Businesses Want Cybersecurity to Protect Voice Recordings, per Survey

A recent survey found that 93% of surveyed enterprises wanted voice security included in risk management programs.

When a plan participant calls a support line and states his or her name for authentication, they might not think there is any danger.

However, according to voice security provider Mutare Inc.’s 2026 Voice Threat Survey, voice communication tools are often a preferred pathway from scammers to bypass traditional cybersecurity controls. Criminals regularly use impersonation, a sense of urgency, misplaced trust and human psychology to turn phone calls into an effective means of gathering personal information. Generative artificial intelligence and deepfake technologies are also making impersonation easier.

Want the latest retirement plan adviser news and insights? Sign up for PLANADVISER newsletters.

Asked which voice threats were impacting their business, 53.6% of surveyed organizations cited robocalls, 51.2% said spam calls and 38.9% said voice phishing.

Such instances are drawing companies’ attention toward voice security tools, with 93% of respondents saying they believed voice security should be included in cybersecurity and risk management programs.

Organizations are beginning to understand that awareness training alone is no longer sufficient. A modern cybersecurity strategy must include technical controls that reduce opportunities for malicious callers to ever reach employees, executives, help desks or contact center agents,” said Brian McDonald, Mutare’s chief security officer, in a statement.

The increased focus on voice security comes in part because more retirement industry firms have adopted voice recognition and voice biometric technologies to authenticate participants and customers.

Companies such as TIAA, Transamerica, Fidelity, Schwab and Empower Retirement use voice-based tools to verify identities, reduce reliance on passwords and security questions, and detect potential fraud.

For example, TIAA customers can create a “voiceprint” to securely identify themselves when they call to speak to a representative, transfer funds or check their account balances.

A TIAA spokesperson said that protecting the voice interactions of its customers is integrated into the firms broader cybersecurity strategy.

“Since introducing voice biometrics in 2016, we have continued to evolve our voice authentication capabilities to stay ahead of emerging threats, including the rise of AI-generated voice attacks and deepfakes,” wrote a spokesperson from TIAA in an email to PLANADVISER. “Our fraud detection strategies combine advanced technology with trained human experts who monitor calls into our national contact center for unusual activity, helping us identify and stop bad actors before they can cause harm.”

Similarly, Transamerica’s Voice Pass, a feature developed with Nuance Communications Inc., lets customers call Transamerica’s customer care service to securely authenticate and access their accounts.

Such firms will have to be cautious of how advances in voice recognition technology are also making it easier for bad actors to mimic voices.

Cybersecurity strategies have evolved dramatically over the past decade, but voice security has largely remained a blind spot, said McDonald. Our survey shows that security leaders and business owners are beginning to recognize voice as a legitimate attack vector that deserves the same strategic attention as email, endpoints, data, identity and cloud security.”

Nearly half (45%) of Mutare’s respondents said they were somewhat concerned about generative AI-based voice attacks and deepfakes, while 22.3% said they were extremely concerned.

Mutares survey respondents came primarily from healthcare (29.4%) and technology and innovation organizations (29.4%), while 7.1% represented financial services firms.

«