
Deepfakes are becoming harder for enterprise security teams to treat as an edge case. The Gartner deepfake survey found that 41% of CISOs reported at least one social engineering incident involving a deepfake during an employee audio call in the past 12 months. Another 36% reported a deepfake incident during a video call.
The findings come from a March-May 2026 survey of 297 senior cybersecurity leaders. More broadly, the survey shows how AI is making social engineering more convincing, more personalised and harder to detect using familiar warning signs.
Enterprise security faces a wider social engineering problem
Deepfakes are only one part of a broader threat picture. Seventy-nine percent of surveyed CISOs reported at least one phishing, spear-phishing or business email compromise incident in the past year. Meanwhile, 58% reported a vishing or smishing incident.
This matters because attackers can now combine different approaches rather than relying on a single channel. Gartner said phishing, business email compromise, synthetic media and aggregated personal information can be used together.
For enterprise security teams, the challenge is therefore moving beyond simply identifying whether a message, voice or video is fake.
Growing deepfake risk changes how employees verify requests
Gartner recommends shifting security training away from simply teaching employees to “spot the fake.” Instead, organisations should make secure verification a normal response to high-risk requests.
That means encouraging employees and approvers to pause, verify and report suspicious requests whether they arrive through email, voice, video, collaboration tools or AI applications. Workforce simulations can also test how employees respond to AI-driven suspicious events.
Deepfake CISO threats now connect identity and recovery
The survey also points to identity and account recovery as important areas of defence. Gartner recommends phishing-resistant authentication, risk-based identity controls and trusted verification channels for sensitive activities such as account recovery, privileged access and payment authorisation.
Detection also needs to connect signals across systems. Suspicious communications can be correlated with account recovery events, new devices, privilege changes and financial transactions.
Read More:
Shivaami and Google Cloud tackle multi-agent enterprise security
Vertiv acquires King Environmental to strengthen EMEA cooling
Outcome-based managed services: The high stakes of owning business outcomes
/dqc/media/agency_attachments/2026/08/21/2026-08-21t061716244z-dq-channels-logojpg-2026-08-21-11-47-17.jpeg)
/dqc/media/media_files/2026/09/10/dq-channels-whatsapp-2026-09-10-17-07-48.png)
Follow Us