By Forrest Knueppel, VP of Sales, White Label Communications
There’s a story making the rounds in security circles that I think about a lot. A finance employee at a large organization joins a video call with what appears to be a room filled with the familiar faces of company executives asking to authorize a series of transfers. The employee complies.
The room was entirely AI-generated. Every person on that call was a deepfake. The company lost $25 million.
That’s not some far-fetched future threat. It happened. And the technology required to pull it off is not out of reach for serious bad actors.
We spend a lot of time in this industry talking about how well AI enables things like better contact center efficiency, more consistent interactions, and real-time insights that used to require manual analysis. But the same capabilities are available to people who intend to use them against your customers. The threat surface has changed, and the security conversation has to change with it.
Social Engineering at Scale
Social engineering remains the most immediate risk in unified communications and contact center environments. And AI has made it both dramatically more scalable and significantly more convincing.
An attacker can deploy an AI-powered agent that navigates IVR systems, answers security questions using scraped or purchased personal data, and adapts its responses in real time to get where it’s trying to go. The consistency and patience of an AI-driven attack is qualitatively different from a human attacker. It doesn’t get nervous and it doesn’t hesitate. It runs the same play thousands of times until something works.
For businesses operating contact centers, this means that the same AI infrastructure used to automate customer service can, in the wrong hands, be used to automate fraud. That’s not a reason to avoid AI. Rather, it’s a reason to think more carefully about identity verification, call authentication, and how your contact center handles requests for sensitive information.
The Convergence Trade-Off
UCaaS and CCaaS are converging. Providers that used to run separate systems for internal communications and customer-facing contact center operations are increasingly building unified platforms. Having one platform to manage, one vendor relationship, and one support path is certainly appealing from an operational standpoint.
But consolidation is a double-edged sword from a security standpoint.
A unified platform means a single point of compromise. If an attacker gains access to that environment, they potentially have access to both internal communications and external customer-facing channels at once. That’s a materially different risk profile than two separate systems with separate authentication and access controls.
The flip side — fortunately — is that a single platform is also easier to secure consistently. One set of controls, one monitoring posture, one place to enforce policy. Managing one platform is actually simpler than managing two. So long as you do it right.
What Your Customers Need to Know Now
Organizations are asking more specific questions during RFPs and security reviews, going beyond general assurances about data protection:
- Where is it stored?
- Is the storage environment certified?
- What controls does the provider enforce on their own internal access?
The regulatory dimension adds urgency depending on the vertical. Healthcare organizations can’t work with a contact center platform that doesn’t account for PHI handling. Financial institutions face PCI requirements around call recording and data retention. For customers in regulated industries, compliance with those standards is a prerequisite for doing business.
What I’d push back on is the assumption that these concerns only matter in regulated verticals. If you’re a contact center provider, you’re in the supply chain. Your security posture is part of your customers’ risk profile whether they’ve formally assessed it or not.
That’s why security measures like multi-factor authentication, role-based access controls, single sign-on, endpoint detection, and audit logging should now be considered baseline. I say “should be” because in practice, a surprising number of providers haven’t gotten there yet.
A Trend Worth Watching
There’s another development accelerating fast with direct implications for how contact centers procure AI. Organizations are increasingly moving toward private, internally managed LLMs, driven by both data security concerns and the need to protect proprietary information, rather than relying on public AI models.
So if your contact center platform is built around a single AI provider and can’t connect to a customer’s internal solution, it gets ruled out. Platforms built with open API architectures that can ingest whatever AI or LLM a customer prefers are in a fundamentally different position.
How You Can Lead the Conversation
Before the platform evaluation starts, the most valuable thing you can do is ask pointed questions about the customer’s security posture:
- What kind of data flows through their communications environment?
- How are they protecting it today?
- What compliance framework are they operating under?
That context shapes everything else — which platforms are viable, what controls need to be in place, and where the gaps are. It’s also a different conversation than the one many of your competitors are having.
For SMBs specifically, the honest answer is that enterprise-grade security has historically been too expensive to implement properly. That’s changing. Managed security offerings that bundle endpoint detection and response, email security, security awareness training, identity management, and outside monitoring are becoming accessible at a price point that works for smaller customers. If you’re focused primarily on the SMB market, being able to have that conversation is increasingly table stakes.
WLC approaches security from the inside out. Compliance, rigorous internal controls, and an open API architecture give you the flexibility to connect the security and AI tools your customers actually need. The goal is to be the kind of platform partner that doesn’t introduce risk into a customer’s environment.
The security conversation used to happen at the end of a deal, as a formality. It’s moving to the front. The resellers who are ready for it will be the ones still in the room.