Skip to content
CISOs Must Update Incident Response Playbooks for Multimodal Deepfakes, Gartner Warns

CISOs Must Update Incident Response Playbooks for Multimodal Deepfakes, Gartner Warns

Infosecurity-Magazine • September 22, 2026

Almost half of CISOs have reported at least one deepfake incident in the past 12 months, highlighting the need to update incident response playbooks to address multimodal deepfake threats.

As the opening of the Gartner Security & Risk Management Summit in London on September 22, the global consulting firm published findings from its AI-driven Social Engineering Attacks report, which surveyed 297 senior cybersecurity leaders .

The study, conducted between survey conducted in March and May 2026, found that AI is increasing the volume, personalization and credibility of social engineering while reducing the reliability of familiar detection cues.

More than four in ten respondents (41%) reported at least one social engineering incident involving a deepfake during an employee audio call in the 12 months and 36% reported one during a video call.

Additionally, 79% of CISOs surveyed reported at least one email phishing, spearphishing, or business email compromise (BEC) incident in the last 12 months, while 58% reported one vidoe phishing (vishing) or SMS phishing (smishing) incident.

Craig Porter, director analyst at Gartner, said that as most attacks will continue to rely on users, stolen credentials, weak recovery processes and familiar technical methods, CISOs “must use the same discipline used to assess identity and access risks to combat AI-driven social engineering threats.”

How CISOs Can Mitigate Deepfake Phishing Threats

To effectively counter evolving AI social engineering attacks, Porter’s team shared three measures CISOs should take:

Shift secure behavior and culture programs from teaching employees to “spot the fake” toward making secure verification the standard for consequential requests, with training, simulations, and clear expectations to pause, verify, and report suspicious activity across all communication channels

Protect high-value workflows such as account recovery, privileged access, and payment authorization with phishing-resistant authentication, risk-based identity controls, trusted verification channels, and measures that detect identity abuse after login or password resets

Correlate suspicious communications and impersonation reports with account recovery events, new devices, privilege changes, and financial transactions, while updating incident response playbooks to address multimodal impersonation, manipulated AI recommendations, and compromised, misused, or out-of-bounds AI agents

When Seeing Isn’t Believing: Deepfakes in the Digital Age Opinion 25 September 2019

When Seeing Isn’t Believing: Deepfakes in the Digital Age

Gartner Warns Agentic AI Will Accelerate Account Takeovers News 19 March 2025

Gartner Warns Agentic AI Will Accelerate Account Takeovers

North Korean Hackers Use Deepfake Video Calls to Target Crypto Firms News 11 February 2026

North Korean Hackers Use Deepfake Video Calls to Target Crypto Firms

#Infosec2025: Combating Deepfake Threats at the Age of AI Agents News 8 May 2025

#Infosec2025: Combating Deepfake Threats at the Age of AI Agents

Psychology, AI and the Modern Security Program: A CISO’s Guide to Human Centric Defence Opinion 6 February 2026

Psychology, AI and the Modern Security Program: A CISO’s Guide to Human Centric Defence

What’s Hot on Infosecurity Magazine?

ShinyHunters Claim Hack of Rival Ransomware Gang Clop

Revolut Customers Targeted with New Wave of Phishing Attacks

Experts Alarmed Over Gyazo’s Breach of 490 Million Metadata Records

Major Cyber Vendors Turn to New UK Testing Program as MITRE Evaluations Face Changes

New Settra Ransomware Variant Deployed in Attacks on Retail and Manufacturing

New Chinese-Made ‘RatHat’ Android Malware Leverages AI to Steal Financial Data

Major Cyber Vendors Turn to New UK Testing Program as MITRE Evaluations Face Changes

CRA Reporting Rules Take Effect: How to Ensure Your Organization is Ready

AI Agent Carries Out Multi-Stage Data Theft Attack

Most Firms Unable to Recover Quickly from Ransomware

A CISO's Lessons in Ransomware Response and Recovery After a Real-World LockBit Attack

ShinyHunters Claim Hack of Rival Ransomware Gang Clop

Your Security Awareness Programme Isn't Failing, It's Just Not Relevant

How to Secure AI with Modern App and API Strategies

Frontier AI: How Cyber Defenders Can Harness the Defender’s Window

Human Risk in Cybersecurity: Protecting Your Organization Beyond Technology

Financial Services Cyber Resilience: Stress Testing Third Parties Before Attackers Do

Same Front Door, New Visitors: Securing Humans and AI Agents at the Browser

How Faster Cyber-Attacks Are Reshaping Enterprise Cybersecurity Strategies

Researchers Claim First Fully Agentic Ransomware: JadePuffer

AI is Already Powering Cyber-Attacks. Can it Power Cyber Defense?

Google Cloud's New CISO Chris Betz on Integrating AI in Cyber Defenses

How World Cup Password Trends Can Increase Active Directory Risk

New CISA Guide Helps Agencies Adopt SASE For Zero Trust

Extracted Entities

APT Groups (1)

Attack Types (1)

Industries (2)

Malware (1)

MITRE ATT&CK (1)

Platforms (1)

Ransomware Groups (4)