The Numbers, Stated Once
Cyber security writing has a habit of leading with alarm and never getting to anything actionable. So here are the published figures once, and then we move to what can be done about them.
84,700+
Cybercrime reports in a year β about one every six minutes
$80,850
Average cost per incident, up 50%
1,200+
Incidents responded to, up 11%
$56,600
Average cost for a small business, up 14%
| Organisation size | Average cost per incident | Change |
|---|---|---|
| Small business | $56,600 | Up 14% |
| Medium business | $97,000 | Up 55% |
| Large organisations (200+ staff) | $202,700 | Up 219% |
The assessment accompanying those figures is the part worth sitting with: AI almost certainly enables malicious actors to execute attacks on a larger scale and at a faster rate. AI-generated phishing, cloned voices and cloned websites have made a category of fraud that used to require genuine skill into something that requires a subscription.
Notice which line grew fastest and what that implies. The 219% increase sits with large organisations β the ones with security teams, budgets and controls. That is not a story about small businesses being careless. It is a story about attack quality improving faster than defences, at every size. The correct inference for a smaller business is not that it is safe by obscurity; it is that the attacks reaching it are now the same quality as the ones reaching organisations with a security function.
Why the Phone Layer Is the Gap
Most businesses have spent a decade hardening email. Filters, banners on external senders, link rewriting, staff training, multi-factor authentication. That work was correct and it worked well enough that attackers moved.
They moved to voice, and voice is where three things are simultaneously true.
It is where authorisation happens
Payment details get changed on calls. Account access gets granted on calls. Urgency gets manufactured on calls. The decisions with money attached are disproportionately verbal.
It is the least monitored channel
Email is logged, searchable and inspected. Calls, in most businesses, are a sample of recordings nobody listens to and a set of notes somebody may have written. There is no filter on a phone call.
It defeats trained scepticism
Staff have been taught to distrust an unexpected email. They have not been taught to distrust a voice, because until recently a voice was a reasonable identity proof. That training gap is the whole opportunity.
So the argument of this article is narrow and specific: the highest-value AI security deployment for most Australian businesses is not a new security product. It is switching on capability that already exists in the communications platform, because that is the channel with the largest gap between how much risk it carries and how much attention it gets.
1. Caller Verification That Actually Verifies
The current state of caller verification in most businesses is a person asking for a name and a date of birth, listening to an answer, and deciding. That process fails against a caller who has done fifteen minutes of research, which is now every caller who matters.
| What AI adds | How it helps |
|---|---|
| Consistent challenge sequences | The same verification steps every time, in the same order, regardless of how busy, tired or sympathetic the person answering is. Social engineering works on inconsistency. |
| Cross-checking against the record | What the caller says, checked against what the system holds, while the call is still happening rather than afterwards. |
| Flagging mismatches for a human | Not refusing service β escalating. The AI notices the discrepancy and hands it to a person with the discrepancy already stated. |
| Removing the pressure variable | An automated first stage does not feel embarrassed about asking a third question, does not respond to urgency and cannot be flattered. Those three human traits are what the attacker is actually targeting. |
The important limit, stated up front
This is not voice biometrics and we are not proposing that a voice should be an identity proof. The whole premise of the current threat is that a voice can be synthesised. What AI adds here is process consistency and cross-checking, not a magic identification of the human speaking. Any vendor selling you voice-as-password in 2026 is selling you the exact thing that just stopped working.
2. Transcripts as Evidence
The least glamorous item on this list and quite possibly the highest value. An accurate transcript of every call, searchable, timestamped and retained, changes what is provable.
Searchable across everything
When you learn on Thursday that a fraud attempt is circulating, you can ask whether anyone in the business took a call matching it β this month, or last quarter. Without transcripts that question has no answer.
Provable authorisation
Who approved the change, in what words, at what time. Disputes about verbal authorisation currently resolve on whoever is more confident. With a transcript they resolve on the record.
Faster incident response
Reconstructing an incident is where most of the response time goes. A searchable call history collapses days of interviews into an afternoon of queries.
And a real obligation attached
Transcripts are personal information. They need a retention period, an access rule and a purpose, decided before you turn them on rather than after. This is a genuine cost of the capability, not a footnote.
3. Toll Fraud and Traffic Anomalies
This is the oldest AI-adjacent security function in telephony and it remains among the most valuable, because the losses are immediate and denominated in real money.
Toll fraud is the compromise of a phone system to place calls someone else pays for β historically to international premium destinations, at volume, usually overnight or across a long weekend. The economics are brutal: by the time a human notices on Tuesday morning, the bill exists.
| Signal | Why a pattern engine catches it and a person does not |
|---|---|
| Calls to destinations you have never called | A business's calling geography is remarkably stable. A first-ever call to an unusual international destination at 2am is a strong signal, and nobody is awake to see it. |
| Volume outside business hours | Not zero β plenty of businesses operate at night β but a departure from that business's own established pattern rather than a generic rule. |
| Concurrent call counts that make no sense | Forty simultaneous calls from an eight-person business is not a busy period. It is a compromise, and it is arithmetically obvious the moment anything is watching. |
| Registration anomalies | An extension registering from an unexpected network or geography. Frequently the earliest signal available, and entirely invisible without monitoring. |
Why this one belongs to the platform
Toll fraud detection only works where somebody sees the traffic in real time and can act on it. A business running its own system detects it on the invoice. A provider who operates the network and the platform sees the pattern as it forms and can stop it mid-event β which is the difference between a conversation about a $40,000 bill and a phone call at 3am telling you something was blocked. This is also why it is worth asking a prospective provider directly what their limits are, what triggers a block, and whether anybody is on the other end of the alert.
4. Patterns Across a History, Not a Call
Here is the capability that is genuinely new, as opposed to older automation being relabelled as AI.
Sophisticated social engineering is rarely a single call. It is a sequence: a harmless call to confirm the receptionist's name, another to learn who approves invoices, a third that mentions the two facts already gathered to establish credibility, and a fourth that asks for the thing. No individual call in that chain looks wrong. Any human reviewing any one of them would find nothing.
The attack is only visible in aggregate, which is precisely the shape of problem pattern recognition across a corpus is good at β and precisely the shape of problem that human review of individual calls cannot address, no matter how diligent the humans are. A person who reviews a sample of calls is looking for a bad call. The threat is a sequence of unremarkable ones.
What this looks like in practice is unglamorous: repeated calls from a number that never books anything, a caller who asks about internal process rather than about your product, requests that consistently arrive just before close of business, and the same voice appearing across departments. Each is nothing. Together they are a profile worth flagging to a human.
5. Synthetic Voice and the Vishing Problem
We have written at length elsewhere about voice cloning and will not repeat it. The relevant point here is narrower, and it is about what AI can and cannot contribute to the defence.
| Defence | Effectiveness |
|---|---|
| Detecting synthetic audio automatically | Improving, unreliable. Treat any vendor claim here with heavy scepticism. Generation is currently outrunning detection and betting a control on it is unwise. |
| Enforcing a callback rule | Highly effective. Any request to change payment details or move money gets verified by calling back on a known number. AI enforces the rule consistently, which is where humans fail. |
| Flagging the request type regardless of the voice | Effective. Do not try to detect the fake. Detect the ask. A request to change bank details is high-risk whoever appears to be making it. |
| Training staff with real examples | Effective. Recordings and transcripts of actual attempts on your business beat a generic awareness module by a wide margin. |
The strategic point: stop trying to authenticate the voice and start authenticating the request. Voice as an identity proof is over, and no amount of technology restores it. What survives is process β out-of-band verification for a defined list of high-risk actions, applied without exception. AI's contribution is that it applies the rule the same way at 4:55pm on a Friday as it does on a Tuesday morning, and that is not a small thing, because 4:55pm on a Friday is when the request arrives.
6. Killing the Shadow Channels
An indirect security benefit that nobody puts in this category, and it may be the largest one on the list.
When a business cannot answer its phone reliably, staff invent workarounds. Personal mobile numbers given to good customers. A WhatsApp group with a supplier. A personal email address used because the shared inbox is unmanageable. Each is a reasonable individual response to an operational failure, and collectively they are a security disaster: business communication happening on channels the business does not control, cannot log, cannot search and cannot revoke when somebody leaves.
Calls answered means calls stay on the system
AI answering after hours and at peak means nobody needs a workaround. The traffic stays where it can be logged and governed.
Offboarding actually works
When a staff member leaves, revoking a platform account removes their access. It does not remove a customer's habit of texting their personal mobile, and no policy fixes that after the fact.
One record instead of six
Voice, SMS and messaging in one history means the interaction record is complete. Six channels means the record is a guess, and a guess is not evidence.
7. Reviewing Every Call Instead of Two Per Cent
Traditional call quality review covers a sample β commonly a couple of per cent, chosen by whoever had time. As a security control, a two per cent sample is close to useless: it will find a systemic problem eventually and will essentially never find a targeted one.
Automated review changes the coverage from a sample to the population. For security specifically, that matters in three ways.
- Policy breaches surface as a rate, not an anecdote. If verification steps are being skipped, you learn how often and by whom, rather than learning that it happened once in a reviewed call.
- Coaching targets the actual gap. Training built on complete data addresses what people are really doing under pressure, not what a reviewer happened to hear.
- Trend detection becomes possible. A slow drift in how staff handle unusual requests is invisible at two per cent sampling and obvious at a hundred.
Do not let this become surveillance
Reviewing every call is powerful and it changes the relationship with staff if it is introduced badly. Say what is analysed, why, who sees it and what it will and will not be used for β before you switch it on. A control that staff experience as monitoring produces defensive behaviour, and defensive staff are worse at reporting the thing you most need reported. Consultation here is not a compliance formality, it is what makes the control work.
8. An Audit Trail That Writes Itself
Most Australian businesses have some obligation to demonstrate what happened rather than assert it β sector rules, regulatory codes, insurance conditions, contractual undertakings. The traditional method is somebody writing a note, which produces a record that is incomplete, retrospective and written by the person with the most reason to shade it.
| Question you may have to answer | With notes | With platform records and AI summaries |
|---|---|---|
| Did we disclose the required information? | Probably β somebody remembers doing it | Here is the call and the words used |
| When was the customer first told? | Approximately | Timestamped |
| Did we verify identity before acting? | Standard practice | Here is the verification sequence, or here is where it was skipped |
| How did we respond to the complaint? | A file note written afterwards | The whole interaction, in order, across voice and messages |
The uncomfortable half of this is worth saying: an audit trail that writes itself also records the times you got it wrong. Businesses that want evidence only when it helps them should not deploy this. Businesses that would rather know are the ones it serves.
Four Things AI Will Not Do for You
Any article that lists eight benefits and no limits is a brochure. Here are the four categories where AI on the communications layer contributes nothing, and where the money should go instead.
| Threat | What AI on the phone layer does | What actually works |
|---|---|---|
| Compromised credentials | Nothing | Multi-factor authentication, a password manager, conditional access. Do this first, before any of the eight above. |
| Unpatched systems and known vulnerabilities | Nothing | Patching. Unfashionable, unglamorous, and still the highest-return security activity available. |
| A malicious insider with legitimate access | Very little β the activity looks authorised because it is | Least privilege, separation of duties, and dual authorisation on payments. |
| No process to escalate to | Generates alerts nobody acts on | Deciding, in advance and in writing, who is called and what they are empowered to do. An unattended alert is worse than none, because it manufactures false confidence. |
The order of operations matters
If you have not done multi-factor authentication and patching, do not start with AI. Nothing in this article substitutes for either, and a business with sophisticated call analytics and shared passwords has bought the interesting control and skipped the effective one. We would rather tell you that than sell you the wrong thing first.
Governance Before Deployment
Australia has no general AI statute and, as at mid-2026, no mandatory guardrails for private business. What exists is the National AI Plan, an AI Safety Institute, and voluntary guidance whose ten guardrails have been distilled into six practices worth using as a checklist whatever your view of regulation.
| Practice | What it means for a phone-layer deployment |
|---|---|
| Decide accountability | Name the person responsible for the AI in your phone system. If nobody is named, nobody is accountable, and this is the step most often skipped. |
| Understand impacts | Who is affected β customers, staff, callers who never consented to anything. Write it down. |
| Measure and manage risks | What happens when it is wrong? A misrouted call is trivial; a wrongly refused verification is not. |
| Share information | Tell people. Callers, staff, customers. Undisclosed AI is a reputational risk on top of any legal one. |
| Test and monitor | Check it still works. Models change, call patterns change, and a control nobody tests is a control nobody has. |
| Maintain human control | A person can always override, and there is always a path to a human. For security decisions this is not optional. |
Note that from 15 June 2026 the first mandatory AI requirements applied to Commonwealth agencies β impact assessments, procurement guidance, foundational training and chief AI officers. If you sell to government, that is not somebody else's framework; it is arriving in your procurement questionnaires.
The 10 December 2026 Obligation
One date deserves its own section because it is close and it is under-recognised.
Automated decision-making transparency, from 10 December 2026
Amendments to the Privacy Act require entities that use personal information in automated decision-making capable of affecting a person's rights or interests to disclose in their privacy policy the kinds of personal information used and the kinds of decisions made. The drafting is broad and captures rule-based tools and automated assessment technologies as well as AI. The regulator has signalled a wide reading, with final guidance expected around September 2026, and civil penalties for serious breaches run to very large amounts.
Why it lands on phone systems: an AI agent that qualifies leads, prioritises a queue, decides who reaches a human quickly, or scores an interaction is plausibly making decisions affecting rights or interests using personal information. The obligation is a privacy-policy disclosure obligation, which is genuinely manageable β but only if somebody knows the deployment exists. The businesses that get caught will be the ones where the AI was switched on by an operations team and the privacy policy was last touched by a lawyer in 2023.
Two practical steps, neither expensive. Inventory every automated decision your systems currently make, including the ones that predate anyone calling them AI. Then make sure whoever maintains your privacy policy has that inventory before December.
Twelve Questions to Ask Any AI Security Claim
Including ours. If a vendor cannot answer these plainly, that is the answer.
| # | Question | Why it matters |
|---|---|---|
| 1 | Where does the processing physically happen? | Jurisdiction determines who can compel access to your call audio. |
| 2 | Is my call audio or transcript retained, and for how long? | Retention you did not choose is retention you cannot defend. |
| 3 | Is anything used to train a model? | Should be no by default, in writing, not in a blog post. |
| 4 | Who are the subprocessors? | You are inheriting their security posture whether you know it or not. |
| 5 | What happens when the AI is wrong? | There must be a defined failure path, not an assumption of correctness. |
| 6 | Can a human always override? | If no, do not deploy it on a security decision. |
| 7 | What triggers a toll fraud block, and who acts on it? | An alert with nobody behind it is theatre. |
| 8 | Do you claim to detect synthetic voice? | An emphatic yes is a reason for scepticism, not comfort. |
| 9 | What is logged, and can I export it? | Evidence you cannot extract is evidence you do not have. |
| 10 | Who is accountable at 3am? | The most useful question in security procurement, and the least asked. |
| 11 | What does your ADM disclosure look like? | If they have not thought about December 2026, they will not help you with it. |
| 12 | What does this not protect me from? | A vendor who cannot answer this has not thought carefully about their own product. |
The summary
Australian businesses report a cybercrime roughly every six minutes and the average incident costs $80,850, with AI cited as a driver of both the scale and the speed. The same technology helps most on the layer businesses monitor least β voice, where authorisation actually happens. Eight real gaps it closes: verification consistency, transcript evidence, toll fraud detection, patterns across a history, request-based rather than voice-based authentication, eliminating shadow channels, complete rather than sampled review, and a self-writing audit trail. Four it does not touch: stolen credentials, unpatched systems, malicious insiders and the absence of an escalation process. Do multi-factor authentication and patching first. Then name an accountable person, disclose what you are doing, keep a human in control, and get your automated-decision inventory to whoever writes your privacy policy before 10 December 2026.
Related reading: voice cloning and vishing in depth, VoIP security and toll fraud, what a real breach looks like from the outside, the December 2026 automated-decisions obligation in detail, and the Scams Prevention Framework.