Your journey
  1. 1
  2. 2
  3. 3
  4. 4
  5. 5
  6. 6
0 of 34 units

You are in Degree 4 · Protectionunit 5 of 6Ahead of you: A miniature red-team test and a cognitive defence plan.

Degree 4 · Unit 4.5

Deepfakes and identity

For years the advice was to examine the eyelashes, the movement of the lips, the shadows across the face. That advice has now expired. The quality of generation is advancing faster than the human eye can, and every marker published today gets repaired in the model tomorrow. Relying on it does you a double harm: you end up believing a well-made fake, and disbelieving an honest person who happens to have a poor camera.

The shift you need to make in your own thinking is this. Do not ask "is this fake?". Ask "what is the evidence that this is genuine?" The first is a question about appearances, and it has no reliable answer. The second is a question about procedure, and it does.

FIG. 22 — From detecting forgery to proving origin
Detecting forgery
Depends on a trace in the file · ages with every update · produces false alarms · a race you lose
Proving origin
Depends on an agreed procedure · does not age · its result is decisive · a control you own
fawzooz.ai

Four controls that work today

1The known channel: financial and contractual decisions are never taken from a call or a voice message, however exactly the voice matches. They are taken through an approved channel that the recipient opens themselves.

The most dangerous effect of forgery is not that people come to believe lies. It is the denial of truth: every piece of evidence becomes disputable, and the truth loses its footing entirely.

Do this

  1. 1 — In your field. Write the first-two-hours procedure for a forgery incident touching your organisation: who decides, who speaks, and what the first three steps are.

  2. 2 — In practice. Review which decisions in your work could be taken today on the basis of a call or a voice message alone. Close that door with a written procedure.

Your digital identity as an asset to be protected

Your voice, your face and your professional name are assets with a market value, which is precisely why they became a target. The difference between you and whoever impersonates you is that you can establish a trusted reference people go back to whenever they are in doubt: one known official channel, a verified account, and a published policy stating that you never ask for money or data through a voice message.

And the first thing that will be asked of you when an incident happens is speed. Every hour that passes without an official denial adds credence to the fake. So do not design your procedure on the day of the incident. Design it today, and name in it the spokesperson, the channel, and the wording of the denial you will use.

Responding to an incident in a creative agency

A calm, orderly response builds a client's trust; chaos destroys it. These three steps belong to the first hour.

FIG. B22 — Three immediate steps
1
Contain the breach
Disconnect the affected machine · isolate the network if in doubt · change the critical passwords, starting with administrator rights.
And delete nothing: suspicious files are evidence; keep them for the investigation.
2
Assess the situation
What happened? When? Which systems and accounts were touched? Which data is exposed?
3
Escalate and document
Tell the responsible person at once · split the roles (technical investigation / client communication) · log every action with a timestamp.
Once the storm passes
A blameless lessons-learned session: what was the root cause? What went well and what did not? How do we catch it sooner? Then an action plan with an owner and a date.

fawzooz.ai

Telling the client always comes before they find out: a call first, then it in writing, with facts rather than promises. And once the storm passes: a blameless lessons-learned session — what was the root cause? what went well and what did not? how do we catch it sooner? Then an action plan with an owner and a date.

Where to after this unit? A deferred danger remains that nobody sees: the data you encrypt today may be opened years from now.