Back to scenarios
Digitally distorted face, illustrating the Deepfake Threat: Cyber Attack Microsimulation
AI RiskTeam

Deepfake Threat: Cyber Attack

At a glance

Deepfake Threat: Cyber Attack is a simulation from iluminr in the AI Risk category for Data & AI, Technology & Security and Risk. It tests how your team protects aI-enabled customer services, with indicative mapping to NIST AI RMF, EU DORA and SEC Cyber Disclosure Rule.

Your organization grapples with an AI-driven cyber-attack, where advanced deepfake technology is being used to generate highly convincing fraudulent communications. This attack triggers a governance breakdown, posing severe risks to the organization’s reputation and operational integrity. --- [EngUS] Your organization grapples with an AI-driven cyber-attack, where advanced deepfake technology is being used to generate highly convincing fraudulent communications. This attack triggers a governance breakdown, posing severe risks to the organization’s reputation and operational integrity.

What it tests

  • Demonstrate awareness of the roles and responsibilities involved in responding to a critical event.
  • Evidence knowledge of the first actions in an event.
  • Verify key role alternates.

How you can run it

MicrosimulationRun as a team in a shared event room.
Full-Scale SimulationExtend it across teams, functions and partners.
Expert-FacilitatedOur team designs and runs it with you.

Questions about Deepfake Threat: Cyber Attack

What does Deepfake Threat: Cyber Attack test?

Deepfake Threat: Cyber Attack tests whether your team can demonstrate awareness of the roles and responsibilities involved in responding to a critical event, evidence knowledge of the first actions in an event and verify key role alternates.

Who should take Deepfake Threat: Cyber Attack?

Deepfake Threat: Cyber Attack is designed for Data & AI, Technology & Security, Risk, Compliance, Legal, Executive & Board, Chief AI Officer, AI Governance & Ethics and Model Risk Management.

Which regulations and standards does Deepfake Threat: Cyber Attack support?

Deepfake Threat: Cyber Attack supports testing expectations in NIST AI RMF, EU DORA, SEC Cyber Disclosure Rule, UK Consumer Duty, MAS TRM Guidelines, Interagency Third-Party Guidance, EBA ICT & Security Risk Guidelines, ISO 27001, NIST SP 800-53, ISO 22398 and NIST SP 800-84. Mapping is indicative, so confirm scope against your own obligations.

Can Deepfake Threat: Cyber Attack be run individually or as a team?

It runs as a team exercise in a shared event room. It can also be extended into a full-scale simulation across teams and partners.

Can we customize Deepfake Threat: Cyber Attack?

Yes. You can tailor the roles, plans, critical services, injects and objectives in the iluminr builder, or have our team customize it for you.

How do we get access to Deepfake Threat: Cyber Attack?

Request it from this page. If you are an iluminr customer, we will set up access in your account. If not, we will contact you and either provide access or facilitate it for you.

Related scenarios

A boardroom at night, illustrating the Green Light: AI Board Governance MicrosimulationAI RiskGreen Light: AI Board GovernanceThis Microsimulation builds your awareness of director accountabilities when a company deploys AI into customer-facing operations. You will be asked to evaluate an AI deployment proposal under commercial pressure, navigate conflicting advice from executives, and test how governance, documentation and disclosure expectations apply when things go wrong. The scenario is based on real-world AI governance and D&O risk patterns faced by organizations across sectors.AI neural network visualization, illustrating the Breached: AI IP Leak MicrosimulationAI RiskBreached: AI IP LeakRespond to a sensitive data leak involving AI-generated content, focusing on incident assessments, situational awareness, and securing communication protocols.AI neural network visualization, illustrating the Poisoned: Data Corruption MicrosimulationAI RiskPoisoned: Data CorruptionAssess and mitigate the impact of a sophisticated data poisoning cyber-attack that has corrupted critical operational data and disrupted decision-making processes.