Which of the following is an EASY-to-implement first step for a small business owner to protect against AI voice clone CEO fraud targeting their accounts-payable clerk?
- A.Establish a written policy that all wire transfers and payment instruction changes require a callback to the vendor or executive on a pre-registered phone number, regardless of how the request arrived
- B.Install enterprise-grade deepfake detection software on all employee workstations
- C.Require employees to attend a full-day AI security certification course before handling payments
- D.Switch all vendor communications to encrypted email so AI voice cloning cannot intercept messages
Why A is correct
A callback verification policy is free to implement, requires no technology investment, and directly defeats AI voice clone fraud by creating an out-of-band verification step. It matches what major banks and payment processors recommend for business customers. Enterprise deepfake detection software is expensive and primarily addresses video, not voice calls. A full-day certification course is a long-term investment, not an immediate control. Encrypted email protects email in transit but does not address phone-based voice clone attacks at all.
Know someone studying for AI Security Fundamentals? Send them this one.