Business Security
If the boss calls asking for money, recognising their voice is no longer enough
When a payment or access request arrives by video or phone, verify the request through a process you already trust—not by judging how familiar the caller sounds.
8 min read — Altitude IT Security Team
A finance employee joins a Teams call. The Managing Director is on screen, sounds like themselves and urgently asks for a supplier’s bank details to be changed before a payment goes out. The employee recognises the face and voice. That recognition may once have felt like enough. It should not be the approval process.
The useful response to convincing impersonation is not to train staff to become better at spotting synthetic audio or video. It is to design important business processes so that seeing or hearing someone is not, by itself, authority to move money, reset an account or grant access.
What the Gartner figures do—and do not—say
Gartner’s September 2026 survey covered 297 senior cybersecurity leaders, including CISOs and equivalents. In the previous 12 months, 41% said their organisation had encountered at least one social-engineering incident involving a deepfake audio call to an employee; 36% reported at least one involving video. The survey was conducted between March and May 2026.
Those are reports from surveyed security leaders. They are not a claim that 41% of all businesses were successfully breached, lost money or suffered the same outcome. Gartner also found that 79% of respondents reported at least one email phishing, spear-phishing or business-email-compromise incident. Ordinary email fraud remains a major concern; these figures do not establish that deepfakes are more common.
The practical point is narrower: familiar social-engineering requests can arrive through a channel that feels unusually persuasive. Controls should depend on what the request would do, not on whether the caller seems convincing.
Verify the request through a separate route
For a consequential change, staff should pause and contact the person or supplier using details already held in the business—not a number, link or email address supplied in the new request. If the request is genuine, the extra check is a small delay. If it is not, the request has not crossed the approval boundary.
Payment and supplier changes
Never accept new bank details solely from an email, telephone call, Teams meeting or video conference. Use a known supplier number from your finance system or an established contact list. Have a second person approve payment-detail changes and unusually large or urgent payments, with thresholds that fit the size and normal cash flow of the business. A second approval is useful only if the approver checks the evidence rather than repeating the first person’s assumption.
Password resets and privileged access
A familiar voice should not bypass the service desk’s identity-checking steps. Define what staff must verify before resetting MFA, changing recovery details, issuing a temporary credential or granting administrator access. The check should use an existing, independently controlled contact method or an established identity-verification process. Do not use the new phone number or alternate email address supplied in the request as proof that the request is legitimate.
Urgent requests from senior people
Urgency, secrecy and a request to skip the normal process are reasons to slow down, not reasons to create an exception. A Managing Director can authorise a business decision, but should not be able to turn a video call into a substitute for payment approval or identity verification. Make that distinction explicit in the written procedure.
Remove the “CEO override”
Even a well-written process fails if an employee believes, “The Managing Director told me to do it, so I did not want to question them.” Senior leaders need to give staff clear permission to verify unusual requests, including requests that appear to come from the leaders themselves. Nobody should be criticised for independently checking a high-impact financial or access request.
This is a management control, not just an awareness message. Rehearse the route for raising a concern, make sure people know who can approve an exception, and ensure that approval cannot be granted by the same person who initiated a sensitive change. A supportive culture can be more useful than another reminder to inspect a caller’s face for signs of manipulation.
Technology helps, but process carries the decision
Multi-factor authentication, Conditional Access, least-privilege accounts, endpoint protection and audit logs can reduce the impact of a compromised account or device. Email authentication such as DMARC can help limit some forms of domain spoofing. Payment workflows can require a second approver, and a service desk can record how an identity was checked. These controls matter, but they do not decide whether a business should change bank details because one person appeared on a call.
Cyber Essentials is a useful baseline for common technical controls; it is not a certification of deepfake detection or payment-verification procedures. Treat it as one part of security, alongside clear financial authority, identity checks and an incident route for suspicious requests.
What should businesses do?
For any request involving money, credentials or privileged access, ask:
- Was this change expected, and is it consistent with the normal process?
- Can I verify the requester using a contact route already held by the business?
- Does the change require a second approver or a recorded approval?
- Am I relying on contact details included in the request itself?
- Is anyone pressuring me to skip a check, keep the request secret or act immediately?
- Do I know how to pause the transaction and report a concern without blame?
Then test the process with a realistic scenario: a senior person asks for a supplier change during a video call, or an apparent employee requests an urgent MFA reset. A useful test is whether staff know exactly what to do next—not whether they can identify a deepfake.
Do not ask people to trust their eyes and ears more carefully. Design important processes so that eyes and ears are not enough. The IT Club has also looked at why confident AI output still needs independent human checking; the same principle applies when a request sounds familiar but carries real authority.