Rupert Marais has spent years at the intersection of network management and identity security, witnessing firsthand how the front lines of cyber defense have shifted from the firewall to the phone line. As a specialist in endpoint security and cybersecurity strategies, he has observed the evolution of social engineering from clumsy phishing emails to the high-fidelity AI voice clones that now haunt corporate service desks. His expertise lies in recognizing that while human intuition is valuable, it has become a dangerous vulnerability in an era where “seeing is believing” and “hearing is trusting” no longer apply. In this conversation, we explore why the traditional help desk model is failing and how organizations must adapt to a world where identity is manufactured by algorithms.
The threat of AI-generated voices has moved from theoretical to a daily reality for many organizations. When a service desk agent receives a call that sounds exactly like a senior executive or a frantic colleague, what are the physiological and psychological pressures they face that make traditional training ineffective?
The pressure on a service desk agent is immense because they are caught between two conflicting mandates: security and service speed. When an agent hears a voice that sounds identical to a person they might have interacted with dozens of times, their brain naturally defaults to a “trust” response. The FBI has already raised the alarm about these malicious campaigns, noting that AI-cloned voices can be nearly indistinguishable from the real speaker. For an agent, the physiological response to a “distressed” executive or a “frustrated” colleague is to bypass hurdles and provide a solution as quickly as possible. We are essentially asking these agents to act as human deepfake detectors, which is an impossible task when an attacker can reproduce tone, speech patterns, and confidence with terrifying accuracy. Relying on an agent’s “gut feeling” in 2026 is no longer a security strategy; it is a gamble that the attacker’s software will glitch.
We have seen groups like Scattered Spider successfully target massive organizations like MGM Resorts and Marks & Spencer by simply picking up the phone. Looking at those specific incidents, how did they exploit the “recovery path” to undermine millions of dollars in cybersecurity investments?
Those breaches were a wake-up call because they proved that your most expensive, phishing-resistant credentials can be rendered useless by a single conversation. Groups like Scattered Spider didn’t need to crack 256-bit encryption; they just needed to sound plausible enough to trick an agent into resetting a password or transferring multi-factor authentication to a device they controlled. By impersonating employees and creating a sense of manufactured urgency, they were able to escalate their access and eventually deploy ransomware that caused widespread, multi-million dollar disruption. It reveals a fundamental flaw in many security architectures: companies spend a fortune on the front door but leave the “recovery” window wide open. If your process for regaining access is easier to defeat than the login process itself, the entire security perimeter is an illusion.
NIST guidelines now treat account recovery as a distinct identity security process rather than just another routine login. Why is this distinction so critical for the way we structure our service desks today?
This distinction is vital because a recovery event is inherently higher risk than a standard login. When someone asks for a password reset or an MFA bypass, they are asking to change the very foundation of how the organization recognizes them. NIST recognizes that if you treat this as a routine task, you lose sight of the fact that you are fundamentally re-establishing a trust relationship. At the service desk, the question shouldn’t be whether the agent followed a polite script, but whether the process provided enough assurance that the caller is who they claim to be. We have to move away from the idea that a service desk interaction is a “customer service” event and start treating it as a “security verification” event. If the recovery process doesn’t provide the same level of assurance as the original authentication, then the security of the entire account is compromised the moment a user forgets their password.
How does a technical solution like Specops Secure Service Desk practically remove the “judgment call” from an agent’s hands while still maintaining a smooth experience for the employee?
The goal is to make verification a mandatory prerequisite rather than a recommendation. With a tool like Specops Secure Service Desk, the agent literally cannot proceed with high-risk actions—like unlocking an account or resetting a password—until the user has successfully verified their identity through a secure channel. We provide agents with more than 15 MFA factors to choose from, ensuring that every user, whether they have their work phone on them or not, can be authenticated through a secondary method. This removes the “human” element of the decision; the agent doesn’t have to wonder if the voice sounds “off” or if the caller knows enough personal trivia to be genuine. It also builds a rock-solid audit trail by exporting events to a SIEM or analytics platform, so the organization has proof that verification occurred before the sensitive action was taken. It turns the agent back into a facilitator of the process rather than a detective trying to spot a deepfake.
What is your forecast for the evolution of vishing and social engineering over the next few years as AI continues to mature?
I believe we are entering an era of “hyper-personalized” social engineering where attackers will use large language models to ingest an employee’s public speaking style, social media presence, and corporate history to create an avatar that is more “real” than the person themselves. We will see attacks that combine cloned voices with real-time video deepfakes, making it impossible for a human to distinguish truth from fiction in a live call. Because of this, my forecast is that any organization still relying on “human judgment” for identity verification at the service desk will experience a breach within the next 24 months. The only path forward is to completely decouple the verification process from the human conversation, moving toward a “Zero Trust” model for the help desk where every single request is cryptographically or multi-factorially proven before a single click is made by the agent.
