<p>Cybersecurity executives are already familiar with the idea of phishing prevention. For years, CISOs have trained staff to be suspicious of and resistant to old-school social engineering attacks, in which attackers use fake emails or texts that seem to come from executives, managers, vendors, partners or customers. Some organizations use security awareness training tools or services that run simulated phishing attacks to identify weaknesses in training materials and users who need further training.</p>
<p>With the steady spread of AI tools through every part of the cybercrime marketplace, some social engineering campaigns now include voice and video, which humans are predisposed to trust. Generative AI helps malicious actors craft deepfake phishing attacks, <a href="https://www.techtarget.com/searchsecurity/tip/Real-world-AI-voice-cloning-attack-A-red-teaming-case-study">using the cloned voices</a> and synthetic images of company executives or even employees' direct managers or peers.</p>
<p>Phishing simulation tools are leveling up accordingly, incorporating AI deepfakes to probe organizational resistance to state-of-the-art social engineering across multiple channels. With these tools, security teams can <a href="https://www.techtarget.com/searchcio/tip/How-executives-can-counter-AI-impersonation">impersonate executives in deepfake voice</a> or video messages or even converse with staff in real time on audio or video calls, perhaps demanding they change a password or permission setting or authorize a financial transaction.</p>
<section class="section main-article-chapter" data-menu-title="Is deepfake phishing simulation software worth it?">
<h2 class="section-title"><i class="icon" data-icon="1"></i>Is deepfake phishing simulation software worth it?</h2>
<p>As in all cybersecurity decisions, <a href="https://www.techtarget.com/searchsecurity/tip/5-ways-to-achieve-a-risk-based-security-strategy">CISOs need to weigh risk and cost</a> in deciding whether to deploy deepfake-capable phishing simulations.</p>
<p>These kinds of tools typically come at significant cost. A CISO must weigh that cost against the organization's potential losses if a staff member falls victim to social engineering, and the likelihood of that happening. Imagine just one person responds to, say, an urgent phone call purportedly from the CIO with instructions to isolate an entire data center from the rest of the enterprise. If that would drive losses of hundreds of thousands or millions of dollars, or create existential operational risk, then better hardening against social engineering is probably justifiable. Other risks, such as leakage of personally identifiable information or confidential intellectual property, might also justify the expense.</p>
<p>A CISO should factor another sort of vulnerability into the calculation, too: the availability of raw materials needed to generate deepfakes. If executives, leaders or subject matter experts in the company have appeared in public at live events or on podcasts or webinars, and video or audio of those appearances is readily available on YouTube or the like, then overall risk increases. That CEO's TED Talk, that CTO's MWC (formerly Mobile World Congress) keynote, that CISO's RSAC conference session — any could be turned into deepfake fodder.</p>
<p>One way to gauge the true level of vulnerability in the organization is, of course, to test using a reputable <a href="https://www.techtarget.com/searchsecurity/tip/Prepare-for-deepfake-phishing-attacks-in-the-enterprise">deepfake phishing</a> simulation tool on a short-term contract. Some vendors even offer trial versions, fully expecting their offerings to successfully fool prospective customers' staff and thereby prove their value.</p>
<div class="extra-info">
<div class="extra-info-inner">
<h3 class="splash-heading">Deepfake phishing simulations: Metrics beyond clicks</h3>
<p>Just by identifying which kinds of attacks get an employee to do the wrong thing — click a link, change a setting, whatever — phishing simulation tools identify where training needs improvement, processes need tightening and staff — both individually and by department or role — need more training.</p>
<p>These tools might also offer additional insights, such as how many users who avoided the phishing attempt also reported it and how long it took them to do so. The more data cybersecurity teams have, the more targeted and meaningful their proactive efforts in training and in process and behavioral hardening can be.</p>
<p>With deepfakes, new levels of testing and reporting are possible. Are staff more susceptible to pleas or threats? To emergencies or tedium? How much does tone of voice change response rates? What about the gender and appearance of the faked person? CISOs, equipped with all kinds of additional data about what their users are susceptible to, can tailor training and hardening initiatives accordingly.</p>
</div>
<p>With the steady spread of AI tools through every part of the cybercrime marketplace, some social engineering campaigns now include voice and video, which humans are predisposed to trust. Generative AI helps malicious actors craft deepfake phishing attacks, <a href="https://www.techtarget.com/searchsecurity/tip/Real-world-AI-voice-cloning-attack-A-red-teaming-case-study">using the cloned voices</a> and synthetic images of company executives or even employees' direct managers or peers.</p>
<p>Phishing simulation tools are leveling up accordingly, incorporating AI deepfakes to probe organizational resistance to state-of-the-art social engineering across multiple channels. With these tools, security teams can <a href="https://www.techtarget.com/searchcio/tip/How-executives-can-counter-AI-impersonation">impersonate executives in deepfake voice</a> or video messages or even converse with staff in real time on audio or video calls, perhaps demanding they change a password or permission setting or authorize a financial transaction.</p>
<section class="section main-article-chapter" data-menu-title="Is deepfake phishing simulation software worth it?">
<h2 class="section-title"><i class="icon" data-icon="1"></i>Is deepfake phishing simulation software worth it?</h2>
<p>As in all cybersecurity decisions, <a href="https://www.techtarget.com/searchsecurity/tip/5-ways-to-achieve-a-risk-based-security-strategy">CISOs need to weigh risk and cost</a> in deciding whether to deploy deepfake-capable phishing simulations.</p>
<p>These kinds of tools typically come at significant cost. A CISO must weigh that cost against the organization's potential losses if a staff member falls victim to social engineering, and the likelihood of that happening. Imagine just one person responds to, say, an urgent phone call purportedly from the CIO with instructions to isolate an entire data center from the rest of the enterprise. If that would drive losses of hundreds of thousands or millions of dollars, or create existential operational risk, then better hardening against social engineering is probably justifiable. Other risks, such as leakage of personally identifiable information or confidential intellectual property, might also justify the expense.</p>
<p>A CISO should factor another sort of vulnerability into the calculation, too: the availability of raw materials needed to generate deepfakes. If executives, leaders or subject matter experts in the company have appeared in public at live events or on podcasts or webinars, and video or audio of those appearances is readily available on YouTube or the like, then overall risk increases. That CEO's TED Talk, that CTO's MWC (formerly Mobile World Congress) keynote, that CISO's RSAC conference session — any could be turned into deepfake fodder.</p>
<p>One way to gauge the true level of vulnerability in the organization is, of course, to test using a reputable <a href="https://www.techtarget.com/searchsecurity/tip/Prepare-for-deepfake-phishing-attacks-in-the-enterprise">deepfake phishing</a> simulation tool on a short-term contract. Some vendors even offer trial versions, fully expecting their offerings to successfully fool prospective customers' staff and thereby prove their value.</p>
<div class="extra-info">
<div class="extra-info-inner">
<h3 class="splash-heading">Deepfake phishing simulations: Metrics beyond clicks</h3>
<p>Just by identifying which kinds of attacks get an employee to do the wrong thing — click a link, change a setting, whatever — phishing simulation tools identify where training needs improvement, processes need tightening and staff — both individually and by department or role — need more training.</p>
<p>These tools might also offer additional insights, such as how many users who avoided the phishing attempt also reported it and how long it took them to do so. The more data cybersecurity teams have, the more targeted and meaningful their proactive efforts in training and in process and behavioral hardening can be.</p>
<p>With deepfakes, new levels of testing and reporting are possible. Are staff more susceptible to pleas or threats? To emergencies or tedium? How much does tone of voice change response rates? What about the gender and appearance of the faked person? CISOs, equipped with all kinds of additional data about what their users are susceptible to, can tailor training and hardening initiatives accordingly.</p>
</div>
[…]
Content was trimmed to protect the source. Please visit the original article for the full text.
This article has been indexed from Search Security Resources and Information from TechTarget
Read the original article: