
Gartner opened its Security and Risk Management Summit in London on Tuesday with a number pulled from a survey of 297 senior cybersecurity leaders: 41% of them had at least one social engineering incident involving a deepfake on an employee audio call in the past 12 months. On video calls, 36%. The survey ran from March to May 2026, which means the people answering it were describing a threat they had already met, not one they were bracing for.
The trade coverage has settled on the operational reading, that CISOs should update their incident response playbooks. Read the rest of the same survey and it is reporting something larger. 79% of these leaders logged phishing, spear phishing or business email compromise. 58% logged vishing or smishing. Put the four numbers in a row and every channel a company uses to reach a human being remotely is on one list, and the list is of channels that have already been used against them.
Each of those numbers has been reported on its own for years. Email fraud is old enough to be boring. Voice phishing got its own acronym. What is new is that they arrived in a single survey, from a single population, inside a single 12 month window, which turns four separate security problems into one commercial fact: there is no longer a remote channel where the person on the other end is presumed to be who the caller ID says.
We have written before that the AI-assisted email pitch finished last of seven prospecting channels while cold calling scored what it scored in 2018. That was a performance story. This is the same decay arriving from the other direction, as a trust problem rather than a response rate problem, and it lands on the channels that were still working.
The first of its three recommended actions is to move training away from identifying fakes and toward verification protocols for sensitive requests. That is a quiet surrender, and it is the correct one. University of Florida researchers tested thousands of people against hundreds of real and fake images and videos and found humans performing at chance on still images while detection algorithms reached up to 97%. On video the result reversed: the algorithms dropped to chance and people caught roughly two thirds. Whether anyone in your company can spot the fake depends on which format the attacker happened to pick.
Craig Porter, a director analyst at Gartner, said that CISOs must use the same discipline used to assess identity and access risks to combat AI-driven social engineering threats. Translated out of the analyst register: stop asking people to judge, start asking systems to prove.
Gartner's guidance is to make verification the default response for risky requests across every channel, with phishing-resistant authentication on account recovery, privileged access and payment authorization. Sound policy. Also a cost, and the cost does not land on the security team that wrote it. It lands on the finance clerk who now calls back before releasing the wire, the procurement lead who confirms out of band before signing, and the account executive whose approval sits for another day inside a process nobody wants to be the person who skipped.
Describe the remedy to someone outside this industry and it sounds like this: the technology can now clone a chief financial officer well enough to move 200 million Hong Kong dollars, and the countermeasure the analysts recommend is a second phone. At Arup, that is precisely what worked. The engineering firm lost $25.6 million after an employee in its Hong Kong office joined a video call populated by fake colleagues and made 15 separate transfers, and the fraud broke only when someone checked with the UK head office. Rob Greig, Arup's chief information officer, said afterwards that he hoped the company's experience would raise awareness of how sophisticated bad actors have become.
Every control in Gartner's list adds a step to a remote interaction. None of them are needed for the interaction that happens in a room, where identity is confirmed by the same mechanism humans have used since before there were wires, and confirmed for free.
That is not an argument that meetings should replace security programs. A handshake does not stop a wire fraud, and pretending otherwise is how vendors get themselves quoted. It is an argument about relative cost. Every remote channel just got more expensive to trust, in seconds of delay and in steps added, while the in-person one did not, and the in-person one remains the last channel in B2B with no audit trail, no log and no record of who was actually in the conversation. The stricter institutions have already moved on the first half of that sentence. Almost nobody has moved on the second.
Here is the position. Within a year, verification steps will be measurable inside sales cycle length, and the teams that route their highest-value approvals through rooms rather than through callbacks will close faster than the teams that add a second phone call to every payment. If your security team is drafting verification policy and nobody from revenue is in the meeting, that trade is being made anyway. It is just being made without you.
Pieter Limburg, Mobilo: "Security is about to make remote selling slower, and nobody is budgeting for it. The companies that notice first will move their big approvals into rooms and look like they got lucky on cycle time."
Undivided Attention is powered by Mobilo.