Cloning a voice takes a few seconds of audio. Faking a video call is not far behind. The attacks aimed at small firms are simple: “It's the boss, pay this invoice today.” “It's your supplier, our bank details have changed.” We design and test the verification steps that stop them: for your team, your customers and your AI voice agents.
An urgent payment, a cloned voice, and a plausible reason not to talk later.
By email or phone, with the right logo and a familiar name.
Someone rings the office as a colleague and gets back in.
A fake HR or finance message that staff follow because it looks normal.
Deepfake video is now good enough for a short call.
If it can book, move or disclose, it needs to verify callers too.
This is identity verification for people, not systems. The principle has protected bank payments for decades: urgency is not proof, and no single voice is enough for a big action.
The requests that cost money, and the check for each.
| Request | Arrives as | Check |
|---|---|---|
| Urgent payment | Call from the “boss” | Call-back + 2nd approver |
| New bank details | Email on supplier letterhead | Call the number on file |
| Reset my password | Call to the office | ID check + manager confirms |
| Move my booking | Call to your voice agent | One-time code |
| Send me the file | Message from a colleague | Confirm on a second channel |
Each check is small. Together they stop the attack.
For a team of up to 30, design and training take about two weeks. Testing follows a few weeks later, once the new habits have settled.
Which actions could cost you money or data, and who can trigger them today.
A verification ladder, scaled to risk, that your team can follow on a busy day.
Procedures written, voice agent configured, staff trained, suppliers told.
Controlled simulated attempts by phone, email and voice-agent call, then adjustments.
A building contractor's office manager took a call from the “managing director” asking for a same-day payment to a new subcontractor. Under the new ladder, any new payee needed a call-back to the MD's known number and a second approver. The call-back went to the real MD, who was on site and knew nothing about it.
Illustrative example, drawn from typical findings. Not a named client.
“Access control is the part most AI suppliers wave at. It's the part we came from.”
Yes. The tools are cheap and the attacks target people, not systems, so size doesn't protect you. Smaller firms are often targeted precisely because one person can approve a payment.
A little, once. Owners who've been through an attack say the alternative is far worse. The ladder is light for everyday actions and firm for the few that move money or data. The owner sets it, so nobody is “disobeying”.
Yes, and it's often the weakest link: an agent that confirms bookings or discloses details to anyone with a name. We configure it to verify first. If we built it, this comes as an upgrade.
A word or phrase agreed in person and used to confirm urgent requests. It works when it's kept off email and changed now and then. It's one rung of the ladder, not the whole thing.
Only with your written agreement, within agreed limits, and never to embarrass anyone. The results improve the process. They are not used to blame people.
A fixed price after a free discovery call, based on your team size and the channels involved. Testing can be a one-off or repeated each year.