the basis of security depth, physical access protection, and breadth of available tools. The paper concludes that MFA mechanisms are the superior solution because they offer a wider range of authentication tools, including biometrics, device assessment, and knowledge-based verification, making them more resilient against vishing-enabled unauthorized access.
- Bottom Line Up Front: MFA recommended to prevent costly vishing attacks
- Background: Insider Threat and Vishing: Defines vishing risk and financial impact
- Analysis of Prevention Options: Compares MFA and VPN restriction approaches
- Conclusions and Recommendations: MFA preferred for broad security tool range
✍️ How to write this paper — guide, tools & examples ▾
What makes this paper effective
- The BLUF (Bottom Line Up Front) format immediately signals the memo's recommendation, a hallmark of professional business and government communication that respects the reader's time.
- The comparative analysis section systematically evaluates both solutions on the same criteria — layers of security, device restrictions, and physical access protection — making the final recommendation logically grounded rather than arbitrary.
- Concrete financial figures (e.g., $58,000 average loss for small businesses, 76% of businesses affected annually) anchor abstract security risks in measurable business impact.
Key academic technique demonstrated
The paper demonstrates structured comparative analysis: rather than simply advocating for one solution, it presents two viable options with parallel criteria, identifies where they overlap, and then explains which is superior and why. This technique is essential in professional and policy writing, where decision-makers need to understand trade-offs, not just conclusions.
Structure breakdown
The paper follows a standard executive memo format: a BLUF statement previews the recommendation; the Background section defines the threat and quantifies risk; the Analysis of Options section introduces and compares MFA and VPN restrictions; and the Conclusions and Recommendations section restates the preferred solution with justification. References in APA style support the factual claims throughout.
Bottom Line Up Front
To: [Recipient]
From: [Sender]
Date: April 20, 2022
RE: Insider Threat – Vishing
A vishing attack is a major insider threat that could result in losses of billions of dollars for an organization due to unauthorized access to corporate systems. Multi-factor authentication (MFA) mechanisms are the most effective approach to preventing vishing attacks because they provide a wide range of security tools for an organization.
Background: Insider Threat and Vishing
Insider threat is one of the most common issues in the corporate and intelligence world. While it is often a high priority for senior management, definitional challenges have made it difficult for many organizations to identify and resolve this issue. According to the National Insider Threat Task Force, insider threat refers to the threat an insider poses to U.S. national security when he or she uses authorized access — knowingly or unknowingly — to cause harm (Cybersecurity and Infrastructure Security Agency, 2020). However, insider threat extends beyond risks to national security, as it also occurs in the corporate and intelligence world and can include actions as seemingly minor as forgetting to lock a computer. In essence, an insider threat is a security risk emanating from within the targeted organization through the intentional or unintentional acts of its internal stakeholders.
This organization faces the risk of vishing, a security threat that falls under the broader category of phishing attacks. Vishing is carried out against a targeted organization to obtain sensitive information that could be used for identity theft or financial gain. It involves the use of fraudulent phone numbers, text messages, and voice-altering software to trick users into providing sensitive information (Pangaro, 2020).
As the organization continues to rely on technology, vishing remains an insider threat capable of compromising its effective operations and success. If any internal stakeholder answers a call from a fraudulent phone number, he or she could provide cybercriminals with sensitive information that results in significant losses. A successful vishing attack could give cybercriminals access to sensitive customer data, financial assets, systems, files, and trade secrets. Whether a stakeholder participates wittingly or unwittingly, the organization could lose at least $58,000. Pangaro (2020) notes that a successful vishing scam results in losses worth multi-millions of dollars annually, while the average cost for small businesses is $58,000.
Vishing attacks remain major insider threats given that nearly 76% of businesses suffer from this risk each year. Therefore, the organization needs to develop a suitable framework to prevent and deter this form of insider threat. By establishing a proper prevention and deterrence framework, the company would reduce the risk of significant financial losses and operational disruptions. In short, the organization could save more than $58,000 by building a strong framework to prevent and reduce its vulnerability to vishing attacks.
References
Cybersecurity and Infrastructure Security Agency. (2020). Insider threat mitigation guide. U.S. Department of Homeland Security. https://www.cisa.gov
Jang-Jaccard, J., & Nepal, S. (2014). A survey of emerging threats in cybersecurity. Journal of Computer and System Sciences, 80(5), 973–993.
Nwabueze, E., Obioha, I., & Onuoha, O. (2017). Enhancing multi-factor authentication in modern computing. Communications and Network, 9, 172–178.
Pangaro, J. J. (2020). The insider threat related to cybercrime. Retrieved April 20, 2022, from https://www.govpilot.com/blog/the-insider-threat-related-to-cybercrime
Create your account
Always verify citation format against your institution’s current style guide requirements.