← Vercon Research

4 min read

Voice Security·

Caller Verification Should Not Depend on Memory

LH
Lesia Hawkins
Director, Threat Research & Intelligence, Vercon
modern operations workspace with displays

Most organizations already have policies for voice security. The failure point is usually the handoff: what the employee hears, what the system records, and what the next person is allowed to assume.

A useful public reference point is CISA's "Scattered Spider Cybersecurity Advisory" (2023-11-16), which shows why voice, identity, and approval controls now belong in the same operating conversation.

That record should be useful to managers, not just auditors. A supervisor should be able to see rising call volume, repeated destination changes, unusual after-hours activity, transcript-sensitive terms, and overage patterns without waiting for a post-incident report.

Policy should be written in plain language. Employees need to know which requests require a callback, which require a second approver, and which the system should refuse outright.

The point is not to make every call suspicious. The point is to stop treating the telephone as a low-risk side channel. In an AI-assisted fraud environment, the voice channel deserves the same management discipline as login, payments, email, and customer data access.

Referenced reporting

Links are provided for reference and are not legal advice or a guarantee of verification.

#caller verification#identity proofing#social engineering

Find out where your communications channels are exposed.

A Vercon Communications Security Assessment gives you an executive-readable risk report and a prioritized remediation roadmap, usually inside of four weeks.