Back Infosecurity-Magazine CISOs Must Update Incident Response Playbooks for Multimodal Deepfakes, Gartner Warns
Almost half of CISOs have reported at least one deepfake incident in the past 12 months, highlighting the need to update incident response playbooks to address multimodal deepfake threats.
As the opening of the Gartner Security & Risk Management Summit in London on September 22, the global consulting firm published findings from its AI-driven Social Engineering Attacks report, which surveyed 297 senior cybersecurity leaders .
The study, conducted between survey conducted in March and May 2026, found that AI is increasing the volume, personalization and credibility of social engineering while reducing the reliability of familiar detection cues.
More than four in ten respondents (41%) reported at least one social engineering incident involving a deepfake during an employee audio call in the 12 months and 36% reported one during a video call.
Additionally, 79% of CISOs surveyed reported at least one email phishing, spearphishing, or business email compromise (BEC) incident in the last 12 months, while 58% reported one vidoe phishing (vishing) or SMS phishing (smishing) incident.
Craig Porter, director analyst at Gartner, said that as most attacks will continue to rely on users, stolen credentials, weak recovery processes and familiar technical methods, CISOs “must use the same discipline used to assess identity and access risks to combat AI-driven social engineering threats.”
How CISOs Can Mitigate Deepfake Phishing Threats
To effectively counter evolving AI social engineering attacks, Porter’s team shared three measures CISOs should take:
Shift secure behavior and culture programs from teaching employees to “spot the fake” toward making secure verification the standard for consequential requests, with training, simulations, and clear expectations to pause, verify, and report suspicious activity across all communication channels
Protect high-value workflows such as account recovery, privileged access, and payment authorization with phishing-resistant authentication, risk-based identity controls, trusted verification channels, and measures that detect identity abuse after login or password resets
Correlate suspicious communications and impersonation reports with account recovery events, new devices, privilege changes, and financial transactions, while updating incident response playbooks to address multimodal impersonation, manipulated AI recommendations, and compromised, misused, or out-of-bounds AI agents
When Seeing Isn’t Believing: Deepfakes in the Digital Age Opinion 25 September 2019
When Seeing Isn’t Believing: Deepfakes in the Digital Age
Gartner Warns Agentic AI Will Accelerate Account Takeovers News 19 March 2025
Gartner Warns Agentic AI Will Accelerate Account Takeovers
North Korean Hackers Use Deepfake Video Calls to Target Crypto Firms News 11 February 2026
North Korean Hackers Use Deepfake Video Calls to Target Crypto Firms
#Infosec2025: Combating Deepfake Threats at the Age of AI Agents News 8 May 2025
#Infosec2025: Combating Deepfake Threats at the Age of AI Agents
Psychology, AI and the Modern Security Program: A CISO’s Guide to Human Centric Defence Opinion 6 February 2026
Psychology, AI and the Modern Security Program: A CISO’s Guide to Human Centric Defence
What’s Hot on Infosecurity Magazine?
ShinyHunters Claim Hack of Rival Ransomware Gang Clop
Revolut Customers Targeted with New Wave of Phishing Attacks
Experts Alarmed Over Gyazo’s Breach of 490 Million Metadata Records
Major Cyber Vendors Turn to New UK Testing Program as MITRE Evaluations Face Changes
New Settra Ransomware Variant Deployed in Attacks on Retail and Manufacturing
New Chinese-Made ‘RatHat’ Android Malware Leverages AI to Steal Financial Data
Major Cyber Vendors Turn to New UK Testing Program as MITRE Evaluations Face Changes
CRA Reporting Rules Take Effect: How to Ensure Your Organization is Ready
AI Agent Carries Out Multi-Stage Data Theft Attack
Most Firms Unable to Recover Quickly from Ransomware
A CISO's Lessons in Ransomware Response and Recovery After a Real-World LockBit Attack
ShinyHunters Claim Hack of Rival Ransomware Gang Clop
Your Security Awareness Programme Isn't Failing, It's Just Not Relevant
How to Secure AI with Modern App and API Strategies
Frontier AI: How Cyber Defenders Can Harness the Defender’s Window
Human Risk in Cybersecurity: Protecting Your Organization Beyond Technology
Financial Services Cyber Resilience: Stress Testing Third Parties Before Attackers Do
Same Front Door, New Visitors: Securing Humans and AI Agents at the Browser
How Faster Cyber-Attacks Are Reshaping Enterprise Cybersecurity Strategies
Researchers Claim First Fully Agentic Ransomware: JadePuffer
AI is Already Powering Cyber-Attacks. Can it Power Cyber Defense?
Google Cloud's New CISO Chris Betz on Integrating AI in Cyber Defenses
How World Cup Password Trends Can Increase Active Directory Risk
New CISA Guide Helps Agencies Adopt SASE For Zero Trust
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
