Estimated reading time: 6 minutes
CISOs, beware of deepfake social engineering! Four in ten chief information security officers have now sat through a deepfake on a work audio call. More than a third have seen one on video.
Security awareness training taught people to spot a bad link and a wrong domain. It never taught them to doubt a familiar voice. Gartner surveyed 297 senior cybersecurity leaders between March and May 2026. Forty-one percent reported at least one social engineering incident involving a deepfake during an employee audio call. Thirty-six percent reported one during a video call.
The Deepfake Social Engineering Numbers In Order
The ranking matters as much as the headline figure.
Seventy-nine percent of those CISOs reported at least one email phishing, spear-phishing, or business email compromise incident. Fifty-eight percent reported vishing or smishing. Deepfakes follow behind both.
Craig Porter, a Director Analyst at Gartner, put the balance plainly. Most attacks “will continue to rely on users, stolen credentials, weak recovery processes,” he said.
One point of precision. Gartner asked whether leaders reported at least one incident. A detected attempt counts alongside a successful one. The survey does not separate the two, so 41 percent describes exposure rather than loss.
What Gartner Tells CISOs To Do
Porter set out three actions.
- The first replaces static training. Gartner argues for making verification the expected behavior for consequential requests, rather than teaching staff to spot a fake. Approvers should pause and verify whatever channel a request arrives through.
- The second hardens identity and recovery. Account recovery, privileged access, and payment authorization need phishing-resistant authentication and trusted verification channels. Gartner also wants detection for identity abuse after a successful login or password reset.
- The third updates incident response. Gartner calls for playbooks covering multimodal impersonation, manipulated AI recommendations, misused agents, and agents operating beyond their boundaries.
Porter framed the whole set in familiar terms. CISOs “must use the same discipline used to assess identity and access risks,” he said.
The CISO Meeting This With Less Than Before
The role absorbing this threat has been losing ground elsewhere.
Cyber Insurance News reported this year that the CISO role has hit a boardroom access wall. Budgets have not helped. Cybersecurity budgets flatlined while threats kept climbing. The workforce shortage left teams short of the people who would run those programs. ISACA’s 2026 research, published this week, records 58 percent of teams describing themselves as understaffed.
The threat mix shifted underneath all of it. The World Economic Forum found cyber-enabled fraud overtaking ransomware on the risk list. Sophos recorded identity attacks dominating 2026, and SpyCloud predicted the same.
A detection market has grown around the problem. Reality Defender launched its Real Suite for enterprise deepfake detection earlier this year.
What Practitioners Told The Podcast
Four guests on the Cyber Insurance News podcast have worked on this ground from different sides.
Mike Nelson, VP and Field CTO at DigiCert, took on the evidence problem. His episode is titled If Nobody Can Prove What Happened To A File, Somebody Still Pays For It. It deals with content provenance and claims fraud. A deepfake is a provenance failure before it is a security failure.
Matthew Butler, Director of Cyber Risk services at Travelers, described attackers compressing the victim’s decision time. The Ransom Bot Is Not Haggling covers AI in ransom negotiation, and the same pressure tactic drives deepfake payment fraud.
Chris Skipworth, Chief Executive at Passpack, addressed the credentials Porter names. Nobody Owns The Password examines how credential management fails in practice.
Julien Richard, VP of Information Security at Lastwall, supplied the episode that matters most to underwriters. They Said They Had MFA. They Were Telling the Truth. The Claim Still Failed shows a control present on the application form and absent at the moment of loss.
That is the shape of the deepfake problem too. Verification training exists at most of these organizations. It did not stop the call.
Who Pays When Deepfake Social Engineering Works
The coverage question arrives once the fraud succeeds.
Cyber Insurance News covered a ruling on a 475,000 dollar fraudulent wire transfer that turned on exactly this. When social engineering defeats a human approver, a court decides who absorbs the loss.
Deepfakes sharpen that question without changing its structure. A finance clerk authorizing a payment after a convincing call has followed a process. Whether the policy responds depends on wording written before synthetic voice existed.
Verification questions matter more here than detection tooling. A carrier can read a documented callback procedure. It cannot read whether an employee found a voice convincing.
Get The Cyber Insurance News Upload
Subscribe to our weekly newsletter!
What Underwriters Can Ask
Gartner’s three actions convert into three application questions.
- Does the insured require out-of-band verification for payment authorization and account recovery, through a channel the requester cannot control?
- Does it run phishing-resistant authentication on privileged access and recovery workflows?
- Do its incident response playbooks name impersonation scenarios, and has anyone exercised one?
Each has a documentary answer. None depends on whether staff can tell a real voice from a synthetic one. Gartner says that test is now failing.
Methodology
Gartner surveyed 297 senior leaders of the cybersecurity function, described as CISOs or equivalent. The fieldwork ran from March to May 2026. Gartner released the findings alongside its Security and Risk Management Summit in London. That summit runs from 22 to 24 September.
FAQ – Deepfake Social Engineering
How common is deepfake social engineering?
Gartner found 41 percent of 297 CISOs reported at least one deepfake incident on an employee audio call in the previous 12 months. Thirty-six percent reported one on a video call.
Are deepfakes now the leading attack type?
No. Seventy-nine percent of the same CISOs reported email phishing, spear-phishing or business email compromise, and 58 percent reported vishing or smishing. Gartner expects familiar methods to continue dominating.
Does 41 percent mean those organizations lost money?
Not necessarily. The survey counts any reported incident, including attempts that were detected. It does not separate successful attacks from blocked ones.
What does Gartner recommend?
Three actions. Make verification the expected behavior for consequential requests, harden identity and account recovery with phishing-resistant authentication, and update incident response playbooks for impersonation and agent misuse.
How does this affect cyber insurance?
Social engineering fraud coverage turns on whether a human approver was deceived and what verification the insured required. Courts have already ruled on fraudulent wire transfers, and deepfakes sharpen the same question.
What can underwriters ask about deepfake readiness?
Whether out-of-band verification is required for payment authorization and account recovery, whether phishing-resistant authentication covers privileged access, and whether incident response playbooks name impersonation scenarios.
Related Cyber Insurance Posts
- One AI Failure, Four Policies: AXA XL Names The Scenarios
- Cyber Insurers Grapple with AI Deepfakes(Opens in a new browser tab)
- Insurers Filed Deepfakes Under Cybersecurity. The Risk Walked Into The Claims File.(Opens in a new browser tab)
- Identity Risk Shifts As AI Drives New Wave Of Impersonation Attacks(Opens in a new browser tab)
- Top Strategies for Identity Verification in the Age of Deepfakes, Remote Work, and AI Threats(Opens in a new browser tab)
1 thought on “Four In Ten CISOs Have Met A Deepfake On A Work Call”