惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

人人都是产品经理
人人都是产品经理
Stack Overflow Blog
Stack Overflow Blog
L
LINUX DO - 最新话题
Google Online Security Blog
Google Online Security Blog
Schneier on Security
Schneier on Security
Spread Privacy
Spread Privacy
www.infosecurity-magazine.com
www.infosecurity-magazine.com
雷峰网
雷峰网
Google DeepMind News
Google DeepMind News
Microsoft Azure Blog
Microsoft Azure Blog
IT之家
IT之家
V
Vulnerabilities – Threatpost
K
Kaspersky official blog
S
Schneier on Security
B
Blog
The Register - Security
The Register - Security
SecWiki News
SecWiki News
Hacker News: Ask HN
Hacker News: Ask HN
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
S
Security Affairs
T
The Blog of Author Tim Ferriss
G
Google Developers Blog
T
Tenable Blog
P
Proofpoint News Feed
Apple Machine Learning Research
Apple Machine Learning Research
D
DataBreaches.Net
S
Secure Thoughts
Security Latest
Security Latest
H
Heimdal Security Blog
The Hacker News
The Hacker News
O
OpenAI News
AWS News Blog
AWS News Blog
量子位
Exploit-DB.com RSS Feed
Exploit-DB.com RSS Feed
腾讯CDC
U
Unit 42
L
Lohrmann on Cybersecurity
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
L
LangChain Blog
阮一峰的网络日志
阮一峰的网络日志
T
The Exploit Database - CXSecurity.com
NISL@THU
NISL@THU
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
Application and Cybersecurity Blog
Application and Cybersecurity Blog
Hugging Face - Blog
Hugging Face - Blog
The Last Watchdog
The Last Watchdog
Recorded Future
Recorded Future
V2EX - 技术
V2EX - 技术
爱范儿
爱范儿
F
Full Disclosure

Search Security Resources and Information from TechTarget

How to operationalize threat modeling with AI | TechTarget CISO First fully agentic ransomware attack sparks readiness concerns | TechTarget Evaluating secure enterprise browsers vs. security plugins | TechTarget The AI vulnerability storm is here: Is your security program ready? | TechTarget Perimeter to posture: A roadmap to zero trust maturity | TechTarget TLS certificate lifetime changes: What CISOs must do now | TechTarget The agentic AI 8 key aspects of a mobile device security audit program | TechTarget Why mobile security audits are important in the enterprise | TechTarget Beyond the perimeter: The shift to data-centric protection | TechTarget How agentic AI threat intelligence aids NGO cyber defense: Case study | TechTarget How to conduct a mobile app security audit | TechTarget NO FAKES Act advances: What CISOs need to know | TechTarget What CISOs should know about AI runtime security | TechTarget As Q-Day looms, 90% of systems are unprepared for PQC | TechTarget A CISO Most security pros say their culture is Zscaler lays out its vision to secure the AI era at Zenith Live | TechTarget The OpenClaw security risks every CISO needs to know | TechTarget Cloud security metrics and KPIs: A CISO Florida public sector training on SimSpace cyber range: Case study | TechTarget Reporters' Notebook — Focus on Cyber Insurance: How Quantifying Risk Is Reshaping Security It's time to update incident response for the AI era How to build AI security guardrails without blocking innovation The prosecution gap: Why cybercrimes go unpunished AI in cyberdefense: Learning from threat actors' playbooks Top identity and access management risks CISO role changes as cyber-risk appetites in the C-suite grow CISO's guide to data minimization Researchers build autonomous AI worm that can reason and adapt How to secure data at rest, in use and in motion How to find cyber-risk data sources for a FAIR analysis Lost in translation: Cybersecurity board reporting for CISOs How to prepare security controls for future AI regulations EO 14390 raises stakes for enterprise cybersecurity First month of Mythos Preview testing exposes 10K flaws OT attacks shift from recon to physical control, raising stakes For CISOs, dawn of OpenAI Daybreak brings good and bad news Gartner Security & Risk Management Summit 2026: Adapting for AI | TechTarget Inside business email compromise attacks: Real-world examples Verizon 2026 DBIR: 6 key takeaways for CISOs Identity security for AI agents: The proliferation challenge How to build a business impact analysis checklist Taking care of business: The CISO's role in a cyber crisis What CISOs need to know about AI audit logs SOC vs. MDR: What CISOs need to consider Instructure cyberattack reignites ransom payment debate Transform SIEM rules with behavior-based threat detection CISO's guide: How to test an incident response plan How to implement zero trust for AI Data after the breach: Economics of the dark web The breakup: Why CISOs are decoupling data from their SIEMs | TechTarget News brief: Security worries and warnings as AI use expands How to construct an effective security controls evaluation 5 leading enterprise password managers to consider Claude Mythos changes the AI security threat matrix Buyer 6 things to check in your cyber insurance policy fine print How cyber insurance helped with breach recovery -- or not News brief: Critical infrastructure, OT cybersecurity attacks Tape's strategic role in modern data protection Top zero-trust use cases in the enterprise What every CISO should consider before a SIEM migration CISO's guide to centralized vs. federated security models Shadow code: The hidden threat for enterprise IT How to fix cybersecurity's agentic AI identity crisis 5 top SIEM use cases in the enterprise Top 8 e-signature software providers for 2026 How do digital signatures work? News brief: AI woes continue for security leaders Is SOAR dead or alive? Sort of The push for digital sovereignty: What CISOs need to know Beyond awareness: Human risk management metrics for CISOs Cybersecurity in the age of AI means bigger, faster threats At RSAC 2026, AI optimism and anxiety -- and an MIA U.S. government Inside the SOC that secured RSAC 2026 Conference How to roll out an enterprise passkey deployment How to improve the SOC analyst experience -- and why it matters How contact centers detect and prevent fraud News brief: Iranian cyberattacks target U.S. water, energy CISO checklist: Cybersecurity platform or marketing ploy? RSAC 2026 Conference: Key news and industry analysis | TechTarget Next-generation firewall buyer's guide for CISOs Contact center monitoring best practices for CX leaders RSAC 2026: Cyber insurance and the rise of ransomware Agentic AI's role in amplifying and creating insider risks RSAC 2026 recap: AI security and network security trends Identity security at RSAC 2026: The new enterprise dynamics Meaningful metrics demonstrate the value of cyber-resiliency What to know about red team testing and the law News brief: Iran cyberattacks escalate, U.S. targets named 5 top SOC-as-a-service providers and how to evaluate them Cloud security architecture: Enterprise cloud blueprint for CISOs Contact center compliance checklist for modern workforces How AI caught a malicious North Korean insider at Exabeam Watch your words: Tim Brown's advice for CISOs News brief: U.S. absence at RSAC sparks leadership concerns Network security management challenges and best practices 10 enterprise secure remote access best practices
Deepfake era demands proof-based security, not just awareness
2026-04-24 · via Search Security Resources and Information from TechTarget

Sean Michael Kerner

By

Published: 23 Apr 2026

For decades, cybercriminals have impersonated targets' trusted contacts to convince them to send funds, credentials or sensitive data. Thanks to deepfake and voice cloning technology, however, security awareness training -- the usual countermeasure to social engineering attacks -- is arguably no longer enough.

Traditional security awareness training relies on pattern recognition: Does this email look suspicious? Does that link seem off? But highly convincing deepfake audio and video attacks mean users can no longer rely on instinct or context cues to determine if a message is legitimate.

"Recognition-based training breaks down when an employee believes they're talking to an executive with an urgent request," said Diana Rothfuss, director of global strategy for risk, fraud and compliance solutions at data and AI software provider SAS. "To defend against this type of threat, organizations have to get their employees to go beyond 'does this look right?'"

The vast majority of fraud professionals -- 77% -- say deepfake attacks are increasing, according to the 2026 Anti-Fraud Technology Benchmarking Report, co-published by SAS and the Association of Certified Fraud Examiners (ACFE). Just 7% described their organizations as more than moderately prepared to detect or prevent deepfakes. As a result, some security experts are calling on organizations to implement and normalize proof-based systems, processes and policies to verify that people are who they say they are and short-circuit deepfake attacks.

Prove it: Separating authority from authentication

The core principle of a proof-based approach is that no single interaction, whether voice, video or text, can authorize a sensitive action on its own -- what SAS' Rothfuss described as "separating authority from authentication." That sounds straightforward but runs against how most employees are wired to respond to executive requests.

Consider, for example, a 2024 incident in which threat actors used deepfake technology to steal $25 million from global engineering firm Arup. A finance employee, believing he was on a video conference with senior executives, wired the money at the attackers' request.

While such highly sophisticated deepfake video attacks are still relatively rare, audio cloning is a light lift for cybercriminals. Experts say such incidents present a clear mandate for finance and IT teams to formalize processes for verifying wire transfer requests, rather than handling them on an ad hoc basis.

"Proof-based verification policies should not be that hard; frankly, they should already exist," said Ira Winkler, field CISO at cybersecurity company Aisle. "There should now be operational procedures in place, such as email verification of a financial transfer before transferring the money, even with 'visual' instruction."

Equally important, Winkler added, staff must be trained on such policies and understand that there are no exceptions -- even if they receive verbal instructions from a senior executive over the phone or on Zoom. "This is not just for deepfakes, but for fraud protections in general," he said.

Specific authentication controls that do not depend on a human user's recognition of a voice or face include the following:

Out-of-band, two-factor verification

Before fulfilling sensitive requests -- e.g., fund transfers, credential resets and privileged access changes -- users require confirmation through two separate, pre-approved channels, such as an internal authentication app and a team messaging platform. Because of the rising prevalence of deepfakes and voice cloning, video calls, phone calls and voicemails do not satisfy this requirement.

"How I will contact you" protocols

Executives and IT leadership establish in advance specific channels they will use for sensitive requests. Any request arriving outside those channels triggers a mandatory hold and verification through a separate, trusted path.

"Employees can no longer rely on instinct to determine whether a message is legitimate," said T. Frank Downs, senior director of proactive services at BlueVoyant, a cybersecurity services provider based in New York. "We need to reinforce the idea that identity is confirmed through process and verification steps."

Pre-established verification phrases

Known only to authorized parties, these phrases confirm identity in high-stakes communications without relying on voice or video recognition.

Designated approvers

No single employee can authorize a high-risk transaction. A named secondary approver must confirm before funds move or access is granted.

The hard part: Executing consistently and under pressure

Policy design is the easier part of proof-based verification. Consistent execution under real conditions is where most programs fall short. Experts suggested the following best practices to improve governance and human follow-through:

Treat verification as a safety rail, not a judgment call

Deepfake video- and audio-based attacks, like traditional business email compromise, are designed to generate urgency at precisely the moment verification matters most.

"Verification isn't optional," Rothfuss said. "That means instituting proof-based controls that operate as non-negotiable safety rails, not something discretionary that employees can skip when they're feeling pressured or rushed. As with other less sophisticated scams, pressure and urgency is precisely the point."

Get executives on record before an incident occurs

Staff will not push back on out-of-channel requests unless leadership has made clear in advance that doing so is expected and part of the organization's cybersecurity culture.

"That requires defining the rules well in advance, so executives understand and encourage pushback, and employees don't feel forced to improvise under duress," Rothfuss said.

Reinforce continuously, not just once

Staff who understand how verification controls protect the organization are more likely to adopt them, but that understanding does not make the behavior automatic.

"Under pressure, people tend to fall back into old habits, which is exactly when verification is most important," Downs said. That makes continuous training and reinforcement a must.

Build a culture in which slowing down is the norm

Adoption ultimately depends on employees feeling confident that if they pause to verify requests, leaders will reward rather than penalize them for doing so.

"Organizations need to normalize 'see something, say something' behavior and make verification frictionless," said Mika Aalto, co-founder and CEO at Hoxhunt, a Helsinki-based human risk management vendor. "The real challenge is cultural: giving employees confidence that slowing down to verify is expected, supported and reinforced through human risk management practices."

Sean Michael Kerner is an IT consultant, technology enthusiast and tinkerer. He has pulled Token Ring, configured NetWare and been known to compile his own Linux kernel. He consults with industry and media organizations on technology issues.

Dig Deeper on Risk management