Security

Gartner: 41% of Security Chiefs Have Experienced Deepfake Attacks

TECHWORLD ·

✦ AI Summary

In Gartner's survey, 41% of 297 CISOs said they had experienced a deepfake social engineering attack in an employee voice call in the past 12 months, while 36% said they had experienced an attack in a video call. Gartner said AI has increased the frequency, personalization, and persuasiveness of social engineering attacks while reducing the reliability of traditional detection indicators. Gartner identified three key measures: shifting away from standardized training, strengthening employee identity and recovery systems, and improving detection and response systems for AI-mediated threats.

Gartner released the results of a survey of CISOs. The survey was conducted from March to May and included 297 senior cybersecurity executives holding CISO or equivalent roles. The results showed that 41% of CISOs had experienced at least one social engineering attack exploiting a deepfake of an employee's voice call in the past 12 months. Another 36% said they had experienced the same type of attack in video calls.

The survey found that AI has driven an increase in the frequency of social engineering attacks. It also showed that AI has increased the personalization of such attacks and made them more convincing. At the same time, it has lowered the reliability of traditional indicators of detection.

Craig Porter, a Gartner director analyst, said attackers are carrying out multichannel attacks that combine phishing, business email compromise, synthetic media, and collected personal data. He forecast that most attacks in the future will rely on users, stolen credentials, weak recovery procedures, and familiar tactics.

Craig Porter emphasized that CISOs need to respond to AI-based social engineering threats. He called for a systematic response such as identity and access risk assessments.

The survey also showed the frequency of the threat by finding that many CISOs had encountered multiple forms of social engineering attacks over the past year. Among participating CISOs, 79% said they had experienced at least one email phishing, spear phishing, or business email compromise incident in the past 12 months. The share reporting vishing and smishing incidents was also 58%.

In response, Gartner outlined three key measures to counter AI-based social engineering attacks. The first is to shift from standardized training to adaptive security behavior and culture programs. The second is to strengthen employee identity and recovery systems against impersonation attacks. The third is to improve detection and response systems for AI-mediated threats.

On the training side, Gartner proposed making secure verification procedures for important requests a basic rule of conduct, rather than focusing on 'spotting fakes,' as part of the shift away from standardized training.

Organizations need to train employees and approvers to respond to high-risk requests in order to counter threats using AI and impersonation. The training should apply regardless of the channel used and should cover email, voice, video, collaboration tools, and AI applications. It should also teach pause, verify, and report procedures, and simulation exercises should be used to check whether verification and reporting processes for suspected AI-related activity actually work.

Organizations need to strengthen employee identity and recovery systems to prepare for impersonation attacks. In particular, they should protect critical business processes, including account recovery, privileged access, and payment approvals. To do so, they need phishing-resistant authentication, risk-based identity controls, and trusted channels. They also need controls that can detect misuse of identity information even after a normal login or password reset.

In addition, organizations need to improve detection and response systems for AI-mediated threats. To strengthen threat detection capabilities, they should analyze suspicious contact and impersonation reports together with account recovery history, new device access, privilege changes, and financial transaction information.

Incident response systems should be supplemented so they cover not only existing risks but also newly emerging AI-related threat types, and that requires updating incident response manuals. The scope of the manuals should be expanded so they can address multimodal impersonation, manipulated AI recommendations, compromised or misused AI agents, and agents operating outside defined boundaries.

Source: TECHWORLD · Lee Gwang-jae
Original: https://www.epnc.co.kr/news/articleView.html?idxno=407407

References

This article was produced with the help of an automated content generation algorithm.


Source: TECHWORLD

View original

This article was summarized and organized by BizCrush based on the original article from TECHWORLD. For exact quotations and full details, please refer to the original article.