Subscribe to the Zog Blog

Subscribe to the Zog Blog to get news Delivered straight to Your box!

Newsletter Signup

Escape the Hall of Mirrors: Protect Your Business From Impersonation

Escape the Hall of Mirrors: Protect Your Business From Impersonation

Earlier this week, we entered The Hall of Mirrors, where a familiar face, voice or message may not be enough to prove someone is who they claim to be.

AI is making impersonation easier and potentially more convincing. An attacker may be able to imitate an executive’s voice, create manipulated video, write messages in a familiar style or build a believable story using information that's publicly available.

So how do businesses respond?

Not by expecting every employee to become a deepfake expert.

And not by assuming they'll always be able to spot something fake.

The better approach is much simpler:

Build verification processes that work even when the impersonation looks real.

It's time to Survive the Scare and find our way out of The Hall of Mirrors.

Create Rules Around High-Risk Actions

Not every business interaction requires the same level of verification.

If your CEO emails someone asking where the company holiday party is being held, you probably don't need a multi-step identity verification process.

If the CEO asks someone to transfer $100,000 to a new bank account, that's different.

Businesses should identify actions where getting the person's identity wrong could create significant consequences.

That might include:

    • Wire transfers or large payments
    • Changes to banking information
    • Payroll or direct-deposit changes
    • Password resets
    • Requests for credentials
    • Access to sensitive systems
    • Requests for confidential employee or customer information
    • Changes to account permissions

Then establish clear procedures for verifying those requests.

Employees shouldn't have to decide in the moment whether something feels suspicious enough to verify.

The process should make that decision for them.

Use a Second Channel

One of the simplest defenses against impersonation is independent verification.

If an unusual request arrives by email, don't verify it by replying to that email.

If someone sends new banking information, don't call the phone number included in the message.

Instead, switch to a communication method you already trust.

Call the person using a known phone number.

Use your company's approved messaging platform.

Contact the vendor through information already stored in your system.

Talk to the executive in person.

The important part is that your verification method is independent of the potentially compromised communication.

If an attacker controls an email account, asking that same account, “Is this really you?” doesn't accomplish much.

Consider Dual Approval

Some actions are important enough that one person's approval shouldn't be sufficient.

High-value financial transactions are an obvious example.

Requiring a second authorized person to approve certain transactions creates another obstacle for an attacker.

Now the criminal doesn't simply have to fool one employee.

They have to get through a process.

Dual approval can also help protect against mistakes that have nothing to do with cybercrime. The goal isn't to make everyday business unnecessarily complicated. It's to put additional controls around the actions where a mistake could be particularly costly.

The higher the potential impact, the stronger the verification should be.

Establish Verification Before the Emergency

There’s another simple idea businesses can consider: establish verification methods before they're needed.

For particularly sensitive situations, teams may agree on internal procedures or information that isn't normally communicated publicly.

The exact method matters less than establishing it ahead of time.

You don't want employees inventing a verification process while an urgent request is already happening.

Attackers rely on uncertainty.

A defined process removes some of it.

Train Employees for the Request, Not Just the Fake

Employees should understand that impersonation attacks aren't limited to obviously fake videos.

The real warning sign may be the request itself.

Is someone asking for something unusual?

Does the request involve money, credentials or sensitive information?

Are they demanding secrecy?

Are they creating unusual urgency?

Are they asking you to bypass a normal procedure?

Those are reasons to stop and verify—even if the face on the screen looks completely convincing.

Employees don't need to prove something is a deepfake before raising a concern.

They just need permission to question an unusual request.

Train Executives Too

Executives aren't exempt from cybersecurity awareness.

In fact, their authority, access and public visibility can make them especially attractive targets for impersonation.

Leadership should understand both sides of the risk.

They may be targeted directly, and attackers may pretend to be them when targeting employees.

Executives can help establish a strong security culture by making one expectation clear:

“If you receive an unusual request from me involving money, credentials or sensitive information, I expect you to verify it.”

Employees shouldn't worry that questioning an unusual request from the CEO will get them in trouble.

That hesitation is exactly what an attacker wants.

Trust Processes More Than Faces

This is the biggest lesson from The Hall of Mirrors.

If your security depends on employees always recognizing a fake voice, video or message, eventually the technology may win.

Instead, build controls around the action.

An employee doesn't have to determine with 100% certainty whether the person on a video call is real.

They need to know that a request to transfer money requires independent verification and a second approval.

The process still works even if the fake is convincing.

A Business Leader's Question

Ask your leadership team:

“What could someone accomplish at our company simply by convincingly pretending to be one of us?”

Could they authorize a payment?

Change banking information?

Obtain employee records?

Reset a password?

Gain access to confidential documents?

Then ask the more important question:

“What independent verification would stop them?”

Those answers will tell you whether your business is prepared for a world where seeing and hearing may no longer be enough.

Survive the Scare

AI may make impersonation better.

Your business processes need to get better too.

Define high-risk actions. Verify through trusted channels. Use dual approval where appropriate. Train employees and executives. Give people permission to question unusual requests.

And above all:

Trust your process more than the face in the mirror.


Leave a Comment

Your email address will not be published. Required fields are marked *