Your Security Team Is Split in Two. Criminals Are Not.
Deepfakes and AI-powered scams now cross physical and digital boundaries at the same time. Most company security programs aren't built to follow.

Key points
- Only 12% of organisations felt prepared to detect a targeted physical attack, according to an EY survey of 250 corporate leaders.
- Transnational criminal groups use deepfakes and stolen identities to pass virtual job interviews, then receive real corporate laptops and network access.
- Security teams in most companies operate in separate silos, with cybersecurity, physical security, HR and legal rarely sharing formal processes.
- AI tools can help spot threats faster, but human analysts must make the final call before any major response is triggered.
Criminals have already mapped the shortest path through your organisation. They don't file threats neatly under "cyber" or "physical": they use whichever door opens, then pivot through whatever gaps nobody is watching.
Most security programs built over the last twenty years haven't caught up.
How are attackers crossing the line between digital and physical?
Deepfakes are the short answer. A deepfake is a video or audio clip generated by artificial intelligence that puts someone else's face or voice onto a recording, convincingly enough to fool a person on a live call.
Criminal networks now use them alongside stolen identities to get through virtual job interviews. Once a fake candidate clears every screen, the company ships a laptop to a home address and grants network access. At that point, a foreign intelligence service or criminal group is sitting inside the corporate network with legitimate credentials, and no single team saw it happen because HR, IT and logistics were each working from separate checklists. Our 15 September report on nation-state actors targeting AI systems shows how quickly those stolen credentials can be turned into weapons.
A deepfake phone call impersonating a finance director can also authorise a fraudulent wire transfer in minutes. An online threat against an executive can become a physical security question before lunchtime. Threats move fast. Org charts don't.
What is actually broken inside most companies?
The gap isn't inside any one department: it's between them. Each function, cybersecurity, physical security, HR, legal, may be doing its own job competently. What's missing is the connective tissue.
CSO Online quotes the leadership of one large organisation describing its physical and cyber security teams as having "strong relationships" and communicating regularly. Pressed further, those same leaders admitted there were no documented processes, no shared escalation procedures and no clearly defined responsibilities for a crisis. Informal goodwill isn't a security programme.
When an incident hits, whether it's a volatile protest outside the office, a workplace violence situation, or an urgent need to move hundreds of staff out of a geopolitical conflict zone, the response can't depend on whether the right people happen to pick up the phone.
| Gap | Real-world consequence |
|---|---|
| HR and IT not sharing hiring data | Fake employee receives hardware and network access |
| Cyber and physical teams with no joint process | Slow, uncoordinated response during a crisis |
| Legal and security not aligned | Compliance steps taken after damage is done |
| AI alerts with no human review | False positives trigger wrong response, or real threats are missed |
Should ordinary employees be worried about this?
Yes, and acting on it doesn't require specialist knowledge.
If you get an unexpected call or video request from someone claiming to be a senior colleague and asking you to move money, approve access or hand over credentials, slow down. Call that person back on a number you already have, not on contact details supplied in the suspicious message itself. Companies can reinforce this by running regular drills before a real incident makes the lesson expensive.
On the technology side, AI is genuinely useful: it can flag social media spikes around a dismissed employee or overlay camera feeds with anomaly detection. But AI systems hallucinate, meaning they sometimes produce confident-sounding alerts that are simply wrong. Experienced people need to review those alerts before anyone acts. We've tracked that failure mode across four "ai-threats" stories in the last 90 days, and it keeps showing up.
The organisations making real progress have stopped waiting for an incident to define their response. They assess risks continuously and make decisions before a situation forces their hand. That shift, from reacting to anticipating, is the practical difference between a security programme and a plan that collects dust.
The piece's central argument is sound, but it's worth saying plainly: integrated security isn't a structural nicety. When the fake IT help desk call, the fraudulent wire and the executive threat are all the same operation, a company that can't connect those dots in real time isn't slow. It's blind.



