From $1,450 per campaign · Remote · Fixed written quote
Practice the call before a criminal makes it.
Authorized security awareness training. With written authorization from your leadership and written consent from the person whose voice is cloned, I call the staff you choose, in that voice, with a plausible story. The script stops before anyone hands anything over. Then everyone gets a debrief.
The problem.
-
Voice phishing grew 442% between the first and second half of 2024, with attackers often posing as IT support.
Source, CrowdStrike 2025 Global Threat Report -
In a study of 529 listeners, people correctly identified deepfake speech 73% of the time, and showing them examples barely helped.
Source, University College London, PLOS ONE, 2023 -
In 2024 a Ferrari executive took a call from a convincing imitation of the CEO's voice. He asked which book the CEO had recommended days earlier. The caller hung up. That is the habit this training builds.
Source, The Drive, July 2024 -
I have run phishing awareness programs for more than 20 organizations and written their monthly risky-user reports. Voice is the channel those programs leave untested.
What I do.
Scope with the sponsor.
On a call with the person who can authorize security testing (CEO, CIO, IT director, city manager, chief of police, compliance officer). We agree who is in scope, which days and hours, which pretexts are allowed, what the caller may never ask for, and which callback procedure the staff will be taught.
Draft the authorization packet.
I draft the leadership authorization letter, the voice-owner consent form, the scope sheet and the employee-notice language for your acceptable-use or security-training policy. Your counsel reviews it. Nothing is scheduled until it is signed.
Collect the voice sample.
A 30-minute session with the consenting leader. I build the clone with a commercial voice-synthesis service under the terms of the consent, test it with the leader present, and store the sample and model only for the engagement.
Write the scripts.
Two or three pretexts drawn from documented cases, such as the locked-out executive who needs a code read back, the vendor who needs a payment change confirmed, and the IT support caller who needs an MFA reset. In the 2023 Retool incident, an attacker used a cloned voice of a real IT employee to obtain an MFA code. Source, Retool engineering blog Every script has a hard stop line written into it.
Run the calls.
From a number your IT lead knows, during the agreed hours, with me on the line. The call stops at the script stop. I disclose immediately, coach for two or three minutes, and remind the person of the callback procedure.
Debrief and train.
An executive debrief and a 45-minute staff session, both over video, an aggregate report and a one-page callback and verification procedure your organization can adopt the same week.
What you get.
- The authorization packet (authorization letter, voice-owner consent, scope sheet, policy language), drafted by me and signed before any call.
- A scoped campaign of calls in the agreed hours, each ending in disclosure and coaching.
- An aggregate report covering which pretexts worked, who verified and how, and the process fixes to make.
- An executive debrief and one 45-minute staff training session.
- A written callback and verification procedure for your help desk, finance team and front office.
- Written confirmation that the voice sample, the cloned model and my call notes were deleted within 30 days of the final report.
What the calls sound like.
Two illustrative scripts from an authorized training exercise, written the way I write them. Names are invented. Both stop before anyone reads a code.
Sample script · Names invented · Authorized training exercise
- Caller (cloned voice, consented)
- Hey, it's Dan. I'm on the way to the board meeting and my phone is about to die. I need you to read me the code that just came through on the Microsoft app so I can get into the deck.
- Employee
- Hi Dan. I can help with that. I'm going to hang up and call you back on your office line, same as always.
- Caller
- I won't be at my desk. I'm driving.
- Employee
- Then I'll call your cell on the number I have saved. Give me thirty seconds.
- Stop
- Script end. The employee verified by callback. Disclosure and coaching followed, about three minutes.
- Facilitator (my own voice)
- This was an authorized training call from Shively Systems. That was the right answer. Here is what to look for next time.
Sample script B · Names invented · What happens when someone slips
- Caller (cloned voice, consented)
- Hey Dana, it's Mark. I'm walking into the board meeting and I'm locked out. IT said you can read me the code that just hit your phone so they can push the reset through.
- Employee
- Oh, hi Mark. Sure, hang on.
- Stop
- Script end. No code is requested again and nothing is written down.
- Facilitator (my own voice)
- Dana, this is Brock Shively. That was an authorized training call. Mark agreed in writing to have his voice cloned for it. No code was read and nothing was collected. Next time, hang up, call Mark on the number in the directory, and tell IT that a caller asked for a code. Today's results are used only for training.
How long it takes.
- Scoping meeting
- 60 to 90 minutes. Packet drafted within 2 business days.
- Leadership and counsel review
- Signatures and the policy notice. Typically 1 to 2 weeks, set by your side.
- Voice sample session
- 30 minutes. Clone built and tested the same day. Pretexts approved by the sponsor within a week.
- Calls
- Run over 5 to 10 business days in the agreed hours.
- Debrief, staff session and report
- Within one week after the last call.
- Deletion
- Confirmed in writing within 30 days of the report.
- Typical total
- 4 to 6 weeks from the first meeting.
Pricing.
The rules come first. Prices follow.
Rules of engagement for voice-clone training
- Leadership signs a written authorization before any call is scheduled.
- The person whose voice is cloned signs a separate consent. Only that voice is used, and the clone is deleted at the end.
- Scope is agreed in advance. Who may be called, on which days and hours, and which pretexts are allowed.
- Calls are not recorded. No passwords, codes, account numbers or protected data are requested, collected or kept. The script stops before anyone hands something over.
- Every call ends with disclosure and a short coaching conversation.
- Results go to the sponsor in aggregate and are used for training only, never for discipline.
Read the full rules of engagement
Before any call
- Written authorization from someone with authority to approve security testing, naming the engagement, the dates, the phone numbers and departments in scope, the allowed pretexts, and the people who will be told in advance.
- Separate written consent from the person whose voice is cloned. It states how the sample is collected, what it is used for, that the clone is deleted at the end, and that consent can be withdrawn at any time. Only that person's voice is cloned.
- Confirmation that the numbers to be called are company-owned, or that employees have agreed in policy to receive simulated calls. The FCC has ruled that AI-generated voices are artificial voices under the TCPA, so calls to personal cell phones need prior express consent.
- Calls happen during business hours and are limited in number, so they do not disrupt operations.
- Scripts stop before anyone discloses anything. No passwords, MFA codes, account numbers, patient data, personnel records or other protected information are requested, collected or stored. If someone offers them, the caller declines.
- Calls are not recorded. I keep written notes limited to the pretext used, whether the person verified, and the coaching given. If your policy obtains all-party consent and you want recordings, that is set in the packet and confirmed with your counsel.
- Every call ends with an immediate disclosure that it was an authorized training exercise, a short coaching conversation and a reminder of your callback procedure.
- Results go to the sponsor in aggregate and are used for training and process improvement only. The engagement agreement states that results will not be used for discipline. Individual names are shared only with the sponsor, and only to arrange follow-up coaching.
- Voice samples, the cloned model and my notes are deleted within 30 days of the final report, and the deletion is confirmed in writing.
- None of this is legal advice. Your organization confirms the approach against its own state law, employment policies and bargaining agreements.
FCC ruling as summarized by HWG LLP, 8 February 2024. Source
-
Starter
One consented voice, up to 10 people, one pretext, coaching on every call, a one-page report and a written callback procedure.
$1,450 per campaign -
Team
One consented voice, up to 30 people, two pretexts, an executive debrief, one 45-minute staff session over video, report and callback procedure.
$2,900 per campaign -
Organization
Up to 100 people or multiple sites, two consented voices, three pretexts, a voice-plus-email scenario, help-desk MFA-reset scenarios, board-ready report.
from $5,900 quoted -
Re-test and quarterly program
Re-test within 12 months at 50% of the original price. Quarterly program from $6,000 per year.
-
Included
Packet drafting, clone build, calls, disclosure and coaching, report, debrief, staff session, deletion confirmation.
-
Extra
An on-site debrief or staff session by arrangement, with travel at cost. Additional voices or pretexts, quoted. Recordings where your policy allows them, quoted. Follow-on policy and help-desk work through the fractional engineer retainer.
Every quote is fixed in writing before work begins.
Questions.
Is this legal?
It is authorized, consent-based training. Leadership authorizes it in writing, the person whose voice is used consents in writing, and employees are notified through policy. The FCC has ruled that AI-generated voices count as artificial voices under the TCPA, which is why the packet includes employee-notice language and why the numbers called are company-owned or covered by consent. This is a description of how I work, and it is not legal advice. Your counsel confirms the approach.
Will my employees be embarrassed or disciplined?
No. Results are reported in aggregate. Names are shared only with the sponsor, and only to arrange coaching. The engagement agreement states that results are never used for discipline. Every call ends with a short, private coaching conversation.
Do you record the calls?
No. I keep written notes limited to the pretext used, whether the person verified and the coaching given. If your policy obtains all-party consent and you want recordings for training, that is set in the packet and confirmed with your counsel.
Does this satisfy our HIPAA or CJIS awareness-training requirement?
It supports awareness-training requirements and produces documentation you can file. Whether it satisfies a specific requirement is a decision for your compliance officer. I do not claim compliance on your behalf.
The first step is a document. Request the packet, route it to leadership and counsel, and I schedule the calls once it is signed.
After the exercise, the findings need an owner. The fractional senior engineer retainer is where that usually goes.