Cloning a convincing voice now requires a short sample, which your executives have posted publicly in podcasts, conference talks, and webinar recordings. The defense has not changed and it is not technical.
If you verify through a channel the requester provided, you have verified nothing. Everything below is implementation detail.
| Trigger | Action | Who verifies |
|---|---|---|
| Any payment over $ | Callback to number on file | |
| Any change to banking details, at any amount | Callback to the previous number on file, logged | |
| Any first payment to a new vendor | Callback plus verification of vendor identity | |
| Any urgent request from an executive | Callback plus code phrase | |
| Any request received while the approver is traveling | Callback, no exceptions |
Banking detail changes are the highest-frequency version of this fraud and the amount is irrelevant. Even if the email is genuinely from your vendor's compromised mailbox, the instruction is not.
The person who initiates a payment is not the person who releases it. For a very small company this can be the bookkeeper and the owner. It cannot be one person holding the whole path.
Initiator: Releaser: Backup releaser:
Treat live video as weak evidence rather than proof, particularly on a short call with poor quality. The attacker has your executive's face and voice. They do not have a phrase that was never spoken online.
Current phrase held by: Set in person on: Rotates every:
This is the artifact the whole control depends on, and most companies do not have it. Established at onboarding, updated only in person or by callback to the previous number.
| Vendor | Authorized contact | Verified phone number | Date verified |
|---|---|---|---|
Speed matters more than anything else. The window is measured in hours and days, not weeks.