Deepfakes and AI phishing in business: how to adapt your email controls and procedures

Share

Introduction - Deepfakes and AI Phishing

Phishing is no longer just a “bad email” full of typos. With AI, the attack becomes more credible, more personalized, and sometimes multimodal: email + SMS + phone call + a Teams message. The real change isn’t that “everyone will get fooled,” but that fraudsters can industrialize persuasion.

Deepfakes (voice, video, images) and CEO fraud (executive impersonation fraud) aren’t new, but they’re becoming more accessible. The right reflex isn’t panic: it’s aligning your technical controls and your human procedures with a simple reality.

In this guide, we’re not going to tell you to “be vigilant.” We’re going to talk deliverables: what you can put in place, verify, audit, and prove to reduce the risk of these kinds of attacks.

What you will learn in this guide

  • What really changes with AI (and what doesn’t)
  • The email controls that block impersonation and reduce impact
  • Anti-deepfake procedures (Finance, HR, IT) that prevent costly mistakes
  • A mini incident playbook if a message still gets through
  • How to justify ROI (risk reduction + time saved)

The diagnostic

If you answer “yes” to 2 or more questions, you have a priority initiative:

  • Do payment requests/bank account changes arrive by email?
  • Are approvals (purchases, wire transfers, admin access) done through a single channel?
  • Does your domain have DMARC set to quarantine or reject (not just none)?
  • Can your users receive “internal” emails from outside (spoofing/impersonation)?
  • Do you have a mandatory call-back process for sensitive requests?

What changes with AI (and what doesn’t)

What changes:

  • Personalization: the attacker can write like your CFO, mimic your tone, and use public details (LinkedIn, press releases, org charts).
  • Speed: generating variants, A/B testing, adapting in real time.
  • Multimodal delivery: email + cloned voice + “proof” (invoice, screenshot, video).

What doesn’t change:

  • Attacks still exploit the same levers: urgency, authority, confidentiality, fear, opportunity.
  • Defense remains a duo: technical controls + procedures + training.

The 7 anti-deepfake deliverables (the “proof” checklist)

  • DMARC in quarantine, then reject (with report monitoring)
  • Anti-impersonation protection (domains, VIPs, vendors)
  • Stronger MFA + conditional access policies for at-risk accounts
  • A “two-channel” process for any sensitive request (payment, access, data)
  • A documented, non-bypassable call-back procedure
  • Logging + evidence retention (email headers, logs, messages)
  • A response plan (who does what, when, and how to communicate)

Email controls: what really matters

1) SPF, DKIM, DMARC (and especially DMARC)

  • SPF: authorizes servers to send for your domain.
  • DKIM: cryptographically signs messages.
  • DMARC: tells what to do if SPF/DKIM fail and provides reports.

The goal: move from “visibility” to “blocking.”

2) Anti-impersonation and VIP protection

  • Protect executive names/aliases (CEO/CFO/VP) against impersonation.
  • Add critical vendors (bank, payroll, firms) into protection rules.

3) Reduce attack surface: attachments, links, macros

  • Block/limit high-risk file types.
  • Use link rewriting/inspection mechanisms.
  • Standardize quarantine and the release procedure (who approves? within what timeframe?).

4) Detection + triage: making the team effective

  • The goal isn’t “0 phishing” (impossible), but rather to reduce inbound exposure, speed up detection, and limit impact.

Identity and access controls: where deepfakes become dangerous

deepfake « marche » mainly when it enables:

  • An MFA access reset;
  • An approval;
  • Administrator access;
  • Exfiltration.

1) MFA : MFA: aim for phishing resistance

  • Avoid approaches that are easy to bypass (MFA fatigue, intercepted codes).
  • Strengthen privileged accounts and sensitive roles.

2) Conditional access and risk segmentation

  • Stricter policies for: Finance, HR, IT admin.
  • Controls based on compliant device, location, session risk.

3) Break-glass accounts and governance

  • Documented emergency accounts.
  • Limited, monitored, tested access.

Anti-deepfake procedures: the real human “firewall”

Rule 1 – “Two channels” for any sensitive request

Examples:

  • Email + validation via Teams/phone on a known number.
  • Teams message + confirmation via internal email.

Rule 2 – Mandatory call-back (using a reference number)

  • Never call back the number provided in the message.
  • Use a number from an internal reference source (CRM, directory, vendor record).

Rule 3 – Separate request and approval

  • One person initiates, another approves.
  • Exceptions must be rare, documented, and audited.

Rule 4 – “Stop the line” with no penalty

  • If someone doubts, they must be able to stop the process without being blamed for a “delay.”

Mini incident playbook (if a message still gets through)

  1. Preserve evidence: full email (headers), attachments, links, screenshots.
  2. Block: sender, domain, URLs, transport rules if needed.
  3. Reset / secure: targeted accounts, sessions, MFA, passwords.
  4. Assess impact: data, payments, access.
  5. Communicate: a short internal message (what to do / what to ignore), without panic.
  6. Improve: technical rule + procedure update + micro-training.

Relevant additional resource to consult on this topic: NIST – Incident Response Recommendations and Considerations for Cybersecurity Risk Management

Common mistakes (and how to avoid them)

  • Relying only on awareness: without DMARC and procedures, AI wins.
  • Allowing “VIP” exceptions: that’s exactly what deepfakes target.
  • Having an “optional” call-back: it must be non-bypassable.
  • Confusing speed with effectiveness: 10 minutes of validation is better than 10 days of crisis.

Mini case study

A company receives an “urgent” email from the CFO requesting a change of banking details, followed by a voice message (very credible voice) confirming the request.

The finance team applies the “two-channel” rule: they trigger a call-back using the CFO’s number from the internal directory. The CFO denies the request.

Result :

  • No wire transfer;
  • Evidence preserved;
  • Blocking of the spoofed domain;
  • DMARC update and anti-impersonation rules.

Your next steps

  • Check your DMARC posture (goal: quarantine, then reject).
  • Define 5 “sensitive” requests (payment, banking details, admin access, HR data, purchasing) and enforce the “two channels + call-back” rule.
  • Test a deepfake scenario internally (table-top): who validates? which logs? which messages?
  • Contact us; describe your context (size, tools, risks) and we’ll propose a deliverables-based knowledge uplift plan.

Certification pathway & recommended training

  • Security foundations (baseline): CompTIA Security+ (to structure controls, risk, best practices)
  • Detection & response (blue team / SOC): CompTIA CySA+ (triage, investigation, response)
  • Assessment & testing (audit/pentest): CompTIA PenTest+ (evidence, actionable report, remediation)
  • Network basics (if it’s a weak spot): CompTIA Network+ (DNS, routing, segmentation, troubleshooting)

FAQ

Yes. The cost of entry is decreasing, and attacks often target payment and approval processes.

DMARC helps a lot, but you also need anti-impersonation protections and procedures (2 channels, callback).

It’s difficult. The right approach is procedural: validation on an independent channel, using a reference number.

DMARC (quarantine/reject), VIP spoofing protection, and “2 channels + call-back” rule for sensitive requests.

Preserve evidence, isolate/control the account, revoke sessions, analyze the impact, then strengthen rules and training.

Link each control to a deliverable: reduced risk of fraud, reduced triage time, fewer costly incidents.

Explore more articles

Our website uses cookies to personalize your browsing experience. By clicking ‘I accept,’ you consent to the use of cookies.