Cyber Security Guide · 28 April 2026
Phishing and deepfake defence in 2026
How AI has changed social engineering - and the layered controls that actually stop it.

Generative AI has industrialised social engineering. Deepfake voice calls, hyper-personalised phishing and executive impersonation are now routine - and the defence has to be layered.
How attacks have changed
- Emails free of the usual typos and translation errors
- Cloned voices used for CEO-to-finance wire fraud
- Video calls with synthetic faces to authorise payments
- Attackers using LinkedIn and public data to personalise pretexts
Technical controls
- Phishing-resistant MFA (FIDO2 / passkeys) for high-risk roles
- Advanced email filtering with URL rewriting and sandboxing
- DMARC, SPF and DKIM enforced at reject
- Out-of-band verification for any payment or credential change
Human controls
- Ongoing, role-relevant security awareness training
- Simulated phishing that reflects current attacker tactics
- A clear, blame-free way to report suspicious messages
- Documented callback procedures for financial requests
