Find the Right GRC Solution

Search and compare GRC technology built for the problems you’re trying to solve

When Seeing Is No Longer Believing: Deepfakes Are Becoming a Governance Problem

When Seeing Is No Longer Believing: Deepfakes Are Becoming a Governance Problem

By
Key Takeaways
  • Deepfakes Challenge Identity-Based Controls: Increasingly convincing AI-generated voices and video can undermine business processes that rely on recognizing or visually confirming an authorized individual.
  • A Control Can Exist and Still Fail: Organizations need to assess not only whether controls are documented and followed, but whether they remain effective as technology changes the underlying risk.
  • Human Behavior Remains Central to the Threat: Deepfake attacks can exploit authority, urgency, and employees’ natural reluctance to challenge senior leaders.
  • Verification Practices May Need to Evolve: Sensitive approvals and high-risk requests may require stronger methods of confirming identity rather than relying solely on voice or video.
  • Risk Management Should Remain Proportionate: Organizations do not need to distrust every interaction, but they should reconsider verification where impersonation could create significant exposure.
Deep Dive

For a long time, seeing someone or hearing their voice gave us a reasonable level of confidence that we knew who we were dealing with. If your manager called, you recognized their voice. If a senior executive joined a video meeting, you could see them on the screen. There was usually little reason to question whether the person you were speaking to was actually who they claimed to be.

Artificial intelligence is starting to challenge something we have taken for granted for years: our ability to trust what we see and hear. Deepfakes are becoming increasingly convincing. AI can now recreate someone's voice, appearance and mannerisms using information that may already be publicly available. What was once relatively easy to spot is becoming much harder to distinguish from the real thing.

From a cybersecurity perspective, that is concerning. From a GRC perspective, it raises another question: are some of the controls organizations rely on still effective when identity itself can be convincingly imitated? We have already seen what this can look like in practice.

In one widely reported case, an employee joined what appeared to be a video conference with the company's Chief Financial Officer and other colleagues. The people on the call looked and sounded genuine, but they were deepfake recreations. The employee was ultimately convinced to authorize payments worth millions.

It is easy to look at an incident like this purely as sophisticated fraud. From a GRC perspective, however, there is another issue worth considering. The trust that supported the business process had been manipulated. A control can exist and the risk can still change.

A lot of my day-to-day work in GRC involves reviewing risks, business requests, changes and security exceptions. Although the requests can be very different, the questions I ask are often quite similar. What is being requested and why is it needed? What could go wrong? Who has approved it? What controls are already in place? How long is it needed for? And who owns the remaining risk?

I won't always have the technical answer, nor do I need to. There are technical security teams with the expertise to assess how a particular solution or control works. My focus from a risk perspective is understanding the exposure, whether the proposed controls are appropriate and whether the business is making an informed decision.

Deepfakes introduce another consideration into that process: how confident are we that the person providing the instruction or approval is actually that person? Consider a sensitive activity that requires approval from a senior manager. The organization has a documented process, and the employee follows it. They speak to someone they genuinely believe is authorized to approve the request and keep evidence of that approval.

On paper, the control has worked. The process has been followed, and the approval exists. But what if the person providing the approval wasn't actually that person?

This is why I think organizations need to look beyond whether a control simply exists and consider whether it remains effective against the threats we face today. A control can be well documented and consistently followed while changes in technology alter the risk around it.

Risk doesn't stand still, and neither should the controls used to manage it.

Deepfakes Exploit More Than Technology

One of the things that makes deepfakes particularly interesting from a risk perspective is that the technology is only one part of the attack. The other part is human behavior.

Imagine receiving a video call from someone who looks and sounds exactly like your CEO. There is an urgent payment that needs to be made. Or perhaps someone who appears to be a senior IT leader needs privileged access because of a major incident. The normal process cannot be followed because they are travelling, and the request needs to be dealt with immediately.

The person is right there on the screen explaining the situation. Would you challenge them?

This is where authority and urgency can become powerful tools for an attacker. We already train employees to question unusual emails, unexpected links and requests for passwords. Challenging an unfamiliar email, however, is very different from challenging someone you believe is your Chief Executive while looking directly at them on a video call.

Deepfakes are changing the social engineering landscape, and the way organizations manage that risk will need to evolve with it.

Verification May Need to Change

This doesn't mean organizations should suddenly distrust every video call or introduce additional controls around every business activity. Risk management needs to remain proportionate.

The GRC Report is your premier destination for the latest in governance, risk, and compliance news. As your reliable source for comprehensive coverage, we ensure you stay informed and ready to navigate the dynamic landscape of GRC. Beyond being a news source, the GRC Report represents a thriving community of professionals who, like you, are dedicated to GRC excellence. Explore our insightful articles and breaking news, and actively participate in the conversation to enhance your GRC journey.

🔒
Cancel anytime
Full archive access
Custom alerts

Oops! Something went wrong