Skip to main content

Pro audit program · v1.0

Executive Impersonation & Account Takeover Defence

CEO / CFO LinkedIn clones, executive deepfakes and impersonation accounts targeting your customers and staff. Detect and respond.

  • General target area
  • NIST CSF framework
  • 6 controls in this program
  • Cyentrix Cyentrix Trusted Author

About this program

CEO / CFO LinkedIn clones, executive deepfakes and impersonation accounts targeting your customers and staff. Detect and respond.

Risks addressed

  • Critical Clone CEO LinkedIn used in CEO-fraud phishing
  • Critical Deepfake voice / video used in wire-transfer scam
  • High Customer-facing scam runs on a lookalike support handle

Controls (6)

  1. Monitor for impersonation accounts on top platforms

    High

    Monitor for impersonation accounts on top platforms

    How to test + evidence

    Testing procedure: Brand-protection tool (or manual sweep) flags clones of named executives + corporate handles.

    Evidence to collect: Monitoring tool config / weekly report.

  2. Reporting workflow with each platform

    High

    Reporting workflow with each platform

    How to test + evidence

    Testing procedure: Documented contacts + workflow at LinkedIn / Meta / X / TikTok for impersonation takedowns.

    Evidence to collect: Takedown contacts + last 5 cases.

  3. Executive accounts verified (blue badge / equivalent)

    Medium

    Executive accounts verified (blue badge / equivalent)

    How to test + evidence

    Testing procedure: Where available, verification reduces clone effectiveness.

    Evidence to collect: Verification screenshots.

  4. Out-of-band verification for finance requests

    Critical

    Out-of-band verification for finance requests

    How to test + evidence

    Testing procedure: Wire-transfer / payment changes require call-back on a known number, not from new requester.

    Evidence to collect: Finance policy + call-back log.

  5. Awareness training covers deepfake + CEO-fraud

    High

    Awareness training covers deepfake + CEO-fraud

    How to test + evidence

    Testing procedure: Annual training + simulated CEO-fraud phishing test.

    Evidence to collect: Training content + simulation results.

  6. Public PR / comms response plan for executive scam

    Medium

    Public PR / comms response plan for executive scam

    How to test + evidence

    Testing procedure: Pre-drafted public response if an impersonation campaign scales.

    Evidence to collect: Comms template library.