{"id":59651,"date":"2026-04-02T10:41:19","date_gmt":"2026-04-02T10:41:19","guid":{"rendered":"https:\/\/www.eccentrix.ca\/?p=59651"},"modified":"2026-06-29T12:00:13","modified_gmt":"2026-06-29T12:00:13","slug":"deepfakes-and-ai-phishing","status":"publish","type":"post","link":"https:\/\/www.eccentrix.ca\/en\/eccentrix-corner\/deepfakes-and-ai-phishing\/","title":{"rendered":"Deepfakes and AI phishing in business: how to adapt your email controls and procedures"},"content":{"rendered":"\t\t<div data-elementor-type=\"wp-post\" data-elementor-id=\"59651\" class=\"elementor elementor-59651 elementor-59628\" data-elementor-post-type=\"post\">\n\t\t\t\t<div class=\"elementor-element elementor-element-1a96984f e-flex e-con-boxed e-con e-parent\" data-id=\"1a96984f\" data-element_type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-58bac4a elementor-widget elementor-widget-heading\" data-id=\"58bac4a\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Introduction - Deepfakes and AI Phishing<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-4e9eab47 elementor-widget elementor-widget-text-editor\" data-id=\"4e9eab47\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>Phishing is no longer just a \u201cbad email\u201d full of typos. With AI, the attack becomes more credible, more personalized, and sometimes multimodal: email + SMS + phone call + a Teams message. The real change isn\u2019t that \u201ceveryone will get fooled,\u201d but that fraudsters can industrialize persuasion.<\/p><p>Deepfakes (voice, video, images) and CEO fraud (executive impersonation fraud) aren\u2019t new, but they\u2019re becoming more accessible. The right reflex isn\u2019t panic: it\u2019s aligning your technical controls and your human procedures with a simple reality.<\/p><p>In this guide, we\u2019re not going to tell you to \u201cbe vigilant.\u201d We\u2019re going to talk deliverables: what you can put in place, verify, audit, and prove to reduce the risk of these kinds of attacks.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-bc4d7e8 elementor-widget elementor-widget-heading\" data-id=\"bc4d7e8\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">What you will learn in this guide<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-2278df5 elementor-widget elementor-widget-text-editor\" data-id=\"2278df5\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<ul><li>What really changes with AI (and what doesn\u2019t)<\/li><li>The email controls that block impersonation and reduce impact<\/li><li>Anti-deepfake procedures (Finance, HR, IT) that prevent costly mistakes<\/li><li>A mini incident playbook if a message still gets through<\/li><li>How to justify ROI (risk reduction + time saved)<\/li><\/ul>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-59353c0 elementor-widget elementor-widget-heading\" data-id=\"59353c0\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">The diagnostic<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-e978d44 elementor-widget elementor-widget-text-editor\" data-id=\"e978d44\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>If you answer \u201cyes\u201d to 2 or more questions, you have a priority initiative:<\/p><ul><li>Do payment requests\/bank account changes arrive by email?<\/li><li>Are approvals (purchases, wire transfers, admin access) done through a single channel?<\/li><li>Does your domain have DMARC set to <em>quarantine<\/em> or <em>reject<\/em> (not just none)?<\/li><li>Can your users receive \u201cinternal\u201d emails from outside (spoofing\/impersonation)?<\/li><li>Do you have a mandatory call-back process for sensitive requests?<\/li><\/ul>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-a5dd235 elementor-widget elementor-widget-heading\" data-id=\"a5dd235\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">What changes with AI (and what doesn\u2019t)<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-28554e7 elementor-widget elementor-widget-text-editor\" data-id=\"28554e7\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><strong>What changes:<\/strong><\/p><ul><li><strong>Personalization:<\/strong> the attacker can write like your CFO, mimic your tone, and use public details (LinkedIn, press releases, org charts).<\/li><li><strong>Speed:<\/strong> generating variants, A\/B testing, adapting in real time.<\/li><li><strong>Multimodal delivery:<\/strong> email + cloned voice + \u201cproof\u201d (invoice, screenshot, video).<\/li><\/ul><p>What doesn\u2019t change:<\/p><ul><li><strong>Attacks still exploit the same levers:<\/strong> urgency, authority, confidentiality, fear, opportunity.<\/li><li><strong>Defense remains a duo:<\/strong> technical controls + procedures + training.<\/li><\/ul>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-3b980f5 elementor-widget elementor-widget-heading\" data-id=\"3b980f5\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">The 7 anti-deepfake deliverables (the \u201cproof\u201d checklist)<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-d7e403f elementor-widget elementor-widget-text-editor\" data-id=\"d7e403f\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<ul><li>DMARC in quarantine, then reject (with report monitoring)<\/li><li>Anti-impersonation protection (domains, VIPs, vendors)<\/li><li>Stronger MFA + conditional access policies for at-risk accounts<\/li><li>A \u201ctwo-channel\u201d process for any sensitive request (payment, access, data)<\/li><li>A documented, non-bypassable call-back procedure<\/li><li>Logging + evidence retention (email headers, logs, messages)<\/li><li>A response plan (who does what, when, and how to communicate)<\/li><\/ul>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-9ea72ee elementor-widget elementor-widget-heading\" data-id=\"9ea72ee\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">Email controls: what really matters<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-4150c60 elementor-widget elementor-widget-text-editor\" data-id=\"4150c60\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><strong>1) SPF, DKIM, DMARC (and especially DMARC)<\/strong><\/p><ul><li><a href=\"https:\/\/en.wikipedia.org\/wiki\/Sender_Policy_Framework\" target=\"_blank\" rel=\"noopener\">SPF<\/a>: <span data-slate-fragment=\"JTVCJTdCJTIyY2hpbGRyZW4lMjIlM0ElNUIlN0IlMjJ0ZXh0JTIyJTNBJTIyYXV0aG9yaXplcyUyMHNlcnZlcnMlMjB0byUyMHNlbmQlMjBmb3IlMjB5b3VyJTIwZG9tYWluLiUyMiU3RCU1RCUyQyUyMnR5cGUlMjIlM0ElMjJwJTIyJTJDJTIyaW5kZW50JTIyJTNBMSUyQyUyMmxpc3RTdHlsZVR5cGUlMjIlM0ElMjJkaXNjJTIyJTJDJTIyaWQlMjIlM0ElMjJ1NjBMTC0xNnNGJTIyJTdEJTVE\">authorizes servers to send for your domain.<\/span><\/li><li><a href=\"https:\/\/en.wikipedia.org\/wiki\/DomainKeys_Identified_Mail\" target=\"_blank\" rel=\"noopener\">DKIM<\/a>: <span data-slate-fragment=\"JTVCJTdCJTIyY2hpbGRyZW4lMjIlM0ElNUIlN0IlMjJ0ZXh0JTIyJTNBJTIyY3J5cHRvZ3JhcGhpY2FsbHklMjBzaWducyUyMG1lc3NhZ2VzLiUyMiU3RCU1RCUyQyUyMnR5cGUlMjIlM0ElMjJwJTIyJTJDJTIyaW5kZW50JTIyJTNBMSUyQyUyMmxpc3RTdHlsZVR5cGUlMjIlM0ElMjJkaXNjJTIyJTJDJTIybGlzdFN0YXJ0JTIyJTNBMiUyQyUyMmlkJTIyJTNBJTIyVl9Nd09adUxVSiUyMiU3RCU1RA==\">cryptographically signs messages.<\/span><\/li><li><a href=\"https:\/\/en.wikipedia.org\/wiki\/DMARC\" target=\"_blank\" rel=\"noopener\">DMARC<\/a>: <span data-slate-fragment=\"JTVCJTdCJTIyY2hpbGRyZW4lMjIlM0ElNUIlN0IlMjJ0ZXh0JTIyJTNBJTIydGVsbHMlMjB3aGF0JTIwdG8lMjBkbyUyMGlmJTIwU1BGJTJGREtJTSUyMGZhaWwlMjBhbmQlMjBwcm92aWRlcyUyMHJlcG9ydHMuJTIyJTdEJTVEJTJDJTIydHlwZSUyMiUzQSUyMnAlMjIlMkMlMjJpbmRlbnQlMjIlM0ExJTJDJTIybGlzdFN0eWxlVHlwZSUyMiUzQSUyMmRpc2MlMjIlMkMlMjJsaXN0U3RhcnQlMjIlM0EzJTJDJTIyaWQlMjIlM0ElMjJrRDhXdXpQOWI3JTIyJTdEJTVE\">tells what to do if SPF\/DKIM fail and provides reports.<\/span><\/li><\/ul><p><span data-slate-fragment=\"JTVCJTdCJTIyY2hpbGRyZW4lMjIlM0ElNUIlN0IlMjJ0ZXh0JTIyJTNBJTIyVGhlJTIwZ29hbCUzQSUyMG1vdmUlMjBmcm9tJTIwJUUyJTgwJTlDdmlzaWJpbGl0eSVFMiU4MCU5RCUyMHRvJTIwJUUyJTgwJTlDYmxvY2tpbmcuJUUyJTgwJTlEJTIyJTdEJTVEJTJDJTIydHlwZSUyMiUzQSUyMnAlMjIlMkMlMjJpZCUyMiUzQSUyMnM2WVYzOU9lMHMlMjIlN0QlNUQ=\">The goal: move from \u201cvisibility\u201d to \u201cblocking.\u201d<\/span><\/p><p><strong>2) <span data-slate-fragment=\"JTVCJTdCJTIyY2hpbGRyZW4lMjIlM0ElNUIlN0IlMjJ0ZXh0JTIyJTNBJTIyQW50aS1pbXBlcnNvbmF0aW9uJTIwYW5kJTIwVklQJTIwcHJvdGVjdGlvbiUyMiU3RCU1RCUyQyUyMnR5cGUlMjIlM0ElMjJoMyUyMiUyQyUyMmlkJTIyJTNBJTIyWmRSV1RrT1VQNSUyMiU3RCU1RA==\">Anti-impersonation and VIP protection<\/span><\/strong><\/p><ul><li>Protect executive names\/aliases (CEO\/CFO\/VP) against impersonation.<\/li><li>Add critical vendors (bank, payroll, firms) into protection rules.<\/li><\/ul><p><strong>3) <span data-slate-fragment=\"JTVCJTdCJTIyY2hpbGRyZW4lMjIlM0ElNUIlN0IlMjJ0ZXh0JTIyJTNBJTIyUmVkdWNlJTIwYXR0YWNrJTIwc3VyZmFjZSUzQSUyMGF0dGFjaG1lbnRzJTJDJTIwbGlua3MlMkMlMjBtYWNyb3MlMjIlN0QlNUQlMkMlMjJ0eXBlJTIyJTNBJTIyaDMlMjIlMkMlMjJpZCUyMiUzQSUyMmRic3lVcU1YSEYlMjIlN0QlNUQ=\">Reduce attack surface: attachments, links, macros<\/span><\/strong><\/p><ul><li>Block\/limit high-risk file types.<\/li><li>Use link rewriting\/inspection mechanisms.<\/li><li>Standardize quarantine and the release procedure (who approves? within what timeframe?).<\/li><\/ul><p><strong>4) <span data-slate-fragment=\"JTVCJTdCJTIyY2hpbGRyZW4lMjIlM0ElNUIlN0IlMjJ0ZXh0JTIyJTNBJTIyRGV0ZWN0aW9uJTIwJTJCJTIwdHJpYWdlJTNBJTIwbWFraW5nJTIwdGhlJTIwdGVhbSUyMGVmZmVjdGl2ZSUyMiU3RCU1RCUyQyUyMnR5cGUlMjIlM0ElMjJoMyUyMiUyQyUyMmlkJTIyJTNBJTIyVFp2MjFoV3BWbyUyMiU3RCU1RA==\">Detection + triage: making the team effective<\/span><\/strong><\/p><ul><li><span data-slate-fragment=\"JTVCJTdCJTIyY2hpbGRyZW4lMjIlM0ElNUIlN0IlMjJ0ZXh0JTIyJTNBJTIyVGhlJTIwZ29hbCUyMGlzbiVFMiU4MCU5OXQlMjAlRTIlODAlOUMwJTIwcGhpc2hpbmclRTIlODAlOUQlMjAoaW1wb3NzaWJsZSklMkMlMjBidXQlMjByYXRoZXIlMjB0byUyMHJlZHVjZSUyMGluYm91bmQlMjBleHBvc3VyZSUyQyUyMHNwZWVkJTIwdXAlMjBkZXRlY3Rpb24lMkMlMjBhbmQlMjBsaW1pdCUyMGltcGFjdC4lMjIlN0QlNUQlMkMlMjJ0eXBlJTIyJTNBJTIycCUyMiUyQyUyMmlkJTIyJTNBJTIybG9NdDZBejQxTSUyMiU3RCU1RA==\">The goal isn\u2019t \u201c0 phishing\u201d (impossible), but rather to reduce inbound exposure, speed up detection, and limit impact.<\/span><\/li><\/ul>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-dcd436e elementor-widget elementor-widget-heading\" data-id=\"dcd436e\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">Identity and access controls: where deepfakes become dangerous<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-b35b6a0 elementor-widget elementor-widget-text-editor\" data-id=\"b35b6a0\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>A\u00a0<a href=\"https:\/\/en.wikipedia.org\/wiki\/Deepfake\" target=\"_blank\" rel=\"noopener\">deepfake<\/a> \u00ab marche \u00bb\u00a0<span style=\"white-space: pre;\">mainly when it enables:<\/span><\/p><ul><li>An MFA access reset;<\/li><li>An approval;<\/li><li>Administrator access;<\/li><li>Exfiltration.<\/li><\/ul><p><strong>1) MFA : <span data-slate-fragment=\"JTVCJTdCJTIyY2hpbGRyZW4lMjIlM0ElNUIlN0IlMjJ0ZXh0JTIyJTNBJTIyTUZBJTNBJTIwYWltJTIwZm9yJTIwcGhpc2hpbmclMjByZXNpc3RhbmNlJTIyJTdEJTVEJTJDJTIydHlwZSUyMiUzQSUyMmgzJTIyJTJDJTIyaWQlMjIlM0ElMjJJM05ybGkyYjBGJTIyJTdEJTVE\">MFA: aim for phishing resistance<\/span><\/strong><\/p><ul><li>Avoid approaches that are easy to bypass (MFA fatigue, intercepted codes).<\/li><li>Strengthen privileged accounts and sensitive roles.<\/li><\/ul><p><strong>2) <span data-slate-fragment=\"JTVCJTdCJTIyY2hpbGRyZW4lMjIlM0ElNUIlN0IlMjJ0ZXh0JTIyJTNBJTIyQ29uZGl0aW9uYWwlMjBhY2Nlc3MlMjBhbmQlMjByaXNrJTIwc2VnbWVudGF0aW9uJTIyJTdEJTVEJTJDJTIydHlwZSUyMiUzQSUyMmgzJTIyJTJDJTIyaWQlMjIlM0ElMjJvaUhvT003aEdPJTIyJTdEJTVE\">Conditional access and risk segmentation<\/span><\/strong><\/p><ul><li>Stricter policies for: Finance, HR, IT admin.<\/li><li>Controls based on compliant device, location, session risk.<\/li><\/ul><p><strong>3) <span data-slate-fragment=\"JTVCJTdCJTIyY2hpbGRyZW4lMjIlM0ElNUIlN0IlMjJ0ZXh0JTIyJTNBJTIyQnJlYWstZ2xhc3MlMjBhY2NvdW50cyUyMGFuZCUyMGdvdmVybmFuY2UlMjIlN0QlNUQlMkMlMjJ0eXBlJTIyJTNBJTIyaDMlMjIlMkMlMjJpZCUyMiUzQSUyMjVqWXlFZmVwbWMlMjIlN0QlNUQ=\">Break-glass accounts and governance<\/span><\/strong><\/p><ul><li>Documented emergency accounts.<\/li><li>Limited, monitored, tested access.<\/li><\/ul>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-a2d183c elementor-widget elementor-widget-heading\" data-id=\"a2d183c\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">Anti-deepfake procedures: the real human \u201cfirewall\u201d<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-795c4bd elementor-widget elementor-widget-text-editor\" data-id=\"795c4bd\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><strong>Rule 1 &#8211; \u201cTwo channels\u201d for any sensitive request<\/strong><\/p><p>Examples:<\/p><ul><li>Email + validation via Teams\/phone on a known number.<\/li><li>Teams message + confirmation via internal email.<\/li><\/ul><p><strong>Rule 2 &#8211; Mandatory call-back (using a reference number)<\/strong><\/p><ul><li>Never call back the number provided in the message.<\/li><li>Use a number from an internal reference source (CRM, directory, vendor record).<\/li><\/ul><p><strong>Rule 3 &#8211; Separate request and approval<\/strong><\/p><ul><li>One person initiates, another approves.<\/li><li>Exceptions must be rare, documented, and audited.<\/li><\/ul><p><strong>Rule 4 &#8211; \u201cStop the line\u201d with no penalty<\/strong><\/p><ul><li>If someone doubts, they must be able to stop the process without being blamed for a \u201cdelay.\u201d<\/li><\/ul>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-b95d43a elementor-widget elementor-widget-heading\" data-id=\"b95d43a\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Mini incident playbook (if a message still gets through)<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-844c940 elementor-widget elementor-widget-text-editor\" data-id=\"844c940\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<ol><li><strong>Preserve evidence:<\/strong> full email (headers), attachments, links, screenshots.<\/li><li><strong>Block:<\/strong> sender, domain, URLs, transport rules if needed.<\/li><li><strong>Reset \/ secure:<\/strong> targeted accounts, sessions, MFA, passwords.<\/li><li><strong>Assess impact:<\/strong> data, payments, access.<\/li><li><strong>Communicate:<\/strong> a short internal message (what to do \/ what to ignore), without panic.<\/li><li><strong>Improve:<\/strong> technical rule + procedure update + micro-training.<\/li><\/ol><p>Relevant additional resource to consult on this topic: <a href=\"https:\/\/csrc.nist.gov\/pubs\/sp\/800\/61\/r3\/final\" target=\"_blank\" rel=\"noopener\">NIST \u2013 Incident Response Recommendations and Considerations for Cybersecurity Risk Management<\/a><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-ac2a5c4 elementor-widget elementor-widget-heading\" data-id=\"ac2a5c4\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Common mistakes (and how to avoid them)<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-a53757c elementor-widget elementor-widget-text-editor\" data-id=\"a53757c\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<ul><li><strong>Relying only on awareness:<\/strong> without DMARC and procedures, AI wins.<\/li><li><strong>Allowing \u201cVIP\u201d exceptions:<\/strong> that\u2019s exactly what deepfakes target.<\/li><li><strong>Having an \u201coptional\u201d call-back:<\/strong> it must be non-bypassable.<\/li><li><strong>Confusing speed with effectiveness:<\/strong> 10 minutes of validation is better than 10 days of crisis.<\/li><\/ul>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-d2c2477 elementor-widget elementor-widget-heading\" data-id=\"d2c2477\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Mini case study<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-5d4ff8a elementor-widget elementor-widget-text-editor\" data-id=\"5d4ff8a\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span data-slate-fragment=\"JTVCJTdCJTIyY2hpbGRyZW4lMjIlM0ElNUIlN0IlMjJ0ZXh0JTIyJTNBJTIyQSUyMGNvbXBhbnklMjByZWNlaXZlcyUyMGFuJTIwJUUyJTgwJTlDdXJnZW50JUUyJTgwJTlEJTIwZW1haWwlMjBmcm9tJTIwdGhlJTIwQ0ZPJTIwcmVxdWVzdGluZyUyMGElMjBjaGFuZ2UlMjBvZiUyMGJhbmtpbmclMjBkZXRhaWxzJTJDJTIwZm9sbG93ZWQlMjBieSUyMGElMjB2b2ljZSUyMG1lc3NhZ2UlMjAodmVyeSUyMGNyZWRpYmxlJTIwdm9pY2UpJTIwY29uZmlybWluZyUyMHRoZSUyMHJlcXVlc3QuJTIyJTdEJTVEJTJDJTIydHlwZSUyMiUzQSUyMnAlMjIlMkMlMjJpZCUyMiUzQSUyMlYxMU83YnVBWHolMjIlN0QlNUQ=\">A company receives an \u201curgent\u201d email from the CFO requesting a change of banking details, followed by a voice message (very credible voice) confirming the request.<\/span><\/p><p><span data-slate-fragment=\"JTVCJTdCJTIyY2hpbGRyZW4lMjIlM0ElNUIlN0IlMjJ0ZXh0JTIyJTNBJTIyVGhlJTIwZmluYW5jZSUyMHRlYW0lMjBhcHBsaWVzJTIwdGhlJTIwJUUyJTgwJTlDdHdvLWNoYW5uZWwlRTIlODAlOUQlMjBydWxlJTNBJTIwdGhleSUyMHRyaWdnZXIlMjBhJTIwY2FsbC1iYWNrJTIwdXNpbmclMjB0aGUlMjBDRk8lRTIlODAlOTlzJTIwbnVtYmVyJTIwZnJvbSUyMHRoZSUyMGludGVybmFsJTIwZGlyZWN0b3J5LiUyMFRoZSUyMENGTyUyMGRlbmllcyUyMHRoZSUyMHJlcXVlc3QuJTIyJTdEJTVEJTJDJTIydHlwZSUyMiUzQSUyMnAlMjIlMkMlMjJpZCUyMiUzQSUyMjM5d2wyck1XYmklMjIlN0QlNUQ=\">The finance team applies the \u201ctwo-channel\u201d rule: they trigger a call-back using the CFO\u2019s number from the internal directory. The CFO denies the request.<\/span><\/p><p>Result :<\/p><ul><li>No wire transfer;<\/li><li>Evidence preserved;<\/li><li>Blocking of the spoofed domain;<\/li><li>DMARC update and anti-impersonation rules.<\/li><\/ul>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-e6f1e72 elementor-widget elementor-widget-heading\" data-id=\"e6f1e72\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Your next steps<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-962f181 elementor-widget elementor-widget-text-editor\" data-id=\"962f181\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<ul><li>Check your DMARC posture (goal: quarantine, then reject).<\/li><li>Define 5 \u201csensitive\u201d requests (payment, banking details, admin access, HR data, purchasing) and enforce the \u201ctwo channels + call-back\u201d rule.<\/li><li>Test a deepfake scenario internally (table-top): who validates? which logs? which messages?<\/li><li>Contact us; describe your context (size, tools, risks) and we\u2019ll propose a deliverables-based knowledge uplift plan.<\/li><\/ul>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-f703c45 elementor-widget elementor-widget-heading\" data-id=\"f703c45\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Certification pathway & recommended training<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-e06f3a5 elementor-widget elementor-widget-text-editor\" data-id=\"e06f3a5\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<ul><li>Security foundations (baseline): <a href=\"https:\/\/www.eccentrix.ca\/en\/courses\/comptia\/comptia-security-ct8731\/\" target=\"_blank\" rel=\"noopener\">CompTIA Security+<\/a> (to structure controls, risk, best practices)<\/li><li>Detection &amp; response (blue team \/ SOC): <a href=\"https:\/\/www.eccentrix.ca\/en\/courses\/comptia\/comptia-cybersecurity-analyst-ct8742\/\" target=\"_blank\" rel=\"noopener\">CompTIA CySA+<\/a> (triage, investigation, response)<\/li><li>Assessment &amp; testing (audit\/pentest): <a href=\"https:\/\/www.eccentrix.ca\/en\/courses\/comptia\/comptia-pentest-ct8729\/\" target=\"_blank\" rel=\"noopener\">CompTIA PenTest+<\/a> (evidence, actionable report, remediation)<\/li><li>Network basics (if it\u2019s a weak spot): <a href=\"https:\/\/www.eccentrix.ca\/en\/courses\/comptia\/comptia-network-ct8734\/\" target=\"_blank\" rel=\"noopener\">CompTIA Network+<\/a> (DNS, routing, segmentation, troubleshooting)<\/li><\/ul>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-3099cda elementor-widget elementor-widget-heading\" data-id=\"3099cda\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">FAQ<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-7a5c4f7 elementor-widget elementor-widget-accordion\" data-id=\"7a5c4f7\" data-element_type=\"widget\" data-widget_type=\"accordion.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-accordion\">\n\t\t\t\t\t\t\t<div class=\"elementor-accordion-item\">\n\t\t\t\t\t<h6 id=\"elementor-tab-title-1281\" class=\"elementor-tab-title\" data-tab=\"1\" role=\"button\" aria-controls=\"elementor-tab-content-1281\" aria-expanded=\"false\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon elementor-accordion-icon-left\" aria-hidden=\"true\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon-closed\"><svg class=\"e-font-icon-svg e-fas-plus\" viewBox=\"0 0 448 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M416 208H272V64c0-17.67-14.33-32-32-32h-32c-17.67 0-32 14.33-32 32v144H32c-17.67 0-32 14.33-32 32v32c0 17.67 14.33 32 32 32h144v144c0 17.67 14.33 32 32 32h32c17.67 0 32-14.33 32-32V304h144c17.67 0 32-14.33 32-32v-32c0-17.67-14.33-32-32-32z\"><\/path><\/svg><\/span>\n\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon-opened\"><svg class=\"e-font-icon-svg e-fas-minus\" viewBox=\"0 0 448 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M416 208H32c-17.67 0-32 14.33-32 32v32c0 17.67 14.33 32 32 32h384c17.67 0 32-14.33 32-32v-32c0-17.67-14.33-32-32-32z\"><\/path><\/svg><\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t<a class=\"elementor-accordion-title\" tabindex=\"0\">Are deepfakes already a real risk for SMEs?<\/a>\n\t\t\t\t\t<\/h6>\n\t\t\t\t\t<div id=\"elementor-tab-content-1281\" class=\"elementor-tab-content elementor-clearfix\" data-tab=\"1\" role=\"region\" aria-labelledby=\"elementor-tab-title-1281\"><p><span class=\"jCAhz ChMk0b\"><span class=\"ryNqvb\">Yes.<\/span><\/span> <span class=\"jCAhz ChMk0b\"><span class=\"ryNqvb\">The cost of entry is decreasing, and attacks often target payment and approval processes.<\/span><\/span><\/p><\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t\t<div class=\"elementor-accordion-item\">\n\t\t\t\t\t<h6 id=\"elementor-tab-title-1282\" class=\"elementor-tab-title\" data-tab=\"2\" role=\"button\" aria-controls=\"elementor-tab-content-1282\" aria-expanded=\"false\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon elementor-accordion-icon-left\" aria-hidden=\"true\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon-closed\"><svg class=\"e-font-icon-svg e-fas-plus\" viewBox=\"0 0 448 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M416 208H272V64c0-17.67-14.33-32-32-32h-32c-17.67 0-32 14.33-32 32v144H32c-17.67 0-32 14.33-32 32v32c0 17.67 14.33 32 32 32h144v144c0 17.67 14.33 32 32 32h32c17.67 0 32-14.33 32-32V304h144c17.67 0 32-14.33 32-32v-32c0-17.67-14.33-32-32-32z\"><\/path><\/svg><\/span>\n\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon-opened\"><svg class=\"e-font-icon-svg e-fas-minus\" viewBox=\"0 0 448 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M416 208H32c-17.67 0-32 14.33-32 32v32c0 17.67 14.33 32 32 32h384c17.67 0 32-14.33 32-32v-32c0-17.67-14.33-32-32-32z\"><\/path><\/svg><\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t<a class=\"elementor-accordion-title\" tabindex=\"0\">Is DMARC sufficient against identity theft?<\/a>\n\t\t\t\t\t<\/h6>\n\t\t\t\t\t<div id=\"elementor-tab-content-1282\" class=\"elementor-tab-content elementor-clearfix\" data-tab=\"2\" role=\"region\" aria-labelledby=\"elementor-tab-title-1282\"><p>DMARC helps a lot, but you also need anti-impersonation protections and procedures (2 channels, callback).<\/p><\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t\t<div class=\"elementor-accordion-item\">\n\t\t\t\t\t<h6 id=\"elementor-tab-title-1283\" class=\"elementor-tab-title\" data-tab=\"3\" role=\"button\" aria-controls=\"elementor-tab-content-1283\" aria-expanded=\"false\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon elementor-accordion-icon-left\" aria-hidden=\"true\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon-closed\"><svg class=\"e-font-icon-svg e-fas-plus\" viewBox=\"0 0 448 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M416 208H272V64c0-17.67-14.33-32-32-32h-32c-17.67 0-32 14.33-32 32v144H32c-17.67 0-32 14.33-32 32v32c0 17.67 14.33 32 32 32h144v144c0 17.67 14.33 32 32 32h32c17.67 0 32-14.33 32-32V304h144c17.67 0 32-14.33 32-32v-32c0-17.67-14.33-32-32-32z\"><\/path><\/svg><\/span>\n\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon-opened\"><svg class=\"e-font-icon-svg e-fas-minus\" viewBox=\"0 0 448 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M416 208H32c-17.67 0-32 14.33-32 32v32c0 17.67 14.33 32 32 32h384c17.67 0 32-14.33 32-32v-32c0-17.67-14.33-32-32-32z\"><\/path><\/svg><\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t<a class=\"elementor-accordion-title\" tabindex=\"0\">How to recognize a voice deepfake?<\/a>\n\t\t\t\t\t<\/h6>\n\t\t\t\t\t<div id=\"elementor-tab-content-1283\" class=\"elementor-tab-content elementor-clearfix\" data-tab=\"3\" role=\"region\" aria-labelledby=\"elementor-tab-title-1283\"><p><span class=\"jCAhz ChMk0b\"><span class=\"ryNqvb\">It&#8217;s difficult.<\/span><\/span> <span class=\"jCAhz JpY6Fd\"><span class=\"ryNqvb\">The right approach is procedural: validation on an independent channel, using a reference number.<\/span><\/span><\/p><\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t\t<div class=\"elementor-accordion-item\">\n\t\t\t\t\t<h6 id=\"elementor-tab-title-1284\" class=\"elementor-tab-title\" data-tab=\"4\" role=\"button\" aria-controls=\"elementor-tab-content-1284\" aria-expanded=\"false\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon elementor-accordion-icon-left\" aria-hidden=\"true\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon-closed\"><svg class=\"e-font-icon-svg e-fas-plus\" viewBox=\"0 0 448 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M416 208H272V64c0-17.67-14.33-32-32-32h-32c-17.67 0-32 14.33-32 32v144H32c-17.67 0-32 14.33-32 32v32c0 17.67 14.33 32 32 32h144v144c0 17.67 14.33 32 32 32h32c17.67 0 32-14.33 32-32V304h144c17.67 0 32-14.33 32-32v-32c0-17.67-14.33-32-32-32z\"><\/path><\/svg><\/span>\n\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon-opened\"><svg class=\"e-font-icon-svg e-fas-minus\" viewBox=\"0 0 448 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M416 208H32c-17.67 0-32 14.33-32 32v32c0 17.67 14.33 32 32 32h384c17.67 0 32-14.33 32-32v-32c0-17.67-14.33-32-32-32z\"><\/path><\/svg><\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t<a class=\"elementor-accordion-title\" tabindex=\"0\">What are the 3 most profitable controls?<\/a>\n\t\t\t\t\t<\/h6>\n\t\t\t\t\t<div id=\"elementor-tab-content-1284\" class=\"elementor-tab-content elementor-clearfix\" data-tab=\"4\" role=\"region\" aria-labelledby=\"elementor-tab-title-1284\"><p>DMARC (quarantine\/reject), VIP spoofing protection, and &#8220;2 channels + call-back&#8221; rule for sensitive requests.<\/p><\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t\t<div class=\"elementor-accordion-item\">\n\t\t\t\t\t<h6 id=\"elementor-tab-title-1285\" class=\"elementor-tab-title\" data-tab=\"5\" role=\"button\" aria-controls=\"elementor-tab-content-1285\" aria-expanded=\"false\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon elementor-accordion-icon-left\" aria-hidden=\"true\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon-closed\"><svg class=\"e-font-icon-svg e-fas-plus\" viewBox=\"0 0 448 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M416 208H272V64c0-17.67-14.33-32-32-32h-32c-17.67 0-32 14.33-32 32v144H32c-17.67 0-32 14.33-32 32v32c0 17.67 14.33 32 32 32h144v144c0 17.67 14.33 32 32 32h32c17.67 0 32-14.33 32-32V304h144c17.67 0 32-14.33 32-32v-32c0-17.67-14.33-32-32-32z\"><\/path><\/svg><\/span>\n\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon-opened\"><svg class=\"e-font-icon-svg e-fas-minus\" viewBox=\"0 0 448 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M416 208H32c-17.67 0-32 14.33-32 32v32c0 17.67 14.33 32 32 32h384c17.67 0 32-14.33 32-32v-32c0-17.67-14.33-32-32-32z\"><\/path><\/svg><\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t<a class=\"elementor-accordion-title\" tabindex=\"0\">What should be done if a user has clicked?<\/a>\n\t\t\t\t\t<\/h6>\n\t\t\t\t\t<div id=\"elementor-tab-content-1285\" class=\"elementor-tab-content elementor-clearfix\" data-tab=\"5\" role=\"region\" aria-labelledby=\"elementor-tab-title-1285\"><p>Preserve evidence, isolate\/control the account, revoke sessions, analyze the impact, then strengthen rules and training.<\/p><\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t\t<div class=\"elementor-accordion-item\">\n\t\t\t\t\t<h6 id=\"elementor-tab-title-1286\" class=\"elementor-tab-title\" data-tab=\"6\" role=\"button\" aria-controls=\"elementor-tab-content-1286\" aria-expanded=\"false\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon elementor-accordion-icon-left\" aria-hidden=\"true\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon-closed\"><svg class=\"e-font-icon-svg e-fas-plus\" viewBox=\"0 0 448 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M416 208H272V64c0-17.67-14.33-32-32-32h-32c-17.67 0-32 14.33-32 32v144H32c-17.67 0-32 14.33-32 32v32c0 17.67 14.33 32 32 32h144v144c0 17.67 14.33 32 32 32h32c17.67 0 32-14.33 32-32V304h144c17.67 0 32-14.33 32-32v-32c0-17.67-14.33-32-32-32z\"><\/path><\/svg><\/span>\n\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon-opened\"><svg class=\"e-font-icon-svg e-fas-minus\" viewBox=\"0 0 448 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M416 208H32c-17.67 0-32 14.33-32 32v32c0 17.67 14.33 32 32 32h384c17.67 0 32-14.33 32-32v-32c0-17.67-14.33-32-32-32z\"><\/path><\/svg><\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t<a class=\"elementor-accordion-title\" tabindex=\"0\">How do you justify ROI to a manager?<\/a>\n\t\t\t\t\t<\/h6>\n\t\t\t\t\t<div id=\"elementor-tab-content-1286\" class=\"elementor-tab-content elementor-clearfix\" data-tab=\"6\" role=\"region\" aria-labelledby=\"elementor-tab-title-1286\"><p>Link each control to a deliverable: reduced risk of fraud, reduced triage time, fewer costly incidents.<\/p><\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t","protected":false},"excerpt":{"rendered":"<p>Introduction &#8211; Deepfakes and AI Phishing Phishing is no longer just a \u201cbad email\u201d full of typos. With AI, the attack becomes more credible, more personalized, and sometimes multimodal: email + SMS + phone call + a Teams message. The real change isn\u2019t that \u201ceveryone will get fooled,\u201d but that fraudsters can industrialize persuasion. Deepfakes [&hellip;]<\/p>\n","protected":false},"author":3,"featured_media":59642,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_jet_sm_ready_style":"","_jet_sm_style":"","_jet_sm_controls_values":"","_jet_sm_fonts_collection":"","_jet_sm_fonts_links":"","footnotes":""},"categories":[84],"tags":[160,99],"class_list":["post-59651","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-eccentrix-corner","tag-compliance-and-governance","tag-cybersecurity"],"_links":{"self":[{"href":"https:\/\/www.eccentrix.ca\/en\/wp-json\/wp\/v2\/posts\/59651","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.eccentrix.ca\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.eccentrix.ca\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.eccentrix.ca\/en\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/www.eccentrix.ca\/en\/wp-json\/wp\/v2\/comments?post=59651"}],"version-history":[{"count":8,"href":"https:\/\/www.eccentrix.ca\/en\/wp-json\/wp\/v2\/posts\/59651\/revisions"}],"predecessor-version":[{"id":59666,"href":"https:\/\/www.eccentrix.ca\/en\/wp-json\/wp\/v2\/posts\/59651\/revisions\/59666"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.eccentrix.ca\/en\/wp-json\/wp\/v2\/media\/59642"}],"wp:attachment":[{"href":"https:\/\/www.eccentrix.ca\/en\/wp-json\/wp\/v2\/media?parent=59651"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.eccentrix.ca\/en\/wp-json\/wp\/v2\/categories?post=59651"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.eccentrix.ca\/en\/wp-json\/wp\/v2\/tags?post=59651"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}