Deepfake executive fraud has become a board-level risk

Synthetic voice and video are no longer a novelty in fraud. The pattern now reported across finance and professional services is consistent: a convincing approach that appears to come from a senior executive, delivered by voice call or video, applying time pressure to an unusual payment or a change of bank details. The technical barrier has effectively disappeared, and compliance commentators are increasingly treating deepfake-enabled fraud as a governance issue that boards and regulators are expected to have addressed.

Why the usual controls do not catch it

Most anti-fraud training is built around detecting a badly written email. Synthetic media defeats that entirely, because the signal people are trained to look for – poor language, an odd address, a generic greeting – is absent. Worse, the approach usually exploits something structurally true about the organisation: that a request from a senior person, marked urgent and confidential, is difficult for a junior member of staff to challenge.

What actually works

The effective controls here are procedural rather than technological, and they are cheap:

  • Out-of-band verification for payments and bank detail changes, using a number held in your own records – never one supplied in the request itself.
  • A standing rule that urgency is a reason to slow down. Make it explicit, from the top, that no executive will ever penalise someone for verifying.
  • Dual authorisation above a defined threshold, with the second approver required to confirm through a different channel.
  • An agreed challenge process that staff can invoke without needing to accuse anyone of anything – a policy they are following, not a judgement they are making.
  • Rehearsal. Include a synthetic-voice scenario in your next tabletop exercise. It changes the conversation quickly.

The organisations that handle this well are not the ones with the best detection technology. They are the ones where a finance assistant can say “I need to call you back on the number we hold” to a director, and know that doing so is exactly what the organisation expects of them.


Sources

The Cyber Security and Resilience Bill: the supply chain is the part most organisations underestimate

The Cyber Security and Resilience Bill cleared its third reading in the House of Commons on 16 June 2026 and has moved to the House of Lords. It is not law yet, and the detail will continue to move – much of the substance will land in secondary legislation and regulator guidance rather than in the Bill itself. But the shape of it is now clear enough to plan against, and we would encourage organisations to start doing exactly that.

What it does

In broad terms, the Bill modernises and widens the UK’s existing network and information systems regime. It applies directly to five sectors – transport, energy, drinking water, health and digital infrastructure – and extends the perimeter to bring in a further population of organisations estimated at around a thousand, including data centre operators, managed service providers, online marketplaces, search engines and cloud computing providers.

For those in scope, the practical obligations are recognisable: demonstrable compliance with defined security standards, strengthened risk assessment, regular audit and reporting, and mandatory incident reporting – including ransomware reporting, which is intended in part to give government a genuine picture of a threat that has been chronically under-reported. Enforcement powers include daily penalties, with figures of up to £100,000 per day discussed since the policy was first trailed in 2025.

The clause that will affect the most organisations

The provision with the widest reach is not the one about regulated sectors. It is the expectation that regulated entities ensure their partners and suppliers meet the standards set under the regime.

That single idea changes the population affected by an order of magnitude. If you supply software, professional services, logistics, facilities management or anything else to an NHS trust, a water company, an energy provider or a large managed service provider, you will feel this regime – not through a regulator, but through your customer’s procurement and contract management teams. You will be asked to evidence controls, accept audit rights, commit to notification timeframes, and demonstrate that your suppliers are held to something equivalent.

In our experience this is where organisations get caught out. Being out of direct scope feels like an exemption. It usually is not. It simply means the requirement arrives as a contractual clause with a commercial deadline attached, rather than as a regulatory obligation with a consultation period and a transition window.

The fundamentals problem

It is worth reading the Bill alongside what the National Cyber Security Centre has been saying about the current threat picture. In June 2026 the NCSC’s chief executive, Dr Richard Horne, noted that the organisation had handled more than 200 incidents in the year to May, and made a point that we think deserves more attention than it received: too many significant incidents remain possible because the fundamentals are not in place.

That is not a comfortable observation for a market that has spent heavily on detection and response tooling. But it matches what we find. Unsupported software still running because a business process depends on it. Administrative access that was granted for a project three years ago and never withdrawn. Backups that exist but have never been restored under realistic conditions. Asset inventories that were accurate at the point they were compiled.

None of that is solved by procurement. It is solved by ownership, discipline and a willingness to fund unglamorous work.

What we would do between now and Royal Assent

  • Establish whether you are in scope, and whether your customers are. The second question matters more for most organisations than the first, and it is the one people forget to ask.
  • Map your critical suppliers properly. Not a procurement list – a view of which third parties could stop you operating, and what you would actually do if one of them was offline for a fortnight.
  • Test the reporting path. Mandatory reporting within tight timeframes is a process problem before it is a legal one. Who decides an incident is reportable? At what hour of the night? On what evidence?
  • Rehearse recovery, not just detection. The regime is called resilience for a reason. Being able to restore service is the outcome regulators, customers and boards actually care about.
  • Fix the fundamentals now. Patching, privileged access, segmentation, tested backups, and knowing what you own. This work has a long lead time and every version of the final legislation will require it.

The organisations that will find this regime straightforward are the ones already doing most of it. For everyone else, the eighteen months between now and meaningful enforcement is a reasonable, but not generous, amount of time.

APHS supports organisations across ICT strategy, information and data governance, security, and programme delivery. If you would like a view on where you stand against the direction of travel – whether as a regulated entity or as a supplier to one – get in touch.


Sources