Dominic Jainy stands at the forefront of the modern digital battlefield, where the lines between reality and synthetic fabrication have blurred beyond recognition. As an IT professional with deep roots in artificial intelligence, machine learning, and blockchain, he has spent years dissecting how emerging technologies can be both a catalyst for innovation and a weapon for deception. Jainy’s expertise is particularly relevant today as organizations grapple with the rise of “deepfake” social engineering—attacks that move past simple text-based phishing into the realm of hyper-realistic voice and video impersonation. In this conversation, we explore how the traditional playbook for cybersecurity is being rewritten. We delve into the mechanics of deepfake phishing simulation software, the psychological triggers that make voice and video clones so effective, and the complex risk-reward calculations CISOs must make when deciding to deploy these advanced training tools. Jainy provides a masterclass on the current threat landscape, from the tactical use of open-source intelligence to the specific software providers leading the charge in defensive simulations.
The landscape of social engineering is shifting rapidly, specifically with attackers leveraging public video and audio from keynote speeches or podcasts to create realistic clones. How does this wealth of open-source intelligence fundamentally change the stakes for a modern enterprise?
The availability of raw materials for deepfakes has turned public visibility into a double-edged sword for corporate leadership. In the past, a CEO’s TED Talk or a CTO’s keynote at a major event like MWC was purely a branding win, but today, that high-quality audio and video serve as perfect fodder for generative AI tools. When an attacker can pull a CISO’s session from a conference like RSAC and run it through a voice-cloning algorithm, they aren’t just sending a fake email; they are projecting a familiar authority figure into a victim’s ears. We are humans, and we are biologically predisposed to trust the voices and faces of people we know, which is why a deepfake call from a direct manager feels so much more urgent than a suspicious link in an inbox. This shift toward using open-source intelligence (OSINT) means that anyone with a public profile is now a high-value target for impersonation, forcing security teams to rethink what it means to protect an executive’s digital identity.
When we look at the financial side, these advanced simulation tools represent a significant investment. How should a CISO justify the high cost of deepfake-capable phishing simulations to a board that might be hesitant to spend on what looks like a niche threat?
The justification for these tools comes down to a hard-hitting analysis of potential losses versus the cost of prevention. If a single employee falls for a deepfake call—perhaps an urgent request from the CIO to isolate an entire data center—the resulting downtime could drive losses into the hundreds of thousands or even millions of dollars. Beyond the immediate financial hit, there is the existential operational risk of losing access to critical infrastructure or the long-term damage caused by the leakage of confidential intellectual property and personally identifiable information. When you frame the cost of a simulation tool against the backdrop of a multi-million-dollar breach, the expense starts to look like a very reasonable insurance policy. Some vendors even offer trial versions of their software, fully expecting their deepfakes to successfully fool the customer’s own staff, which often serves as the “lightbulb moment” a board needs to see the true level of their organization’s vulnerability.
Technologically, what are the essential features that a security team should look for in a simulation platform to ensure it truly mimics the sophistication of today’s cybercriminals?
A truly effective deepfake simulation platform must be as agile and multichannel as the adversaries it aims to mimic. First and foremost, the ability to create realistic clones directly within the platform using OSINT gathered from public sources is critical for realism. It isn’t enough to just send a recorded clip; the most advanced tools, like those from Breacher.ai, can launch orchestrated, multistage attack chains that adapt in real time based on how the target responds. You also want to look for the capability to conduct real-time, two-way voice and video conversations, as these are the frontier of modern social engineering. Finally, the software should support integration with existing training packages and cover all the languages and compliance regimes the company operates under to ensure the training is as broad as it is deep.
You mentioned that some tools use clever pretexts, such as “poor connectivity,” to mask the technical limitations of AI. How does this tactical realism impact the training experience for employees who might be used to more obvious phishing attempts?
This is a fascinating psychological tactic used by providers like Hoxhunt, where they intentionally incorporate lagging or glitching effects into a deepfake video to explain away any slight AI imperfections. By using the pretext of a bad connection on a fake version of Zoom, Microsoft Teams, or Google Meet, the simulation lowers the user’s guard and makes the interaction feel authentic to the modern remote-work experience. When a user is eventually “caught” by the simulation, they aren’t just told they failed; they receive instant micro-training that connects the emotional experience of the call to the technical signs of a deepfake. This kind of high-fidelity stress-testing is far more memorable than a static slide deck, as it forces the employee to confront the sensory details of a real attack in a safe, contained environment. It transforms a passive learning moment into an active defensive habit.
The market for these tools is currently split between agile startups and established incumbents like KnowBe4. How do you see this ecosystem evolving, and what should organizations keep in mind when choosing a partner?
We are seeing a “fresh crop” of specialized startups like Adaptive Security and Brightside that are pushing the leading edge of what is possible with AI-powered deepfakes and custom voice cloning. For instance, Adaptive Security is already serving diverse verticals including healthcare, hospitality, and education, proving that these threats are no longer limited to the finance sector. On the other hand, incumbents are moving quickly to catch up, with KnowBe4 introducing its Deepfake Training Content Agent in 2026, though some of these larger players are still working to fully document and support the most novel threats like real-time, two-way voice conversations. When choosing a provider, a CISO needs to evaluate not just the “cool factor” of the tech, but the financial stability of the vendor and their ability to provide realistic, pre-scripted or live exchanges that mirror actual adversary behavior. It is a rapidly maturing market where today’s niche startup could easily become tomorrow’s industry standard through acquisition or rapid scaling.
What is your forecast for the future of deepfake phishing?
I expect that by 2026 and beyond, the most dangerous frontier will be the widespread adoption of real-time, two-way conversational AI that can maintain a believable persona throughout an entire phone call or video conference. We will likely see a shift away from “batch” phishing toward highly personalized spear-phishing campaigns where the AI has been trained on weeks of a target’s public interactions to perfectly mimic their speech patterns and emotional nuances. As these tools become more accessible to low-level cybercriminals, the “human firewall” will need to rely less on visual spotting of glitches and more on strict procedural proofs and out-of-band verification. The era of “seeing is believing” is officially over; the future of security lies in a “trust, but verify via a secondary, non-AI channel” framework that treats every digital interaction with a healthy dose of skepticism.
