The possible silver lining of enterprise-scale fraud is that it might be the pain which finally pushes telephony / voice comms to adopt true call-level authentication and security.
This need not be a centralised security / authentication / identification system, but the protocols must be standardised and near-universally applied. If these rely on some hardware token (YubiKey, NFC ring, RSA keyfob OTP, or even a smartphone's native ID features).
The other side of this is that networks and carriers who transact largely fraudulent traffic must be penalised for this. I'd like to see both financial and technical penalities, e.g., ruinous fines, with a sufficiently large balance disqualifying the carrier from interconnect rights, and the right for terminating / bridging carriers to reject traffic in proportion to the level of malicious traffic logged.
(This also implies some distributed facility for monitoring traffic from various comms networks and sharing that information with carriers and other security provisioning parties.)
A worse outcome would be a two-tiered system in which large enterprises have access to reasonably fraud-free comms, and the rest of the world does not.
This need not be a centralised security / authentication / identification system, but the protocols must be standardised and near-universally applied. If these rely on some hardware token (YubiKey, NFC ring, RSA keyfob OTP, or even a smartphone's native ID features).
The other side of this is that networks and carriers who transact largely fraudulent traffic must be penalised for this. I'd like to see both financial and technical penalities, e.g., ruinous fines, with a sufficiently large balance disqualifying the carrier from interconnect rights, and the right for terminating / bridging carriers to reject traffic in proportion to the level of malicious traffic logged.
(This also implies some distributed facility for monitoring traffic from various comms networks and sharing that information with carriers and other security provisioning parties.)
A worse outcome would be a two-tiered system in which large enterprises have access to reasonably fraud-free comms, and the rest of the world does not.