The Multichannel Deception Problem: Why CISOs Are Missing The Most Vulnerable Attack Vector
Firas Azmeh, President of Mobile Endpoint Security at Lookout.
gettyFor over two decades, enterprise security strategy treated social engineering almost exclusively as an email problem. CISOs invested billions of dollars fortifying corporate inboxes with secure email gateways (SEGs), enforcing strict DMARC policies and conducting continuous phishing simulations for employees.
Email security remains a necessity. Securing the inbox is critical, but in the age of AI, it is no longer sufficient on its own. While organizations hardened their front door, modern adversaries did not abandon social engineering—far from it. Instead, they shifted their focus toward non-email communication vectors such as SMS (smishing), direct messaging, phone calls (vishing) and digital QR codes (quishing).
Now, fueled by the hyper-growth of the AI-driven threat landscape, mobile has become the primary, most vulnerable surface for human-layer attacks. AI has drastically accelerated the speed, scale and efficacy of modern deception. Social engineering hasn’t died; it has evolved from an email protocol attack into a hyper-personalized, multichannel AI-fueled human interaction attack. To defend the modern enterprise, security leadership must reframe their approach from inbox filtering to multichannel, point-of-interaction defense.
Why are adversaries finding such fertile ground across mobile messaging and voice channels? The answer lies in the psychological and technical dynamics of mobile human behavior:
• Urgency And Context-Switching: Email is traditionally processed in deliberate batches. Mobile messaging relies on push notifications, driving rapid, instinctive responses before an employee’s critical thinking kicks in.
• The “Small Screen” Visual Blind Spot: Mobile form factors obscure essential security cues. Reduced screen size makes inspecting sender origins, verifying domain headers or previewing underlying URLs significantly harder than on a desktop browser.
• The Fallacy Of Personal Versus Professional Trust: Employees naturally view SMS, WhatsApp or phone calls as personal, high-trust channels. Lacking the spam warnings and banner disclaimers common in corporate email, users instinctively drop their security guard.
• The AI Acceleration Effect: AI has removed the traditional telltale signs of social engineering. Voice cloning allows attackers to impersonate executives or IT help desks over live calls, while large language models generate flawless, context-aware messages across text and chat apps at scale.
The core challenge facing enterprise defense is architectural. Traditional secure email gateways and web proxies rely on inspecting SMTP traffic or forcing browser sessions through corporate network tunnels. Mobile communications, on the other hand, operate entirely outside these inspection pipes.
Cellular SMS and MMS traffic bypass corporate firewalls by design. End-to-end encrypted messaging applications prevent network-level content inspection. Furthermore, in hybrid and bring-your-own-device (BYOD) models, routing personal communication through intrusive corporate proxies creates severe privacy violations and network performance issues.
Securing the corporate inbox while neglecting mobile leaves over 80% of an employee’s daily digital communication channels completely unmonitored. Attackers exploit this gap to bypass multifactor authentication (MFA), harvest enterprise credentials and execute wire fraud without ever sending a single email.
Security leaders must maintain their email protections while extending their defensive perimeter to secure the broader human layer.
Map every channel where employees, vendors and partners interact outside of Outlook or Gmail. Identify where SMS-based MFA codes, vendor coordination and team chats occur across both corporate and personal mobile devices. Understanding this unmonitored surface is the first step toward securing it.
Standard security awareness training is heavily anchored in identifying desktop email formatting. Curricula must evolve to train employees on multichannel escalation tactics, such as receiving a text message immediately following an AI-generated voice call and recognizing conversational pressure and acoustic deception.
Network proxies and inbox filters cannot see mobile threats. CISOs must transition toward security architectures that evaluate intent, context and content natively on the device—at the exact point where the human interacts with the communication—without violating user privacy.
In the modern enterprise, identity is the new perimeter, but human trust is the vector being actively exploited.
Security leadership must accept that protecting the email inbox is no longer synonymous with protecting the workforce. As AI continues to supercharge modern deception, the future of social engineering defense belongs to organizations that protect their people across every communication channel they touch.
Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?


