For thirty years, security budgets have followed the threat as it moved: onto the network, then the endpoint, then the cloud. The one place that spending kept working around is the place attackers now go first, which is a person on a phone. That gap is the subject of our new Substack, The Identity Perimeter. You can read it and subscribe for free at trusona.substack.com.
The exposure sits where high privilege meets a helpful person: the help desk that resets access, the call center that moves money, the onboarding flow that hands a new vendor its first credentials. That layer is the identity perimeter, and most organizations still defend it with training and instinct instead of technology.
The breaches in the headlines make the case. When Scattered Spider hit MGM Resorts and Caesars Entertainment in 2023, neither intrusion started with a zero-day or a stolen password. Someone called the IT help desk, posed as an employee, and asked for help getting back into an account. The same play reached Marks and Spencer through an outsourced help desk in 2025. And at the engineering firm Arup, a finance worker joined a video call with what looked and sounded like the company’s chief financial officer, then authorized roughly $25 million in transfers. Every face on that call was synthetic.
The first post, “Why the New Security Boundary Is a Phone Call,” comes from our founder and CEO, Ori Eisen. He explains why the perimeter moved here, and why you cannot train a support agent to be a human lie detector against a professional impersonation in the middle of an ordinary shift.
He also makes the case for the shift Trusona was built around. Most identity checks on this perimeter verify the channel instead of the person. The caller knows the employee ID, but knowledge can be researched. The voice sounds right, but the voice was engineered to sound right. Identity Impersonation Detection moves the proof off the call. It verifies a person against authoritative external records and ties the request to a device the real person holds, with no PII kept on file and no selfie or face scan. Confirm identity that way and a flawless voice clone stops mattering.
Over the coming issues, The Identity Perimeter will work through real incidents, the anatomy of the calls behind them, the numbers on the risk, and the verification methods that hold up. Some posts will come from the Trusona team. Some will come from Ori.
Read the first post and subscribe at trusona.substack.com.