Almost half of Chief Information Security Officers (CISOs) have reported encountering at least one incident involving deepfake technology over the past year, shedding light on the urgent necessity to refresh incident response strategies to cater to the shifting landscape of multimodal deepfake threats. This alarming statistic was highlighted during the opening day of the Gartner Security & Risk Management Summit held in London on September 22. At the summit, global consulting firm Gartner unveiled key findings from its report on AI-driven social engineering attacks, which surveyed 297 senior cybersecurity leaders.
The investigation into these incidents took place between March and May 2026, unveiling a more insidious reality in which artificial intelligence is not only amplifying the scale of social engineering attacks but is also personalizing and enhancing their credibility. This evolution is troubling, particularly as it simultaneously diminishes the reliability of traditional detection signals that organizations typically rely upon.
The report revealed that over 41% of respondents experienced at least one social engineering incident involving a deepfake during an employee audio call within the last year, while 36% reported encountering a similar problem during video calls. This represents a substantial shift, as the lines between genuine and manipulated communications continue to blur, creating an environment ripe for exploitation.
In an even broader scope, 79% of the CISOs acknowledged facing at least one incident of email phishing, spearphishing, or business email compromise (BEC) in the previous twelve months. Furthermore, a significant 58% reported incidents of video phishing (often referred to as vishing) or SMS phishing (known as smishing). These statistics pinpoint a pervasive vulnerability in organizations, one that could lead to severe consequences if left unaddressed.
Craig Porter, a director analyst at Gartner, emphasized that as the majority of attacks leverage user interaction, stolen credentials, inadequate recovery processes, and familiar technical methods, it is paramount for CISOs to adopt a disciplined approach akin to that employed in assessing identity and access risks. He stressed the need for organizations to adapt their protocols to effectively counter AI-driven social engineering threats, which have become increasingly sophisticated and deceptive.
To combat the looming threat of deepfake phishing, Porter’s team proposed three critical measures that CISOs should implement:
-
Shift in Training Focus: Organizations must evolve their secure behavior and culture programs from simply teaching employees to “spot the fake.” Instead, the emphasis should be on establishing secure verification as the norm for significant requests. This can be achieved through comprehensive training, simulations, and explicit guidelines that encourage employees to pause, verify, and report any suspicious activity across all communication channels.
-
Enhanced Protection for High-Value Transactions: Protecting critical workflows such as account recovery, privileged access, and payment authorization is essential. This can be achieved by employing phishing-resistant authentication methods, implementing risk-based identity controls, and utilizing trusted verification channels. Additionally, organizations should put in place measures that can detect identity abuse in the aftermath of login attempts or password resets.
- Correlate Communications with Account Activities: It is vital to correlate suspicious communications and reports of impersonation with specific events such as account recovery attempts, introductions of new devices, privilege changes, and financial transactions. Moreover, organizations must update their incident response playbooks to account for the full spectrum of impersonation tactics, including those involving manipulated AI recommendations and compromised or misused AI agents.
As organizations confront a rapidly evolving threat landscape fueled by advanced technologies, the knowledge and measures expressed at the Gartner summit serve as a crucial guide for CISOs. Embracing these recommendations will not only bolster defenses against deepfake incidents but also pave the way for a more secure and resilient digital environment. The urgency to adapt is palpable, as threats become more intricate and challenging to detect, placing greater responsibility on cybersecurity leaders to safeguard their organizations against these insidious risks.

