Home / Resources / Incident response checklist
Playbook

Deepfake incident response readiness checklist

A practical checklist for confirming whether security, fraud, legal, communications, and leadership teams can respond when AI-enabled impersonation creates operational or reputational risk.

Checklist

What should be ready before an incident

01

Intake path

Employees know where to report suspicious voice notes, video calls, messages, and executive requests.

02

Evidence preservation

Teams can preserve call logs, messages, screenshots, timestamps, and business-system events without contaminating evidence.

03

Decision owner

There is a named owner for pausing transactions, access changes, communications, or vendor actions.

04

Escalation map

Security, fraud, legal, HR, communications, and executive stakeholders know when they must be involved.

05

Containment options

Playbooks cover transaction holds, account locks, communication holds, and third-party notification paths.

06

Post-incident learning

Findings translate into verification-policy updates, coaching, and repeatable simulations.

Simulation makes the checklist real

A checklist is only useful if it survives pressure. Deceptiment can simulate the point of confusion: an urgent voice, a convincing message, a sensitive request, and an incomplete fact pattern. That is where response readiness becomes visible.

The objective is not only to stop one scenario. It is to learn whether the organization can coordinate across functions before a deepfake-driven event becomes a financial, operational, or reputational incident.

Run a response-readiness exercise

Test the handoffs before a real deepfake incident tests them for you.

Book a readiness walkthrough →