惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
AI
AI
L
LINUX DO - 最新话题
The Register - Security
The Register - Security
T
Threatpost
Y
Y Combinator Blog
K
KPMG report finds enterprise disconnect between AI and its ROI | CIO
Attack and Defense Labs
Attack and Defense Labs
T
Tailwind CSS Blog
P
Proofpoint News Feed
MongoDB | Blog
MongoDB | Blog
H
Heimdal Security Blog
小众软件
小众软件
D
Docker
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
T
The Exploit Database - CXSecurity.com
AWS News Blog
AWS News Blog
腾讯CDC
博客园 - 司徒正美
美团技术团队
L
LINUX DO - 热门话题
N
Netflix TechBlog - Medium
Stack Overflow Blog
Stack Overflow Blog
S
Security Affairs
阮一峰的网络日志
阮一峰的网络日志
爱范儿
爱范儿
N
News and Events Feed by Topic
J
Java Code Geeks
F
Fortinet All Blogs
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
U
Unit 42
V2EX - 技术
V2EX - 技术
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
T
Tor Project blog
H
Help Net Security
The GitHub Blog
The GitHub Blog
L
Lohrmann on Cybersecurity
Hugging Face - Blog
Hugging Face - Blog
S
Securelist
PCI Perspectives
PCI Perspectives
W
WeLiveSecurity
A
About on SuperTechFans
N
News and Events Feed by Topic
博客园 - 叶小钗
Cloudbric
Cloudbric
L
LangChain Blog
WordPress大学
WordPress大学
B
Blog
Exploit-DB.com RSS Feed
Exploit-DB.com RSS Feed

Search Security Resources and Information from TechTarget

How to operationalize threat modeling with AI | TechTarget CISO First fully agentic ransomware attack sparks readiness concerns | TechTarget Evaluating secure enterprise browsers vs. security plugins | TechTarget The AI vulnerability storm is here: Is your security program ready? | TechTarget Perimeter to posture: A roadmap to zero trust maturity | TechTarget TLS certificate lifetime changes: What CISOs must do now | TechTarget The agentic AI 8 key aspects of a mobile device security audit program | TechTarget Why mobile security audits are important in the enterprise | TechTarget Beyond the perimeter: The shift to data-centric protection | TechTarget How agentic AI threat intelligence aids NGO cyber defense: Case study | TechTarget How to conduct a mobile app security audit | TechTarget NO FAKES Act advances: What CISOs need to know | TechTarget What CISOs should know about AI runtime security | TechTarget As Q-Day looms, 90% of systems are unprepared for PQC | TechTarget A CISO Most security pros say their culture is Zscaler lays out its vision to secure the AI era at Zenith Live | TechTarget The OpenClaw security risks every CISO needs to know | TechTarget Cloud security metrics and KPIs: A CISO Florida public sector training on SimSpace cyber range: Case study | TechTarget Reporters' Notebook — Focus on Cyber Insurance: How Quantifying Risk Is Reshaping Security It's time to update incident response for the AI era How to build AI security guardrails without blocking innovation The prosecution gap: Why cybercrimes go unpunished AI in cyberdefense: Learning from threat actors' playbooks Top identity and access management risks CISO role changes as cyber-risk appetites in the C-suite grow CISO's guide to data minimization Researchers build autonomous AI worm that can reason and adapt How to secure data at rest, in use and in motion How to find cyber-risk data sources for a FAIR analysis Lost in translation: Cybersecurity board reporting for CISOs How to prepare security controls for future AI regulations EO 14390 raises stakes for enterprise cybersecurity First month of Mythos Preview testing exposes 10K flaws OT attacks shift from recon to physical control, raising stakes For CISOs, dawn of OpenAI Daybreak brings good and bad news Gartner Security & Risk Management Summit 2026: Adapting for AI | TechTarget Inside business email compromise attacks: Real-world examples Verizon 2026 DBIR: 6 key takeaways for CISOs Identity security for AI agents: The proliferation challenge How to build a business impact analysis checklist Taking care of business: The CISO's role in a cyber crisis What CISOs need to know about AI audit logs SOC vs. MDR: What CISOs need to consider Instructure cyberattack reignites ransom payment debate Transform SIEM rules with behavior-based threat detection CISO's guide: How to test an incident response plan How to implement zero trust for AI Data after the breach: Economics of the dark web The breakup: Why CISOs are decoupling data from their SIEMs | TechTarget News brief: Security worries and warnings as AI use expands How to construct an effective security controls evaluation 5 leading enterprise password managers to consider Claude Mythos changes the AI security threat matrix Buyer 6 things to check in your cyber insurance policy fine print How cyber insurance helped with breach recovery -- or not News brief: Critical infrastructure, OT cybersecurity attacks Tape's strategic role in modern data protection Top zero-trust use cases in the enterprise What every CISO should consider before a SIEM migration CISO's guide to centralized vs. federated security models Shadow code: The hidden threat for enterprise IT How to fix cybersecurity's agentic AI identity crisis 5 top SIEM use cases in the enterprise Top 8 e-signature software providers for 2026 How do digital signatures work? News brief: AI woes continue for security leaders Is SOAR dead or alive? Sort of The push for digital sovereignty: What CISOs need to know Beyond awareness: Human risk management metrics for CISOs Cybersecurity in the age of AI means bigger, faster threats At RSAC 2026, AI optimism and anxiety -- and an MIA U.S. government Inside the SOC that secured RSAC 2026 Conference How to roll out an enterprise passkey deployment How to improve the SOC analyst experience -- and why it matters How contact centers detect and prevent fraud News brief: Iranian cyberattacks target U.S. water, energy CISO checklist: Cybersecurity platform or marketing ploy? RSAC 2026 Conference: Key news and industry analysis | TechTarget Next-generation firewall buyer's guide for CISOs Contact center monitoring best practices for CX leaders RSAC 2026: Cyber insurance and the rise of ransomware Agentic AI's role in amplifying and creating insider risks RSAC 2026 recap: AI security and network security trends Identity security at RSAC 2026: The new enterprise dynamics Meaningful metrics demonstrate the value of cyber-resiliency What to know about red team testing and the law News brief: Iran cyberattacks escalate, U.S. targets named 5 top SOC-as-a-service providers and how to evaluate them Cloud security architecture: Enterprise cloud blueprint for CISOs Contact center compliance checklist for modern workforces How AI caught a malicious North Korean insider at Exabeam Watch your words: Tim Brown's advice for CISOs News brief: U.S. absence at RSAC sparks leadership concerns Network security management challenges and best practices 10 enterprise secure remote access best practices
Deepfake era demands proof-based security, not just awareness
2026-04-24 · via Search Security Resources and Information from TechTarget

Sean Michael Kerner

By

Published: 23 Apr 2026

For decades, cybercriminals have impersonated targets' trusted contacts to convince them to send funds, credentials or sensitive data. Thanks to deepfake and voice cloning technology, however, security awareness training -- the usual countermeasure to social engineering attacks -- is arguably no longer enough.

Traditional security awareness training relies on pattern recognition: Does this email look suspicious? Does that link seem off? But highly convincing deepfake audio and video attacks mean users can no longer rely on instinct or context cues to determine if a message is legitimate.

"Recognition-based training breaks down when an employee believes they're talking to an executive with an urgent request," said Diana Rothfuss, director of global strategy for risk, fraud and compliance solutions at data and AI software provider SAS. "To defend against this type of threat, organizations have to get their employees to go beyond 'does this look right?'"

The vast majority of fraud professionals -- 77% -- say deepfake attacks are increasing, according to the 2026 Anti-Fraud Technology Benchmarking Report, co-published by SAS and the Association of Certified Fraud Examiners (ACFE). Just 7% described their organizations as more than moderately prepared to detect or prevent deepfakes. As a result, some security experts are calling on organizations to implement and normalize proof-based systems, processes and policies to verify that people are who they say they are and short-circuit deepfake attacks.

Prove it: Separating authority from authentication

The core principle of a proof-based approach is that no single interaction, whether voice, video or text, can authorize a sensitive action on its own -- what SAS' Rothfuss described as "separating authority from authentication." That sounds straightforward but runs against how most employees are wired to respond to executive requests.

Consider, for example, a 2024 incident in which threat actors used deepfake technology to steal $25 million from global engineering firm Arup. A finance employee, believing he was on a video conference with senior executives, wired the money at the attackers' request.

While such highly sophisticated deepfake video attacks are still relatively rare, audio cloning is a light lift for cybercriminals. Experts say such incidents present a clear mandate for finance and IT teams to formalize processes for verifying wire transfer requests, rather than handling them on an ad hoc basis.

"Proof-based verification policies should not be that hard; frankly, they should already exist," said Ira Winkler, field CISO at cybersecurity company Aisle. "There should now be operational procedures in place, such as email verification of a financial transfer before transferring the money, even with 'visual' instruction."

Equally important, Winkler added, staff must be trained on such policies and understand that there are no exceptions -- even if they receive verbal instructions from a senior executive over the phone or on Zoom. "This is not just for deepfakes, but for fraud protections in general," he said.

Specific authentication controls that do not depend on a human user's recognition of a voice or face include the following:

Out-of-band, two-factor verification

Before fulfilling sensitive requests -- e.g., fund transfers, credential resets and privileged access changes -- users require confirmation through two separate, pre-approved channels, such as an internal authentication app and a team messaging platform. Because of the rising prevalence of deepfakes and voice cloning, video calls, phone calls and voicemails do not satisfy this requirement.

"How I will contact you" protocols

Executives and IT leadership establish in advance specific channels they will use for sensitive requests. Any request arriving outside those channels triggers a mandatory hold and verification through a separate, trusted path.

"Employees can no longer rely on instinct to determine whether a message is legitimate," said T. Frank Downs, senior director of proactive services at BlueVoyant, a cybersecurity services provider based in New York. "We need to reinforce the idea that identity is confirmed through process and verification steps."

Pre-established verification phrases

Known only to authorized parties, these phrases confirm identity in high-stakes communications without relying on voice or video recognition.

Designated approvers

No single employee can authorize a high-risk transaction. A named secondary approver must confirm before funds move or access is granted.

The hard part: Executing consistently and under pressure

Policy design is the easier part of proof-based verification. Consistent execution under real conditions is where most programs fall short. Experts suggested the following best practices to improve governance and human follow-through:

Treat verification as a safety rail, not a judgment call

Deepfake video- and audio-based attacks, like traditional business email compromise, are designed to generate urgency at precisely the moment verification matters most.

"Verification isn't optional," Rothfuss said. "That means instituting proof-based controls that operate as non-negotiable safety rails, not something discretionary that employees can skip when they're feeling pressured or rushed. As with other less sophisticated scams, pressure and urgency is precisely the point."

Get executives on record before an incident occurs

Staff will not push back on out-of-channel requests unless leadership has made clear in advance that doing so is expected and part of the organization's cybersecurity culture.

"That requires defining the rules well in advance, so executives understand and encourage pushback, and employees don't feel forced to improvise under duress," Rothfuss said.

Reinforce continuously, not just once

Staff who understand how verification controls protect the organization are more likely to adopt them, but that understanding does not make the behavior automatic.

"Under pressure, people tend to fall back into old habits, which is exactly when verification is most important," Downs said. That makes continuous training and reinforcement a must.

Build a culture in which slowing down is the norm

Adoption ultimately depends on employees feeling confident that if they pause to verify requests, leaders will reward rather than penalize them for doing so.

"Organizations need to normalize 'see something, say something' behavior and make verification frictionless," said Mika Aalto, co-founder and CEO at Hoxhunt, a Helsinki-based human risk management vendor. "The real challenge is cultural: giving employees confidence that slowing down to verify is expected, supported and reinforced through human risk management practices."

Sean Michael Kerner is an IT consultant, technology enthusiast and tinkerer. He has pulled Token Ring, configured NetWare and been known to compile his own Linux kernel. He consults with industry and media organizations on technology issues.

Dig Deeper on Risk management