A familiar voice can no longer prove who is speaking, according to Adam Boynton, enterprise strategy manager at Jamf. He says organizations must prepare for voice cloning and AI-driven social engineering.
A few seconds of audio from a conference recording or results presentation can be enough to create a convincing voice clone. The technology is accessible even to attackers with limited resources. A cloned voice could persuade an employee to approve a payment or help a caller gain access to an account.
Boynton recommends using a separate verification channel for anything involving money transfers or access approval. He also warns that organizations often review the AI tools they buy while missing AI functions built into ordinary apps, including through development packages that IT has not approved.
AI agents may act as users and inherit their permissions. Encrypted traffic, local functions and mobile devices can also be difficult to monitor. Blocking AI use may push it to private devices and accounts. Boynton instead calls for clear rules, controls on the devices where AI is used, and records showing what was allowed.
He will discuss voice cloning, AI-driven social engineering and changing security work at Connect26: AI i kundmötet on December 2.
Comments
0No comments yet. Be the first to comment.