Skip to main content
Emerging Threats

Gartner Warns CISOs to Update Playbooks for Multimodal Deepfake Threats

Empty conference room with large screen and single chair facing it.

"Almost half of CISOs have reported at least one deepfake incident in the past 12 months," a striking finding Gartner released as the Security & Risk Management Summit opened in London on September 22.

Survey scope and headline findings

Gartner published the results of its AI-driven Social Engineering Attacks report at the opening of the Summit after surveying 297 senior cybersecurity leaders. The study, conducted between March and May 2026, concluded that AI is increasing the volume, personalization and credibility of social engineering attacks while reducing the reliability of familiar detection cues.

How deepfakes and traditional social engineering are showing up

The report draws a clear distinction between the resurgence of known phishing vectors and the rise of AI-enabled impersonation. More than four in ten respondents — 41% — said they experienced at least one social engineering incident involving a deepfake during an employee audio call in the previous 12 months; 36% reported at least one during a video call. At the same time, 79% of CISOs surveyed reported at least one email phishing, spearphishing, or business email compromise (BEC) incident in the last 12 months, and 58% reported at least one vishing (voice phishing) or smishing (SMS phishing) incident.

Craig Porter: treat AI-driven social engineering like identity and access risk

Craig Porter, director analyst at Gartner, framed the problem in terms of identity and access management. He warned that "as most attacks will continue to rely on users, stolen credentials, weak recovery processes and familiar technical methods, CISOs must use the same discipline used to assess identity and access risks to combat AI-driven social engineering threats." That comparison underlines Gartner’s central argument: defensive posture and controls that were designed for credential-based fraud must now be applied with equal rigor to multimodal impersonation.

Three concrete measures Gartner recommends for CISOs

  • Recast secure behavior and culture programs. Porter’s team recommends shifting training away from teaching employees to "spot the fake" and toward making secure verification the standard for consequential requests. That includes simulations and clear expectations to pause, verify, and report suspicious activity across all communication channels.
  • Harden high-value workflows. The report says organizations should protect account recovery, privileged access, and payment authorization with phishing-resistant authentication, risk-based identity controls, trusted verification channels, and post‑authentication measures that detect identity abuse after login or password resets.
  • Correlate signals and update playbooks. Security operations should correlate impersonation reports and suspicious communications with account recovery events, new devices, privilege changes, and financial transactions. Equally important: incident response playbooks must be updated to address multimodal impersonation, manipulated AI recommendations, and compromised, misused, or out‑of‑bounds AI agents.

What this means for technologists, procurement leaders, and end users

  • Technologists and security teams will need to operationalize the correlation guidance: tune identity‑and‑access tooling to flag suspicious recovery events, and adapt detection analytics to span email, SMS, voice, and video channels.
  • Procurement and vendor managers should require phishing‑resistant authentication and trusted verification channels when buying or renewing services that touch account recovery, privileged access, or payment flows.
  • End users should expect training and simulations that emphasize verification habits — pause, verify, and report — rather than relying on the ability to "spot" synthetic audio or video.

Gartner’s survey data underline a simple but urgent point: AI has amplified both old and new social engineering techniques, and organizations that treat multimodal impersonation as a people problem alone will fall short. The firm’s prescription is operational and specific — shift culture, harden identity pathways, and revise incident response playbooks — leaving CISOs with a clear next step: translate these recommendations into control objectives, detection rules, and tabletop exercises before the next high‑stakes impersonation surfaces.

Original story