Wednesday, September 23, 2026

Sign In


Home USA Innovation Cisco Gartner Survey: 41% of CISOs R...

Gartner Survey: 41% of CISOs Report Deepfake Social Engineering Incidents


Cisco

Gartner Survey: 41% of CISOs Report Deepfake Social Engineering Incidents

A Gartner survey found that 41% of CISOs reported at least one deepfake-related social engineering incident during an employee audio call in the past 12 months.

  • 41% of CISOs reported a deepfake-related incident during an employee audio call

  • 36% reported a deepfake incident involving a video call

  • Email phishing and business email compromise remained the most commonly reported incidents

  • Gartner recommends adaptive security training and stronger identity controls

  • Security teams are being urged to prepare for AI-mediated impersonation and social engineering

AI is making social engineering attacks more believable with the help of deepfake audio and video content, which presents new cybersecurity challenges.

According to a Gartner survey of 297 high-ranking cybersecurity professionals, 41% of CISOs reported having at least one social engineering incident involving deepfakes during employee audio calls within the past 12 months. Another 36% reported a social engineering incident involving deepfakes during video calls.

Conducted between March and May 2026, the survey showed that AI is making social engineering attacks more numerous, personalised, and believable.

Traditional methods of attack still remain widespread. Seventy-nine percent of CISOs reported at least one incident involving email phishing, spear-phishing, or business email compromise in the previous year. At the same time, 58% of CISOs reported at least one vishing or smishing attack.

According to Gartner, attackers can combine phishing, business email compromise, synthetic media, and personal information collected through several channels. As a result, AI-driven social engineering attacks are becoming a growing threat to companies.

Gartner advises CISOs to focus on three areas: adaptive security training, stronger workforce identity controls, and better detection and response. Employees need to be trained to verify high-risk requests rather than simply trying to detect fake content.

Firms should also improve account recovery, privileged access, and payment authorisation through phishing-resistant authentication and risk-based identity controls.

Organisations need to prepare incident response procedures for cases involving multimodal impersonation, manipulated AI recommendations, and compromised or misused AI agents. These measures may become increasingly relevant as deepfake cyberattacks on organisations evolve alongside the wider use of AI.

Business Honor observes that Gartner’s findings highlight how AI-driven impersonation is expanding the cybersecurity challenge from conventional phishing to increasingly sophisticated social engineering attacks.

FAQs

What percentage of CISOs reported deepfake social engineering incidents?
Gartner found that 41% of surveyed CISOs reported at least one deepfake-related incident during an employee audio call.

How many CISOs participated in the Gartner survey?
The survey included 297 senior cybersecurity leaders, including CISOs and equivalent roles.

What other social engineering attacks were reported?
Seventy-nine percent reported phishing, spear-phishing or business email compromise, while 58% reported vishing or smishing incidents.

How can companies respond to AI-driven social engineering?
Companies can strengthen verification practices, use phishing-resistant authentication, improve identity controls and update incident response processes.

Why are deepfakes a cybersecurity concern?
Deepfake audio and video can make impersonation attempts appear more credible, reducing the reliability of traditional detection cues.


Comments

0 Comments

Business News


Recommended News

×

Subscribe To Our Newsletter

email

please enter valid email

×
tankyu


Latest Magazine