Gartner said nearly half of CISOs surveyed had seen at least one deepfake incident in the past 12 months, with 41% reporting one in an audio call and 36% in a video call. The findings came from a March-to-May 2026 survey of 297 senior cybersecurity leaders, and Gartner used the London launch of its security summit on September 22 to push the message that incident response has to catch up.
The mechanism is simple: a believable voice or face can make a request feel like it came from a boss, colleague, or vendor, long enough to trigger a password reset, privileged access change, or payment approval. That means the weak point is less the fake media itself than the recovery and approval path it unlocks, especially where weak verification still gets treated as routine.
For organizations that rely on account recovery, privileged access, or payment workflows, the exposure now sits in identity controls and post-login abuse detection, not just in phishing awareness. If those paths are loosely governed, a deepfake can become the front door to access that looked legitimate at the moment it was granted.
CISOs Must Update Incident Response Playbooks for Multimodal Deepfakes
Gartner warns that CISOs must update incident response playbooks as AI-powered deepfakes make social engineering attacks more convincing and harder to detect