Cybersecurity executives are already conversant in the thought of phishing prevention. For years, CISOs have skilled workers to be suspicious of and immune to old-school social engineering assaults, during which attackers use pretend emails or texts that appear to return from executives, managers, distributors, companions or clients. Some organizations use safety consciousness coaching instruments or companies that run simulated phishing assaults to establish weaknesses in coaching supplies and customers who want additional coaching.
With the regular unfold of AI instruments by each a part of the cybercrime market, some social engineering campaigns now embrace voice and video, which people are predisposed to belief. Generative AI helps malicious actors craft deepfake phishing assaults, utilizing the cloned voices and artificial photographs of firm executives and even staff’ direct managers or friends.
Phishing simulation instruments are leveling up accordingly, incorporating AI deepfakes to probe organizational resistance to state-of-the-art social engineering throughout a number of channels. With these instruments, safety groups can impersonate executives in deepfake voice or video messages and even converse with workers in actual time on audio or video calls, maybe demanding they alter a password or permission setting or authorize a monetary transaction.
Is deepfake phishing simulation software program price it?
As in all cybersecurity choices, CISOs have to weigh danger and value in deciding whether or not to deploy deepfake-capable phishing simulations.
These sorts of instruments sometimes come at important price. A CISO should weigh that price in opposition to the group’s potential losses if a workers member falls sufferer to social engineering, and the chance of that occuring. Think about only one individual responds to, say, an pressing telephone name purportedly from the CIO with directions to isolate a whole information heart from the remainder of the enterprise. If that may drive losses of tons of of 1000’s or hundreds of thousands of {dollars}, or create existential operational danger, then higher hardening in opposition to social engineering might be justifiable. Different dangers, reminiscent of leakage of personally identifiable data or confidential mental property, may also justify the expense.
A CISO ought to issue one other kind of vulnerability into the calculation, too: the provision of uncooked supplies wanted to generate deepfakes. If executives, leaders or subject material specialists within the firm have appeared in public at dwell occasions or on podcasts or webinars, and video or audio of these appearances is available on YouTube or the like, then general danger will increase. That CEO’s TED Discuss, that CTO’s MWC (previously Cell World Congress) keynote, that CISO’s RSAC convention session — any could possibly be was deepfake fodder.
One option to gauge the true degree of vulnerability within the group is, in fact, to check utilizing a good deepfake phishing simulation software on a short-term contract. Some distributors even provide trial variations, totally anticipating their choices to efficiently idiot potential clients’ workers and thereby show their worth.
What to search for in deepfake phishing simulation software program
When evaluating deepfake phishing simulation software program, CISOs ought to contemplate whether or not choices have the next capabilities:
- Capacity to create practical deepfakes within the platform.
- Capacity to search materials for deepfakes on public sources, also referred to as open supply intelligence (OSINT).
- Capacity to make use of real-time voice conversations with a cloned voice as a part of an assault simulation.
- Capacity to make use of real-time, two-way video with a deepfake picture and cloned voice in a simulation.
- Capacity to drive multichannel assaults — e.g. utilizing voice calling and SMS, or electronic mail and video conferencing.
It is usually necessary to evaluate the software’s integration capabilities with different phishing simulation instruments and phishing coaching packages, in addition to the convenience of working each broad assault simulations and spear phishing campaigns aimed toward particular people.
Moreover, contemplate if there’s a studying curve for superior performance. Additionally consider if the software helps all of the languages the corporate makes use of for enterprise and helps all of the compliance regimes the corporate operates beneath.
Deepfake phishing simulation suppliers
As is typical within the cybersecurity market, deepfake phishing simulation suppliers presently embrace a contemporary crop of startups centered sharply on the forefront of the risk area — on this case, the addition of AI-powered deepfakes — and a smaller set of incumbents. Further safety consciousness coaching incumbents are possible determining which startups to merge with or purchase.
The next choices, listed alphabetically, present CISOs with perception into the present deepfake phishing simulation software program market.
Editor’s be aware: The writer chosen these instruments based mostly on market analysis, prioritizing choices which have sizable buyer bases, related options and distinguishing traits.
- Adaptive Safety. Creates deepfake video and audio simulations, constructed from public OSINT. Permits multichannel simulated assaults throughout electronic mail, voice, SMS and chat. Serves many verticals, together with hospitality, healthcare and training.
- Breacher.ai. Launches orchestrated, multistage assault chains with coordinated OSINT-based campaigns throughout channels, together with deepfake movies and voice cloning. Adapts in actual time based mostly on the goal’s response, mirroring adversaries’ habits and stress-testing enterprise defenses.
- Brightside. Supplies phone-based social engineering assaults with dwell, conversational AI calls that use customized voice cloning. Runs hybrid vishing and electronic mail phishing campaigns, powered by OSINT.
- Hoxhunt. Helps creation of deepfake audio and video to be used in multichannel simulated assaults. Pre-scripted exchanges are designed to seem actual time — utilizing the pretext of poor connectivity to clarify lagging and glitching results — however do not assist open-ended chatting. Makes use of pretend, look-alike variations of Zoom, Microsoft Groups and Google Meet apps to comprise the expertise. A person who falls for the deepfake receives immediate micro-training.
- KnowBe4. Longtime safety consciousness coaching supplier launched its Deepfake Coaching Content material Agent in 2026. Helps audio and video uploads from consenting insiders, reminiscent of executives, to generate deepfakes. As of this writing, nonetheless, KnowBe4’s printed documentation doesn’t describe assist for real-time, two-way voice conversations, which is the place essentially the most novel threats presently lie.
As all the time, CISOs ought to assess distributors’ strengths throughout verticals and geographies. Think about additionally their general monetary stability, particularly if they’re nonetheless venture-funded.
John Burke is CTO and a analysis analyst at Nemertes Analysis. Burke joined Nemertes in 2005 with practically twenty years of expertise expertise. He has labored in any respect ranges of IT, together with as an end-user assist specialist, programmer, system administrator, database specialist, community administrator, community architect and techniques architect.








