Join our Newsletter — 33% off our NHI Course
Home FAQ Threats, Abuse & Incident Response What breaks when organisations rely on video presence…
Threats, Abuse & Incident Response

What breaks when organisations rely on video presence alone to trust callers?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated August 28, 2026 Domain: Threats, Abuse & Incident Response

Video presence alone can fail when attackers use AI-generated faces, cloned voices, or recruited intermediaries to sit in for the real person. That creates exposure in payments, recruitment, customer support, and board communications. The control gap is not the meeting tool itself, but the lack of verified identity before access to the conversation.

Why This Matters for Security Teams

Video presence is often treated as proof of legitimacy, but that assumption breaks as soon as an attacker can simulate a face, clone a voice, or place a recruited intermediary in the call. The real risk is not the meeting platform itself. It is the decision to grant trust, money movement, or internal access before identity has been verified through stronger signals, as reflected in the NIST Cybersecurity Framework 2.0.

This matters because modern fraud rarely looks like a broken login page. It looks like a convincing executive, a rushed recruiter, or a support request that arrives with the right background, tone, and urgency. NHI Mgmt Group research shows how quickly trust collapses once weak identity evidence is paired with real operational access, especially in incidents tied to token exposure and credential leakage such as JetBrains GitHub plugin token exposure and Code Formatting Tools Credential Leaks. In practice, many security teams discover the weakness only after a payment approval, hiring step, or privileged conversation has already been abused.

How It Works in Practice

Trusting a caller based on video alone is a form of identity shortcut. The organisation sees a face, hears a voice, and assumes the person on screen is the authorised human. That model fails because the evidence is easy to spoof, and because the meeting layer is usually disconnected from the identity layer. Security teams should instead treat the call as a channel, not as proof.

Current guidance suggests layering verification before, during, and after the conversation. Before the call, the person should authenticate through a trusted identity process, not just a meeting link. During the call, the team should verify contextual signals such as request history, approval path, and whether the task matches the person’s known role. After the call, high-risk actions should require separate approval and audit logging. Where possible, use phishing-resistant authentication, out-of-band confirmation, and policy checks aligned with NIST CSF 2.0 and identity assurance practices.

  • Require verified identity before any payment, hire, password reset, or records disclosure.
  • Use a second channel for confirmation when the request is urgent or unusual.
  • Bind approvals to role, context, and transaction type, not to appearance on video.
  • Log the verification path so security teams can review how trust was established.

For organisations handling sensitive credentials, the lesson is consistent with NHIMG research on exposed tokens and hard-coded secrets: once an attacker gains a believable front door, the downstream damage comes from what they can access next, not from the call itself. These controls tend to break down in high-pressure environments such as finance close cycles, recruiting rushes, and executive support desks because urgency overrides the separate verification step.

Common Variations and Edge Cases

Tighter verification often increases friction, so organisations must balance fraud resistance against speed, executive convenience, and customer experience. That tradeoff is real, especially for sales, support, and hiring workflows where delayed approval can feel like a business loss.

There is no universal standard for this yet, but best practice is evolving toward risk-based verification. Low-risk internal check-ins may tolerate basic meeting access, while wire transfers, HR changes, sensitive disclosures, and admin actions should require stronger proof. In some environments, video may still be useful as one signal among many, but it should never be the sole trust anchor.

Edge cases include multilingual calls, accessibility accommodations, and third-party participation, where identity checks must avoid excluding legitimate users. Another common gap is deepfake detection. Security teams should not rely on detection tooling alone, because it is an arms race and cannot replace process control. The safer approach is to make the caller prove identity before the conversation becomes operationally meaningful.

As NHIMG analysis of credential exposure incidents shows, the most damaging failures happen when a convincing interaction is treated as sufficient evidence. In practice, organisations usually learn that video is not identity after an impostor has already used the conversation to bypass approvals, not before.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Agentic AI Top 10, CSA MAESTRO and OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0 and NIST AI RMF set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AAIdentity proofing and access decisions must not rely on video alone.
NIST AI RMFRisk-based governance helps separate appearance from trustworthy identity evidence.
OWASP Agentic AI Top 10LLM-04Trusting synthetic or manipulated interaction cues mirrors agentic impersonation risk.
CSA MAESTROIG2Shared governance is needed where social engineering meets identity and workflow abuse.
OWASP Non-Human Identity Top 10NHI-01Weak trust in caller identity parallels poor validation of non-human identities.

Classify video-mediated interactions by risk and require stronger controls for sensitive actions.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on August 28, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org