By Francis West, Security Everywhere
Imagine this. Your finance manager gets a phone call. It’s you — your voice, your usual tone, even the slight rush you always have between meetings — asking for an urgent transfer to a new supplier account. Except it isn’t you. It’s an AI-generated clone of your voice, built from a few seconds of audio pulled from a podcast appearance, a conference talk, or a video on your own website.
This isn’t a hypothetical for a future talk. It’s already happening to businesses across the UK, and it’s exactly the kind of scenario I love bringing to life on stage — because nothing makes a room sit up faster than realising the “obvious” scam call isn’t obvious anymore.
Why criminals have moved from email to voice
Businesses have got better at spotting suspicious emails. So criminals have adapted, using AI voice-cloning and, increasingly, deepfake video on calls, to add a layer of “proof” that email alone never had. A convincing voice on the phone bypasses the healthy scepticism most people now apply to their inbox — because we’re wired to trust a voice we recognise.
The targets are rarely picked at random. Public speakers, business owners, and anyone with video or audio online — talks, podcasts, webinars, LinkedIn videos — are giving criminals exactly the raw material they need. The very visibility that builds trust with customers can, unfortunately, also be mined against a business if the right protections aren’t in place.
Practical steps that cost nothing to put in place
- Agree a verification process for anything involving money or sensitive data — and stick to it, no exceptions. A simple callback to a known number, or a pre-agreed code phrase for genuine urgent requests, defeats a voice clone instantly.
- Treat “don’t tell anyone else” as the biggest red flag there is. Genuine urgent business requests very rarely require secrecy from colleagues.
- Be deliberate about what audio and video of leadership goes public, and where possible, limit clean, isolated voice clips that are easy to lift and clone.
- Brief your finance and admin team specifically — this is a different threat pattern to phishing, and it deserves its own five-minute conversation, not just a line in a wider policy.
- Have a “we got it wrong” plan, not just a prevention plan. The businesses that recover fastest from any fraud attempt are the ones who already know exactly who to call and what to do in the first hour.
Why this connects to more than just “awareness”
Training your team to pause and verify is essential, but it’s only one layer. If a device is compromised — a laptop, a phone, a tablet used to record or store that leadership audio and video in the first place — the raw material for a convincing deepfake can be sitting there for the taking.
That’s where our Computer Security and Mobile Device Security services come in, with 24×7 monitoring that watches for exactly this kind of compromise on the devices your business actually uses day to day, rather than hoping nothing slips through. It’s also why Backup and Recovery matters more than people expect in a fraud conversation — if a deepfake-driven scam does succeed, or a device is compromised as part of one, having clean, fast recovery of your data and systems is what turns a bad day into a manageable one, rather than weeks of downtime.
And because no policy survives contact with a genuinely convincing fake voice on the phone unless it’s been thought through in advance, our Support and Consultancy service exists to help you build that verification process properly — the governance, the “who do we call,” the practical playbook — before you ever need it, not after.
This is the National Cyber Security Centre’s approach in practice: no single control is expected to catch everything on its own. Secure devices, reliable recovery, and sound processes all work together, so one gap doesn’t become the whole story.
The bigger picture
We’re on a mission to protect 1,000,000 businesses from cybercrime — a milestone we’re currently around a third of the way through, having already educated and protected 1,000,000 people by October 2025. Deepfake fraud is a reminder that this mission isn’t really about any one technology. It’s about businesses having the right layers in place before criminals find the gap.
Curious how exposed your business is to this kind of attack? Our free Cyber Security Health Quiz takes a few minutes and gives you an honest picture. And if this is a topic you’d like Francis to bring to your event, panel, or team — get in touch. It’s become one of the fastest-growing talks in the current lineup.
Francis West is CEO of Security Everywhere and Westtek Solutions, and has delivered 500+ talks on cyber security since COVID, sat on 7 security panels including for the Home Office, and holds 181+ LinkedIn recommendations from clients and peers.
