Over the past few weeks, several major asset managers have disclosed a similar cyber incident. In each case, the way in wasn’t a piece of malware or an unpatched server. It was a phone call. Someone posing as internal IT support convinced an employee they were exactly who they claimed to be, and that was enough to get inside.
Apollo Global Management was one of the firms caught up in this wave, and its disclosure has understandably received a lot of attention. But the real story is about a threat that hits every organization. Vishing campaigns like this one aren’t exploiting a weakness in one company’s security stack. They’re exploiting something every organization depends on, trust. The same trust that lets a helpdesk call, a Teams message or an email from a colleague get taken at face value.
When Trust Is the Attack Surface
AI is making trust harder to protect. Voice cloning tools can recreate how someone sounds from a short audio clip. Generative AI can write in a colleague’s exact style. A threat actor no longer needs insider knowledge to sound convincing enough to get someone to click, share a code or grant access. Across the board, AI is lowering the skill it takes to run a social engineering attack, while making each campaign more convincing.
That has real consequences for how you respond. The regular communication channels your team uses are the same ones the attacker just proved they can imitate. If they still have access, they’re watching your response unfold in real time. A message from your security lead or IT helpdesk can’t be trusted by default anymore, because that’s exactly how the attacker got in. Your team ends up running incident response blind, unable to tell if instructions are real or coming from the attacker.
It’s not just the communication channels you can’t trust. Your incident response plan usually lives in the same environment that may be compromised, whether that’s a shared drive, an intranet page or a document library anyone in the company can open. If a threat actor has a foothold in your systems, there’s a real chance they can read your playbook before you execute it, see who’s supposed to be on the call and watch you decide what to do next. A plan the attacker can read isn’t much of a plan.
Isolation Without Verification Is False Security
An out-of-band system, isolated from anything an attacker could access, is the right instinct and it’s not unique to CYGNVS. Any well-built, out-of-band system gets you that far. What’s harder is building one your team uses and trains in before a crisis ever hits, one you can sever from everything else the moment something goes wrong while still controlling exactly who gets let back in. That control matters. A major incident pulls in people from across the business, plus outside counsel, forensics and other external providers, all within hours. You can’t just wave anyone through.
Here’s how I explain this to CISOs. Picture an island off the coast of your main operations. That island holds your out-of-band incident response system: the tools, the playbooks, everything your team needs to run a response, kept separate from your everyday environment. Sounds great until you realize that many of those on your team know the island exists but don’t remember their logins. Others can login but don’t remember how to use the system. And some of the people you need most at the point of the incident don’t even know said system exists.
In the middle of a real incident, an island nobody can reach is useless.
The natural fix is to build a bridge, so your team can walk back and forth freely. The problem is the bridge doesn’t check who’s crossing If the attacker has already impersonated someone on your team, they can walk across that same bridge right behind you. Your “isolated” response room isn’t isolated at all, and neither are the plans inside it.
Doing Out-of-Band Incident Response Right
What organizations need is an island with a checkpoint and a retractable bridge. In peacetime, the bridge stays down. Your team crosses back and forth freely: running tabletop exercises, getting comfortable with the room, building the muscle memory they’ll need later. When the incident is upon you, everyone who needs to enter the island has to verify who they are at the checkpoint first. That verification is what we call out-of-band identity. It’s more than just a badge. It’s a set of criteria your organization defines for who’s allowed across in an incident. Every customer defines their Out-of-Band identity in different ways and sometimes it differs based on the type of incident.
Once the right people are in, the bridge retracts. The room seals, and everything inside seals with it: your conversations, your playbooks, your evidence, your decisions. Legal, forensics, your insurer, whoever needs to be inside can operate there. Nobody who wasn’t verified at that checkpoint can follow them in or read what’s being planned, no matter how convincingly they can imitate your IT helpdesk. This is what Isolate Mode does inside CYGNVS. When your team triggers it, CYGNVS cuts the room’s connections to the rest of your systems, sealing off everything inside until you decide who else needs in.
The core idea behind the CYGNVS patent: out-of-band requires a customizable identity that’s verifiable at the checkpoint and the ability to fully retract the bridge once everyone is on the island. An island by itself doesn’t get used. A bridge by itself doesn’t stay secure. You need both, working together. Neither one does its job alone.
What Separates the Ready from the Rest
Sophisticated social engineering is only going to get harder to stop. AI is putting these techniques within reach of more threat actors and making each one more convincing. It’s easy to watch incidents like these unfold from afar and assume it won’t happen to you.
But a more useful exercise is to reflect inward. If the channels your team relies on every day, the emails, the calls, the shared drives, were compromised tomorrow, could you still run your response from somewhere the attacker can’t see? Could your team get there without a login nobody remembers? And once inside, would the attacker be able to follow?
That’s what an island with a retractable bridge and a checkpoint is for. A system your team has practiced in, so it works when you need it to. A door nobody crosses without proving who they are. Vishing succeeds by exploiting the trust built into the tools your team uses every day. An out-of-band command center with Isolate Mode is how you take that question off the table.
About the Author
Arvind Parthasarathi is the Founder and CEO of CYGNVS, the out-of-band command center that over 3,000 organizations rely on for cyber incident response management. Arvind also serves on the technical advisory council of the Allen Institute for Brain Sciences and on the board of trustees of the Center for Excellence in Education.
Follow Arvind on LinkedIn for more on cyber resilience and incident response.