Deepfake: we measure whether your team verifies before acting on a CEO request

A face and a voice that look like the board can ask for a transfer in minutes. The service builds that piece, runs the scenario and leaves a verification protocol — not an artificial-intelligence highlight.

How it works

How we build a scenario that does not become a weapon

Identity and authorized material

We choose with you whose likeness will be used and we ask for material legal authorizes. Without that person’s consent — or their representative’s — there is no piece. The limit on what is generated is written down.

Channel and clip

We decide audio, video or both, and the channel: a short meeting, a note, a call with image. The clip asks for a payment or an exception, not a customer secret. It is used only in the window. It is not delivered as a marketing file.

Protocol under test

Before we run, we document which verification should happen: a callback to an official number, a second approver, a minimum delay, a channel outside the meeting. The exercise measures that protocol, not the “scare”.

Debrief and destruction

We close with security and finance. The report says who verified and who executed. Synthetic material is destroyed or archived under the agreed rule. What remains is the recommended protocol and the bridge to the Deepfake course for habit.

Why it matters

Why this scenario does not fit an email campaign

Because the control to test is not “do not tap the link”. It is “do not move money or break maker-checker because a known face asked”. BEC email already lives in the simulations module. Deepfake attacks the verification that remains when…

Why this scenario does not fit an email campaign
Deliverables

What you get

A test of the verification protocol against a request that looks like the board, not an artificial-intelligence reel.

Identity scope

Whose likeness may be used, with which material, and what is forbidden to generate. Signed before the clip is produced. It is the document legal asks for and the exercise cannot skip.

Exercise piece

Synthetic audio or video used only in the window. It is not an intranet deliverable and not a file treasury keeps. It carries the transfer or exception ask that real fraud uses.

Report by role

Who verified, who forwarded, who executed. Cut by treasury, executive assistance and management. No regional “deepfake detection” rate.

Recommended protocol

Callback, second approver, delay, out-of-band channel. An owner in finance and an owner in security. An explicit link to the Deepfake course and to vishing if voice was the vector.

Requirements and timelines

What we need from you

  • Consent from the person whose likeness is used — or from whoever represents them — and enough authorized material for a credible piece. Without that we do not produce. Legal and…
  • Also a map of the non-routine payment process: who can authorize, what maker-checker exists, which official number is used to call back. If that map does not exist, the exercise…
The program

How it fits the program and the course

Deepfake does not replace email simulations or vishing. It is the test of a request that looks authentic because it is seen or heard. It is read with finance and with the index, in a conversation the committee…

How it fits the program and the course
Questions

Questions about deepfake simulations

Is this the same as the Deepfake course?
No. The course teaches signals and protocol. This service produces an authorized piece, runs the scenario and measures whether anyone verifies. The course sustains the habit afterwards. They are not sold as the same item.
Is this the same as vishing?
They are family. Vishing is the call and the pretext; it can include cloned voice as a variant. Deepfake puts the synthetic material — face or voice — at the center and tests the payment protocol. We do not paste one page onto the other.
Do you deliver the video?
Not as a file to reuse. The clip lives in the exercise window and is destroyed or archived under legal’s rule. The deliverable that remains is the report and the protocol.
Can you use any executive’s face?
Only with consent and authorized material. Without that there is no production. Identity scope is signed first.
Is there a published price?
No. It depends on the identity, the channel and the window. It is quoted. We do not publish a range or an “AI pack”.

Test the protocol before the request is real

If treasury never verified against a known face, the control is a hypothesis. Let’s talk identity and window.

Full catalog on Services