International Cyber Expo International Cyber Expo
  • About Us
Monday, 5 October, 2026
IT Security Guru
International Cyber Expo
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

A familiar face is no longer proof: rethinking social engineering defence for the deepfake era

by Guru Writer
October 5, 2026
in Featured
A familiar face is no longer proof: rethinking social engineering defence for the deepfake era
Share on FacebookShare on Twitter

Deepfakes have spent much of their short history being treated as a curiosity. According to Anne Cutler, cybersecurity expert at Keeper Security, that complacency is now a risk in itself. “For many people, deepfakes still feel like an internet novelty – a fake celebrity video, an altered image or an amusing example of what AI can create. That perception needs to change,” she says. “Deepfakes are increasingly relevant to personal cybersecurity because the same technology used for entertainment can be weaponized by cybercriminals to impersonate other people, manipulate trust and steal sensitive information.”

Brian Long, CEO of Adaptive Security, believes this year’s Cybersecurity Awareness Month theme captures the problem neatly. “This year’s Cybersecurity Awareness Month theme, ‘Don’t make it easy for them,’ gets at something the old break room poster never did: attackers rarely need to be clever, they just need us to be predictable.”

“The advice hasn’t changed much in a decade: use a strong password, don’t click the weird link, report what looks off. But the threat has,” Long says. “A phishing email can now be generated in seconds, written for one employee by name, and sent at a scale no scammer could manage by hand. Phone calls can carry a cloned voice, and video calls a cloned face. Instinct alone isn’t enough anymore.”

Social engineering, supercharged

Cutler stresses that the underlying tactics are not new, but the quality and volume of attacks have changed. “Cybercriminals have always relied on social engineering, but what AI changes is how convincing and scalable those attacks can become,” she explains. “An attacker no longer has to rely solely on a suspicious email pretending to be an organization or individual you know. AI can help imitate a person’s voice, appearance or communication style, creating a much more persuasive request for money, account credentials or sensitive information.”

Olli Krebs, SVP EMEA at fraud prevention company Incode, argues that this shift demands a fundamental change in how organizations think about security. “Cyber security can no longer be treated as a feature or a compliance exercise. It has to be built into the architecture of everything we do online. AI has changed the stakes,” he says. “From AI-powered fraud to increasingly convincing deepfakes, the question for organizations is no longer simply, ‘are we compliant?’ it’s ‘can we spot and contain a threat before it does damage?’”

“That’s why this year’s Cyber Security Awareness Month theme, ‘Don’t Make It Easy for Them’, matters,” Krebs adds. “Security can’t live in a policy document or be the responsibility of one team.”

When familiarity becomes a vulnerability

For individuals, Cutler says, the biggest adjustment is psychological. “Our natural instinct to trust familiarity has become a vulnerability. Cybersecurity Awareness Month is an opportunity to update the way we think about personal security,” she says. “Recognizing phishing emails remains important, but awareness now also means questioning unexpected requests regardless of how authentic or personal they appear. A familiar face or voice should no longer be treated as proof of identity.”

Her practical advice centres on out-of-band verification. “If a family member, colleague or financial institution appears to contact you with an unusual or urgent request, verify it through another trusted channel. Call the person using a number you already have rather than one provided in the message,” she says. “Never provide passwords or Multi-Factor Authentication (MFA) codes in response to an unsolicited request, and always use strong, unique credentials backed up with MFA to make accounts harder to compromise.”

Building habits, week by week

Long argues that organisations should use October to build habits rather than simply repeat warnings. “That’s why the focus on everyday habits matters and why organizations should be building the month around four weekly themes and in a practical way,” he says.

The first week, he suggests, should tackle credentials: “Your passwords are easier to crack than you think, thanks to AI, so let’s fix those habits first.” The second turns to impersonation: “That voice on the phone or face on the call might not be who it seems, so how do we check?” In week three, the focus shifts to automated attacks: “Some attacks now run start to finish with no human involved, from researching you to writing the pitch.” And the final week addresses the data employees feed into AI: “Before pasting company data into an AI tool, ask whether it’s actually approved for that.”

Long says the delivery matters as much as the message. “By doing it through short videos, posters, plain-language newsletters, a content calendar and ready-to-send emails, security teams can run a full month without starting from scratch,” he says. “Training sticks when it feels like a habit worth keeping, not a rule to memorize. Small, repeated actions each week make us harder targets, and that is exactly what this theme asks of us.”

Assume every door is being tested

Krebs warns that organisations must plan on the basis that attackers are persistent. “In 2026, locking the front door isn’t enough. Organisations have to assume attackers are testing every door, window and loose brick, every day,” he says. “The winners will be those that can spot them early, shut down their access and stop an attempted attack becoming a crisis.”

Cutler concludes that understanding synthetic media is now a core part of staying safe online. “Deepfake awareness is personal cybersecurity awareness. Understanding how attackers can weaponize synthetic media is becoming an essential part of protecting our identities, accounts and financial lives.”

Or, as Long puts it: “This October, let’s swap the poster for a habit.”

ShareTweet
Previous Post

Ship fast, verify independently: keeping application security in step with AI-written code

Next Post

Cybersecurity Awareness Month “cannot be the strategy”: why awareness must become a year-round capability

Recent News

Prime Big Deal Days: scammers stock up early as Amazon impersonation attacks nearly triple

Prime Big Deal Days: scammers stock up early as Amazon impersonation attacks nearly triple

October 5, 2026
Denmark’s CPR breach exposes 8.8 million people as experts warn over trusted third-party access

Denmark’s CPR breach exposes 8.8 million people as experts warn over trusted third-party access

October 5, 2026
Cybersecurity Awareness Month “cannot be the strategy”: why awareness must become a year-round capability

Cybersecurity Awareness Month “cannot be the strategy”: why awareness must become a year-round capability

October 5, 2026
A familiar face is no longer proof: rethinking social engineering defence for the deepfake era

A familiar face is no longer proof: rethinking social engineering defence for the deepfake era

October 5, 2026

Eskenzi PR banner ad

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2026 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2026 IT Security Guru - Website Managed by Dessol