www.infosecurity-magazine.com 22 Sept 2026, 09:30 UTC

Gartner Urges CISOs to Rethink Defences Against Deepfake Scams

Gartner Urges CISOs to Rethink Defences Against Deepfake Scams
CyberSIXT Evidence Panel Source marked as original reporting

GARTNER has warned that chief information security officers (CISOs) need to revise incident-response plans to cover multimodal deepfakes and AI-driven social engineering. Its report, based on a survey of 297 senior cybersecurity leaders conducted between March and May 2026, found that 41% had experienced at least one deepfake-related social-engineering incident during an employee audio call in the previous 12 months, while 36% reported one involving a video call. Gartner said AI is increasing the volume, personalisation and credibility of attacks while making familiar warning signs less reliable.

Traditional phishing remains widespread: 79% of respondents reported at least one email phishing, spearphishing or business email compromise incident in the same period, and 58% reported vishing or smishing. Craig Porter, a Gartner director analyst, said organisations should apply the same discipline used for identity and access risks to AI-enabled social engineering.

Gartner recommends making secure verification standard practice for consequential requests, rather than relying on employees to identify fake content. It also advises protecting account recovery, privileged access and payment authorisation with phishing-resistant authentication, risk-based controls and trusted verification channels.

Incident-response playbooks should link suspicious communications and impersonation reports with recovery events, new devices, privilege changes and financial transactions, and account for manipulated AI recommendations and compromised, misused or out-of-bounds AI agents.

View full article

Article by CyberSIXT