- › Detection training does not work, because the tells people are taught to look for are the ones each new model generation fixes first.
- › Every deepfake attack has to produce one thing to succeed: an action taken without the normal check, under time pressure, by someone who feels they cannot pause.
- › The defensive move is to make the check structural, so the question is never whether the voice sounded right.
- › Design the callback so it is faster than complying, or your people will route around it exactly when it matters.
- › Give the organization one rule everyone can recite, because a policy nobody remembers under pressure is a policy you do not have.
The finance manager who approved the transfer had been on the call for eleven minutes. She recognized the chief financial officer’s voice, she recognized two other faces in the meeting, and the request matched an acquisition she already knew was happening. She asked a clarifying question and got a reasonable answer.
Afterward, the incident report described her as having been deceived by a deepfake.
That framing is where most organizations go wrong on this topic, and it costs them the fix. She was not the failure point. She was a person doing her job inside a process that had exactly one control, and that control was her ability to recognize a colleague. Somebody built that process years ago when recognizing a colleague was a reliable thing to do.
It stopped being reliable, and nobody redesigned the process.
Why Detection Training Does Not Work
Security awareness programs love a checklist, and the deepfake checklist has been circulating for three years now. Watch for unnatural blinking. Look at the edges of the hair. Listen for flat affect and odd cadence. Ask them to turn their head to the side.
Every item on that list is a rendering artifact, and rendering artifacts are precisely what each new model generation fixes first, because they are the most visible thing to fix. The list you taught people in the spring describes a generation of tools that is already two behind.
There is a deeper problem underneath the technical one. You are asking a person to make a perceptual judgment about whether a face is real, under time pressure, while a person they believe is their boss waits for an answer. Human perception is not built to win that contest, and it is getting worse as the tools improve. Training people to try harder at an impossible task mostly teaches them to feel responsible when they lose it.
I have designed training programs for hundreds of people, and the ones that changed behavior all had the same property: they asked people to do something rather than to notice something. Noticing is not a skill you can reliably deploy at 4:45 on a Friday. Doing a specific concrete thing is.
What Every Deepfake Attack Needs
Strip the technology out and look at what the attacker is buying with it.
A synthetic voice or face gets them past one specific obstacle: the moment where the target would normally stop and confirm. That is the whole purchase. Everything else about the attack, the pretext, the urgency, the plausible business reason, has been in the social engineering playbook for decades and worked fine without any AI at all.
So the attack has three requirements, and all three have to hold:
A believable identity. The voice or the face. This is the part you cannot defeat and should stop trying to.
A reason to act now. The deal closes today, the wire has to go before the cutoff, the regulator is waiting, the chief executive is boarding a flight. Urgency is what prevents the pause where verification would happen.
A social cost to checking. This is the one nobody talks about and it is doing most of the work. Verifying your chief financial officer’s identity mid-call feels rude. It implies distrust. It costs the employee something socially, and organizations rarely make it clear that the cost is covered.
Remove any one of the three and the attack fails. You cannot remove the first. You can make the second irrelevant and the third free.
Design the Check Into the Process
The reframe that makes this tractable: stop asking whether your people can tell. Start asking whether it matters if they cannot.
If a wire cannot move without a callback to a number on file, then a perfect deepfake of your chief executive produces exactly nothing. The synthetic voice was excellent and the process did not care.
The callback, and why most of them fail
Almost every organization I talk to says they already have a callback rule. Almost none of them can tell me the last time somebody used it on a senior executive.
The rule exists on paper and dies in practice, for reasons that are entirely predictable if you look at what the organization rewards:
The number is hard to find. The employee has to go looking for a verified contact record while somebody waits, and looking takes ninety seconds they feel they do not have.
The callback goes to the person who is asking. If the only number your employee has is the one in the email signature, the callback is theater.
Nobody has ever seen it done. If no employee has ever watched a colleague verify an executive without consequence, they have no evidence the rule is real.
The person asking outranks them. This is the big one. A policy that requires a junior employee to impose friction on a senior one is a policy that requires that employee to spend social capital they do not have.
Make it faster than complying
The design principle that holds up in practice: the verified path has to be quicker and easier than the unverified one. If checking is slower than complying, people will comply, and they will be right to, because you built a system that punishes the safe behavior.
Concretely, that means a single place where verified contact numbers live, reachable in two clicks from the tool where the request arrives. It means the callback number is already attached to the approval workflow rather than something the employee has to source. It means the person can complete the check without leaving what they were doing.
Ninety seconds of friction is the difference between a control that works and one that exists.
Cover the social cost explicitly
Write it down, and then have leadership demonstrate it.
The sentence should be something like: no employee will ever be questioned for verifying a request, including a request from me, including when I am in a hurry. Put a name under it.
Then make it real. The most effective thing I have seen an executive team do on this took ten minutes: the chief executive called a finance manager, made a routine request, and when she verified him through the callback, he thanked her in the next all-hands by name and described exactly what she did. That story did more than a year of training, because it converted an abstract permission into an observed fact.
People do what they have seen work out well for someone like them. That is how anyone reads an unfamiliar situation.
The Controls Worth Building
Ranked roughly by what they return for what they cost.
1. One rule, recitable from memory
Pick the smallest possible rule that covers your highest-consequence action, and make it something every employee can say back to you without looking it up.
Something like: any request to move money or change payment details gets verified by calling a number from the directory, no exceptions, regardless of who is asking.
A policy people cannot recite under pressure is not a policy. It is a document.
2. A verified contact directory that is genuinely usable
The rule above depends entirely on this. If the directory is a spreadsheet somebody maintained until 2024, the rule fails on its first real test.
Somebody has to own it, it has to be current, and it has to be reachable from the phone, because that is where the call is happening.
3. Dual authorization on the irreversible things
Wires above a threshold, payment detail changes, credential resets for privileged accounts. Two people, and the second person has to be reached through a channel the first request did not come through.
This is the control that holds when everything else fails, including when the employee is fully convinced.
4. A code word for the household
For executives and their families, a shared phrase that verifies identity on a distress call. This is the specific defense against virtual kidnapping, which does not touch your company at all and destroys people anyway.
It takes one dinner conversation and it never expires.
5. A drill, not a test
Run the scenario. Tell people it is happening. Watch where the process breaks rather than watching who fails.
I am suspicious of the phishing simulation run to generate a scary percentage for a board slide, because the number is the deliverable rather than the improvement. A drill where you announce it, run it, and then fix the three places the workflow made verification awkward is worth more than a year of gotcha statistics, and people will help you build it.
What Changes for Leadership
The uncomfortable part of this topic is that the fix lands mostly on senior people, and senior people are the ones whose time it costs.
Your voice is the one being cloned, because you are the one whose requests do not get questioned. There are minutes of you speaking publicly on a conference recording somewhere. That is not a mistake anyone made. It is the job.
What follows from it is that the people below you need explicit, repeated, demonstrated permission to slow you down. Every time an executive expresses irritation at being verified, the story travels and the control weakens across the whole organization. Every time one publicly appreciates it, the same thing happens in the other direction.
The related material worth reading alongside this: why executives are uniquely vulnerable to social engineering covers the targeting logic, deepfake vishing covers the voice-call version in technical detail, and deepfake crisis management covers what to do when the synthetic content is of you and it is already public. The wider strategic picture sits in countering AI-powered social engineering and the C-suite guide to AI-powered disinformation. All of it assumes the four surfaces described in the executive threat model.
Where to Start Tomorrow
Take the single most expensive irreversible action anyone at your company can take. Usually that is a wire.
Walk the actual path a request travels, with the person who would receive it, and find the exact moment where verification would have to happen. Then ask that person what would make checking easier than not checking.
They will tell you. They have thought about it more than you have, because it is their name on the approval.
The finance manager in the first paragraph did nothing wrong. She was standing in a process that asked her to be a detector, and no person is a good detector. Give her a callback number she can reach in two clicks and permission from the top to use it, and the same call ends in ninety seconds with nothing happening at all.
Want to know where verification breaks in your actual workflow? Contact Grab The Axe for a behavioral security assessment, or start with our free Human Attack Surface Score.
With a dual background in I/O Psychology (PhD Candidate) and Business Management (MBA), Marie bridges the gap between clinical rigor and operational strategy. She oversees B2B relations, compliance, and the 'business' of risk management.
View Author Page →