How Cisco IT Modernized Voice Security with AI Cisco IT reduced toll fraud by 70% and manual investigation effort by 60% by applying AI and machine learning to its enterprise voice security, using a composite risk-scoring engine that combines rules with ML across its on-premises Cisco Unified Communications and cloud-native Webex Calling environments, unified with Splunk Cloud Platform. The initiative addresses growing liabilities from nuisance calls, including toll fraud and regulatory exposure related to Federal Trade Commission compliance. The threat landscape for enterprise voice is evolving. Learn how Cisco IT used AI to eliminate a hidden cost center and a compliance liability at scale—before regulators or fraudsters forced our hand—achieving a 70% reduction in toll fraud and a 60% reduction in manual investigation effort. The Challenge: When traditional defenses fall short The impact of nuisance calls to the enterprise is not a minor inconvenience—it is a growing business liability. Across industries, organizations can lose millions to toll fraud, drowning their security teams in manual investigation work, and exposing themselves to regulatory scrutiny, all while their employees are interrupted by relentless robocalls that erode trust in the tools meant to connect them. For most enterprises, the defenses in place today were built for a threat landscape that no longer exists. At Cisco IT, we manage one of the largest enterprise voice environments in the world. As the volume and sophistication of nuisance calls—such as toll fraud, robocalls, and spam—increased, our traditional methods of defense started to show their age. We were relying on manual blocklists, carrier alerts, and static, rule-based controls that were simply not keeping pace with the threat landscape. The real problem was not a lack of tools—it was a lack of context. These systems could tell us that a call had happened, but not what that call meant. Every threat required a human to investigate after the fact, which meant fraud was already in motion by the time we responded. With millions of calls flowing across our global environment daily, that latency was not just inefficient—it was a structural vulnerability, creating a dangerous lag time between a new threat emerging and our ability to mitigate it. This created a significant operational burden, with our team spending countless hours manually reviewing Call Detail Records CDRs . Beyond the productivity impact on our employees, we faced real risks—including potential toll fraud losses and regulatory exposure related to Federal Trade Commission FTC compliance. We realized that to protect our global footprint, we had to stop measuring calls and start understanding them—shifting from reactive to predictive. A new approach: Applying observability to voice Instead of simply adding another point solution to our stack, we decided to apply the same AIOps and observability principles we use across our broader infrastructure and security environments. We wanted a solution that was hybrid—combining rules with machine learning—to ensure we weren’t just relying on “black box” models. Our key requirements were clear: Behavioral context: Moving beyond simple static indicators to understand the intent of a call. Explainability: Ensuring our operations team could understand why a call was flagged. Scalability: The system had to handle millions of calls across our global footprint without breaking a sweat. The solution: Building a composite risk-scoring engine Our voice environment is vast and complex. To secure it, we had to ensure our solution worked seamlessly across our on-prem Cisco Unified Communications https://www.webex.com/us/en/products/suite/enterprise-cloud-calling/CUCM.html UC infrastructure and our cloud-native Webex Calling https://www.webex.com/suite/enterprise-cloud-calling.html environment. The telemetry captured from these platforms provides a comprehensive view of our global footprint. To aggregate all of this data, we unified our UC and Webex environments with Splunk Cloud Platform https://www.splunk.com/en us/products/splunk-cloud-platform.html —utilized to provide a unified, scalable data layer capable of ingesting and normalizing massive volumes of CDRs across both environments. Our approach correlates user-level call data, infrastructure telemetry, and global threat intelligence in real-time. By streaming data from both environments into a single platform, we can normalize and correlate millions of CDRs in real-time. This is the true power of our Cisco platform. We don’t just see the call—we also see the entire digital context surrounding it, correlating voice telemetry with broader enterprise security data to identify sophisticated threats that would otherwise go undetected, allowing us to neutralize threats before they impact our employees. Now, we can automatically stratify risk, prioritizing the most dangerous activity for immediate mitigation while providing guided actions for our team. With that data foundation in place, we layered on an AI-driven detection framework that evaluates each call using multiple independent signals. By leveraging machine learning models—specifically Random Forest and XGBoost—we trained our system on enriched call features and correlated this with external threat intelligence, including Federal Trade Commission FTC complaint data. The results: Efficiency and security The shift has been transformative. We have seen: Operational efficiency: A ~ 60% reduction in manual investigation effort. Cost avoidance: An estimated ~ 70% reduction in potential toll fraud losses. Enhanced security: Faster detection of emerging fraud patterns and a significant decrease in spam reaching our employees. Perhaps most importantly, we have restored trust in our enterprise voice services. Employees are decreasingly interrupted by constant robocalls, and our security posture is now a proactive asset rather than a reactive chore — significantly strengthening our digital resilience. A note on our approach: Flexibility in voice security While our team chose to build this internal solution to address the unique scale and complexity of Cisco’s global voice environment, we recognize that every organization has different requirements. Cisco’s strategy is to provide customers with choice. For many enterprises, our Webex Solution Plus partners—such as Mutare, SecureLogic, and Pindrop—offer powerful, turn-key nuisance call detection solutions that can be deployed rapidly to meet specific business needs. These partner solutions are excellent for organizations looking for specialized, out-of-the-box protection. Our internal journey, however, demonstrates the power of the Cisco platform itself. By leveraging the integration between our voice infrastructure, Splunk, and our internal security telemetry, we were able to create a highly customized, scalable, and cost-effective framework. Whether you choose to leverage the specialized capabilities of our Solution Plus partners or build a custom observability framework using the Cisco infrastructure you already own, the goal remains the same: restoring trust in your voice communications. A c ollaborative e ffort: The r ole of Cisco c ustomer e xperience This was not an isolated IT project. By partnering with our Customer Experience CX team, we combined our internal operational scale with the specialized expertise our Professional Services use to help customers worldwide. This partnership accelerated our development cycle and ensured the solution was built with the same rigorous standards we apply to our global client deployments. For our customers, this project serves as a blueprint: it demonstrates how you may leverage Cisco CX services to assess your environment, recommend Solutions Plus parters, or co-innovate, to bridge the gap between your existing infrastructure and new AI-driven capabilities, and achieve faster time-to-value. A blueprint for modernizing voice security If your organization is looking to modernize its voice security, my advice is to start with visibility. You cannot fix what you cannot measure. Move away from static rules and start applying behavioral intelligence where it adds the most value. Whether you are running Cisco Unified Communications or Webex Calling, this approach is highly scalable and repeatable. Want to dive deeper into the technical architecture? Read Part 2: How Cisco Operationalized Voice Security with Cisco Splunk https://blogs.cisco.com/?p=495772&preview=true Explore More Discover Webex Calling security features https://www.cisco.com/c/en/us/solutions/collaboration/webex-calling.html - Learn more on how Cisco Professional Service https://www.cisco.com/site/us/en/services/professional/index.html can help - Explore more ways Cisco uses its own technology: Visit Cisco on Cisco https://www.cisco.com/c/en/us/about/cisco-on-cisco.html