Home Services About Blog Contact 📞 1-800-890-6133

The Callback No Longer Proves Anything

By Brian Shad  ·  Pro Link Systems  ·  August 15, 2026

A vendor you have paid for six years sends updated remittance details. New bank, correct letterhead, an invoice number that matches your ledger. Your accounts payable lead follows the policy exactly: no reply to the email, no number taken from the letter. They pull the contact from your own records, dial the line they have used for years, and reach the controller they have spoken with a dozen times. Same voice. Same slight impatience. He confirms the change, the payment releases, and the money is gone.

That is a constructed scenario, not an incident report. It is built to make one point. The control did not fail because someone was careless. It failed while being executed correctly.

The thing that broke was independence, not authenticity

Verification never depended on any single check being unforgeable. It depended on the checks being independent — on an attacker needing to compromise two unrelated things at the same moment. Email could be spoofed, so you confirmed by phone. Phone numbers could be spoofed, so you dialed one you already held. Individually the controls were mediocre. In combination they worked, because holding all of them at once was expensive.

Synthetic audio removed that expense. This is analysis rather than a measured claim, but the logic is hard to argue with: an intruder reading a compromised mailbox already knows the invoice numbers, the tone of the relationship, the names on both sides, and the timing of the payment cycle. Producing a convincing voice to match that mailbox now requires a sample many executives have published themselves — a conference panel, a webinar recording, a podcast appearance, an outgoing voicemail greeting.

Your two independent factors were never really two. They were one intruder appearing twice. The callback did not fail because technology got better at lying. It failed because the second factor stopped being separate from the first.

Why "train them to hear the fake" is the wrong line item

The reflexive response is awareness training: teach the finance team to listen for flat affect, odd pauses, breathing that does not match the sentence. Some of that had value when synthetic speech was cruder. Treating it as a control today is, in my view, a category error.

Consider what the ask actually is. You are requiring someone in the payment chain to perform real-time forensic audio analysis, over a compressed phone line, while a senior-sounding person applies time pressure. Then you make that judgment the last thing standing between your company and a wire. If the call goes wrong, the loss is the company's and the blame lands on the least empowered participant. That is not a control. It is a liability transfer.

There is a second problem, and this one is a prediction rather than a fact. The artifacts people are trained to notice are precisely the defects that model developers are working to eliminate. Any control whose effectiveness declines each quarter according to somebody else's product roadmap does not belong on your risk register as a mitigation. Train your people, certainly — but train them on process authority rather than audio perception. The most valuable thing a finance employee can learn this year is that no voice, however familiar, has standing to change a payment instruction.

Authenticate the channel, not the speaker

The reframe worth taking to your controller this quarter is simple to state. Stop trying to authenticate the human on the line. Authenticate the channel the approval arrives through, and choose a channel an outsider cannot occupy even with a perfect impersonation.

Practically, that means moving payment approvals out of voice and email and into a system where identity is proven cryptographically rather than acoustically. Much of that machinery already sits in the identity layer of Microsoft 365, though the specific policy capabilities depend on your licensing tier — worth confirming what your plan actually includes before assuming it is switched on. An approval that must be issued from an enrolled, compliant device, by an account that authenticated with a passkey or another phishing-resistant method, under a Conditional Access policy, is an approval a cloned voice cannot produce. The attacker can imitate your CFO flawlessly and still be unable to hold his credential, his registered device, and his session at the same time.

This is the same shift that reshaped the rest of cybersecurity over the past several years. Identity became the perimeter because everything softer than identity stopped being dependable. Finance workflow is one of the last places the older assumptions survived, protected by the comfortable belief that you know what your colleagues sound like.

Voice keeps one honest use: a pre-shared verification phrase, agreed in person or through an authenticated channel, rotated on a schedule, and never spoken on an inbound call the other party initiated. It works because the secret is independent of the voice. Notice the pattern — independence is doing the work, not the audio.

Five rules a finance team can run without a project plan

A short set of written rules will outperform a large training budget. These are recommendations, not regulatory requirements.

The decision only the executive team can make

None of this is a technology purchase. It is a decision about authority: specifically, a decision that senior people surrender the ability to move money by sounding like themselves. Executives who bypass the process are the vulnerability, because every exception they demand becomes the script an attacker reuses. When the chief executive can override a control with a phone call, the control does not exist. It merely has good manners.

Pro Link Systems has served Los Angeles businesses since 1999 from Woodland Hills, and my judgment is that the version of this that holds is the one where the CFO writes the rule and is visibly the first person bound by it. Configuration follows that. Conditional Access policies, approval workflows, and an in-house, US-based help desk available 24/7 when something looks wrong are all solvable problems. The governance decision is not.

If you want the technical side built to match a policy like this, our managed IT services team can work through it with your finance and IT leads in the same room.

Ready to talk to a real IT engineer?

Pro Link Systems has been protecting and managing IT for Los Angeles businesses since 1999. Book a free 15-minute discovery call — no pressure, no obligation, no scripts.