Gartner Survey Finds 41% of CISOs Reported At Least One Social Engineering Incident Involving a Deepfake in the Past 12 Months
“Attackers can combine phishing, business email compromise, synthetic media, and aggregated personal context across multiple channels,” said Craig Porter, Director Analyst at Gartner. “Most attacks will continue to rely on users, stolen credentials, weak recovery processes, and familiar technical methods. CISOs must use the same discipline used to assess identity and access risks to combat AI-driven social engineering threats.”
Gartner survey found 79% of CISOs reported at least one e-mail phishing, spear-phishing, or business e-mail compromise incident in the last 12 months.
Gartner analysts are discussing how to fight social engineering and agentic threats during the Gartner Security & Risk Management Summit taking place this week in London.
To effectively counter evolving AI social engineering attacks, CISOs must focus on three critical actions:
1- Transform Static Training into Adaptive Security Behavior and Culture Programs
- Evolve secure behavior and culture programs from teaching employees to “spot the fake,” toward making secure verification the expected behavior for consequential requests. Train employees and approvers to pause, verify, and report high-risk requests regardless of whether the request arrives through e-mail, voice, video, collaboration tools, or an AI application. Use workforce simulations to test verification and reporting behavior of AI-related suspicious events.
2- Harden Workforce Identity and Recovery Against Impersonation
- Protect high-value workflows such as account recovery, privileged access, and payment authorization with phishing-resistant authentication, risk-based identity controls, and trusted verification channels. In addition, implement controls to detect identity abuse, including after a successful login or password reset.
3- Prepare Detection and Response for AI-Mediated Threats
- Correlate suspicious communications and impersonation reports with account recovery events, new devices, privilege changes, and financial transactions to improve threat detection. Update incident response playbooks for multimodal impersonation, manipulated AI recommendations, compromised or misused agents, and where applicable, agents that operate beyond their intended boundaries.





