
Your CEO Just Approved a Payment on a Video Call. It Wasn’t Your CEO.
By Rahul Kumar, Regional Director, Experis Europe
A finance director I know got a Microsoft Teams call last quarter from his CEO. Familiar face, familiar voice, familiar mannerisms. The CEO was traveling and needed an urgent £1.8 million wire transfer authorised for a supplier. The finance director started the process. He was two clicks away from execution when a slight, split-second glitch in the video lighting made him pause.
He hung up and dialled the CEO’s mobile. The actual CEO had been on a flight for the last four hours.
It was a deepfake. And it nearly bypassed a seven-figure security perimeter in less than 90 seconds.
This is the new reality of enterprise security. We are no longer talking about crude face-swaps. We are facing real-time, high-fidelity synthetic impersonation.
When I talk to CISOs about this, they invariably show me their new AI-based deepfake detection software or their updated phishing training modules. But they are missing the fundamental point.
You cannot solve an operational trust vulnerability with a software detection tool.
The IBM Cost of a Data Breach Report 2025 found that AI-associated breach incidents cost organisations over $650,000 per breach on average. But the real insight isn’t the cost − it’s the attack vector.
Attackers aren’t hacking your firewalls. They are hacking your “urgent override” processes.
In high-performing enterprises, we train our people to act with speed. When an executive bypasses standard procedure and says “I need this done now,” the cultural instinct is to comply, not to verify. Generative AI weaponises that exact cultural reflex.
If your defense strategy relies on an accounts payable clerk spotting a subtle pixel distortion on a Zoom call, you have already lost.
The enterprises surviving this shift are doing something different. They are implementing hard-stop operational firebreaks.
Ban In-Band Approvals: A verbal approval on a video call is no longer a valid authorisation for a financial or data transfer. Ever.
Mandatory Out-of-Band Verification: If an urgent request comes via video or email, the approval must be confirmed via a completely separate channel (e.g. an encrypted messaging app to a verified mobile device) using a pre-established code word.
Red-Team Your Executives: The only way to know if your culture will withstand a synthetic attack is to run an unannounced, synthetic attack. If you aren’t actively trying to phish your own finance team with a deepfake of your CFO, a criminal group will do it for you.
At Experis, we approach enterprise security as an operational discipline, not just a software installation.
Our Project Services teams don’t just patch your servers; we leverage our cross-border security hubs to audit, break and rebuild your human-layer approval workflows. We help ensure your operational protocols are as hardened as your firewalls.
When was the last time you tested whether a deepfake call to your finance team would succeed? If your answer is “never,” let’s talk.
Next in the series: Post 4 — The AI margin trap your CFO didn’t budget for.
References:
IBM Cost of a Data Breach Report 2025 (https://www.ibm.com/reports/data-breach)
Menlo Security: How AI is Shaping the Modern Workspace (2025) (https://www.menlosecurity.com)
#AI #Cybersecurity #Deepfakes #CTO #CISO #EnterpriseRisk #TrustAndSecurity #Leadership





