ThreatWatch

Vishing Simulation Platforms Compared: Adaptive, Brightside, Keepnet

Adaptive Security, Brightside AI and Keepnet Labs compared. We look at how each platform handles vishing simulations.

A gold trophy on a grey background, captioned 'Comparing vishing simulation platforms'.

Sponsored by Brightside AI.

Let’s talk about vishing. In 2025 and 2026, it kind of became a huge deal. According to CrowdStrike, vishing intrusions increased twofold in H1 of 2026. In 2025, Mandiant reported that vishing accounted for 11% of initial infections compared to 6% for email phishing. In 2025 it was mostly human callers; now it has become more automated with the help of AI, and there are bespoke phishing kits, synchronized calls with login pages and MFA prompts, and multilingual AI caller agents. Basically, in 2026 voice phishing became operationally mature and partially automated.

Obviously, defenders need to answer that threat. One of the things that was immediately clear is that there’s not really a technical solution to the problem, and what has to be trained is correct behavior, based on the verification policy a company has.

Rehearsal scenario

What must happen in a simulation? Typically, an employee receives a call, where the attacker has to convince the employee to do something, like share a TOTP code. Often it is also combined with an email of some sort that should further convince the employee that nothing out of the ordinary is happening.

To set up something like that is not that trivial actually; it’s a complex campaign that requires a lot of thought and effort, so it was interesting to see how modern SAT vendors handle stuff like that.

How SAT vendors handle vishing simulations

We decided to evaluate several platforms, but we need to acknowledge some limitations. Since we don’t actually have direct access, we need to rely on what’s available online and how vendors themselves describe their features, so clarity of marketing materials actually also becomes an important point to consider. We also decided to limit the number of platforms, because we actually check things manually and we want to be thorough.

Adaptive Security: A Comprehensive Multichannel Phishing Simulation Platform

Adaptive Security is a popular platform that grew very fast, even though it’s relatively new on the market. It’s kind of an all-in-one platform, since they simulate attacks across email, SMS, voice and deepfakes, so it basically covers everything. Their general approach seems to be using OSINT for personalization, then the simulation can be deployed in any channel, in our case it’s voice. If an employee fails, they provide a micro-lesson to explain what they did wrong. And finally each interaction is scored for reporting purposes.

Based on what we were able to gather from public sources, official materials, and a preview available on their website (which was not very easy, actually), the flow looks something like this: Configure targets → Pick a voice scenario → Preview/test → Run campaign → Employee interacts → Reveal/training → Review results

Targets can be individual employees, custom groups, or departments. A vishing simulation can be combined with an email or SMS for example. The call itself is handled by an AI agent in real time. After the call is done, Adaptive evaluates the interaction and the employee receives a follow-up, and, depending on the result, they also can get additional micro-training.

Here’s what’s included in reporting for vishing simulations: pickup rates, callback rates, call durations, and AI-generated summaries of how each call went.

Overall, it seems like a comprehensive flow that allows you to recreate real attacks, but there’s a catch. We don’t have access to the platform and it wasn’t easy to figure out what the flow actually looks like.

Brightside AI: Best Self-serve Live Vishing Simulations

What’s great about Brightside AI is that they clearly showed how their vishing simulator works. They have two product update articles right in their blog that describe each step with screenshots and video! To be fair, it’s a bit outdated, but they did release another product update article that explains in the same detailed manner what changed. You basically can just go to their website and check their product page and blog, and you will have all the information you need to know.

But since you’re here, let’s run through Brightside’s vishing simulator. Here’s what the flow looks like: Configure targets → Pick a voice scenario → Preview/test → Run campaign → Employee interacts → Reveal/training → Review results

First, you choose the target. It can be either an individual employee or a group. Groups can be defined however you want; it can be a department or maybe employees who just recently joined.

Then you choose the attack type: voice only or voice + BEC. Once you choose a type, you select a template. Templates are automatically filtered based on the attack type, and you can select multiple templates.

The next step is settings, where you define the schedule and delivery conditions for the simulations.

Things like attack goal, attacker persona, simulated voice and social engineering tactics are defined at the template level. Basically, you create a template and then set up a simulation campaign.

Interestingly, unlike Adaptive Security, you can define not just the goal of the simulation, but how exactly the AI agent will try to socially engineer the target, like applying pressure or maybe creating intrigue. You can define tone and add other details as an additional prompt for an AI agent.

The voice library has multiple voices in multiple languages. There are also custom voices with added artifacts that simulate how real phone calls sound. In reality, some voices are not as good as the others, but just as with Adaptive, they allow you to clone voices, so you don’t have to rely on the library of pre-defined voices.

What we really liked is transparency. They weren’t afraid to show how their vishing simulator works, which is really nice, and they do have some features, like social engineering tactics, that Adaptive Security doesn’t have.

For transparency’s sake, we did have access to the platform itself, since Brightside AI sponsored the article.

Keepnet Labs: Capable Vishing Simulator

Keepnet Labs is a very broad platform that covers phishing, smishing, quishing, callback phishing, and vishing. They also have very clear public-facing documentation, which is really nice if you want to evaluate the platform’s capabilities without having to book a call or surrender your email to get a walkthrough.

Here’s the general flow: Create or select a template → Configure campaign → Select target group → Configure call delivery → Review and launch → Employee interacts → Review results

Before a campaign can be created, employees must be added to a group. All three platforms have their own version of that workflow, and all three platforms allow you to select groups as targets.

The vishing template is what defines difficulty, language, and AI voice. Once the template is ready, you create a campaign. First, you name it and choose whether to send it now, save it for later, or schedule it for a specific date and timezone. Then you select the vishing template, choose the target group, and review the employees and phone numbers included.

For some reason, their vishing simulator still has a text-to-speech option, which kind of feels pointless when they also have live AI agents like Adaptive and Brightside.

To be honest, Adaptive and Brightside feel more polished and more modern, while Keepnet kind of feels outdated, but in terms of capability they’re all similar.

Comparing all three

Brightside offers a bit more customization and steering options for their AI agent, which is a really nice addition, and if you don’t like a black-box-style approach, Brightside stands out here.

Adaptive Security uses OSINT, but we couldn’t confirm how effective it is. Brightside also allows for personalization based on employee role, department, and things like that, but if we had to guess, Brightside probably is more focused on providing comprehensive scenario customization, while Adaptive is more focused on automating that part.

As we said earlier, Keepnet feels a bit outdated, but in terms of capability it’s close to the other two, at least on paper. The advantage of Keepnet Labs is just how broad the platform is: it supports hundreds of languages and has thousands of templates (2,700 vishing templates). It’s very comprehensive.

One thing is clear: if you’re shopping around, Brightside AI’s website basically has everything you need to know about their product. With Adaptive Security you’d have to interact with their sales team to actually get a clear picture of how vishing simulations work. Keepnet Labs has documentation, but it seems outdated because it only mentions text-to-speech, while their AI caller that can adapt in real time is only mentioned in marketing materials.

Latest articles