What we do
01  Advanced Infrastructure 02  Applied AI & Data 03  AI Cybersecurity 04  AI Assurance
Engagements
AI estate inventory Assurance review
Industries
Financial Services Government & Public Sector Energy & Utilities Telecommunications Healthcare & Life Sciences Transport & Logistics Industrial & Manufacturing Retail, Hospitality & Real Estate
Research
The Trust Maturity Model The GCC Assurance Index Readiness self-assessment Case studies Perspectives Sector briefings Technology evaluations
Company
About us Partners Events Careers Contact العربية Talk to our team
AI Cybersecurity  ·  Human Risk Defense

The voice on the call was fake.

Synthetic voice and synthetic video have made the convincing colleague cheap to manufacture. The defence is not a more suspicious workforce. It is a process in which one convinced person is never sufficient.

4–8 WEEKSPROCESS CHANGE, NOT AWARENESS TRAININGTESTED ON YOUR OWN WORKFLOWS
The decisions underneath

Three questions decide the design.

Human-risk programmes are usually measured on click rates. Click rate is a proxy for a thing that no longer describes the attack.

01

Where is one person sufficient

Find every workflow where a single individual, under time pressure, can complete an irreversible action. That list is the programme.

02

What does verification actually cost

A callback to a known number costs ninety seconds. The control fails not because people refuse it but because nobody made it the normal path.

03

Would a synthetic voice pass

Voice as an authentication factor is now a weak one. Any process still relying on recognising a colleague needs re-examining on that basis alone.

How the path runs

The attack that arrives as a person.

These paths do not start with a file. They start with a request that a competent, busy person had no reason to refuse. Choose an entry point.

ENTRY

FOOTHOLD

CREDENTIAL

LATERAL

OBJECTIVE

ATTACK PATH— GATES USUALLY PRESENT
Select an entry point

Five stages, from the way in to the thing the attacker came for. What changes between paths is how long each stage stays invisible.

Human risk is not solved by training people to be suspicious. It is solved by designing processes where one convinced person is not sufficient.

What you receive

Changed processes, not a training completion rate.

Four stages, every engagement. Hover a stage to see what happens in it.

DURATION
4–8 weeks
DELIVERABLE
Workflow findings and process changes
DELIVERED
Remotely; testing scoped and consented in writing
INDICATIVE FEE
[FEE BAND — pending sign-off]
The boundary

We run it. We do not audit what we run.

Three moves. Two of them are ours, and the one in the middle is deliberately somebody else’s.

MOVE 01 — OURS

We operate the capability

Detection engineering, triage, response and the reporting that goes with it. This is an operational service with a named duty owner, not an advisory engagement.

MOVE 02 — NOT OURS

Somebody else tests it

Effectiveness testing of a service Orvix runs is performed by a party that does not report to the team running it. Where a regulator or a board needs the result to carry weight, that party is not Orvix.

MOVE 03 — OURS

We close what the test opened

Detection gaps found by the test become engineering work with a date against them, and the re-test is run by the tester rather than by us.

The sharpest argument we make about other suppliers is that nobody should audit their own estate. It applies here first.
AI Cybersecurity

The rest of this pillar.

Three engagements inside this pillar. Start with the question you can name, or take the whole estate at once.

Questions we are asked

Before you ask us.

Is this awareness training?
No. Awareness has value and it is not what this is. This engagement changes the workflows so that being convinced is not enough to complete the action — which works regardless of how convincing the attack becomes.
Do you run simulated attacks against our staff?
Only with written scope and consent, and never in a way designed to produce an embarrassing statistic. The output is a list of workflows to change, not a list of people who failed.
Can you detect deepfakes for us?
Detection tooling exists in this category and we assess it, but we are deliberately careful here: vendor benchmark performance and performance on your own traffic are often not the same number, and we will not sell a capability as proven for your domain until it has been tested on it.
How is success measured?
By whether the verification step is being used, and by whether the number of workflows where one person is sufficient has gone down. Both are countable.

Start with the payment one person can release.

Thirty minutes. Name a high-consequence action a single person can complete alone, and we will start there.

Book a 30-minute scoping call

ORVIX · INDEPENDENT AI & TECHNOLOGY ASSURANCE · WE DISCLOSE EVERY COMMERCIAL RELATIONSHIP ON THE PAGE FOR THE SERVICE IT BELONGS TO. WHERE LICENSING IS REQUIRED, DELIVERY IS PERFORMED BY NAMED PARTNERS UNDER THEIR OWN LICENCE.