Why no CFO ever recounts their deepfake fraud

Look for a chief financial officer who stands up at a conference and walks an audience, under their own name, through the wire fraud that a faked video call ran against their company. You will not find one. The incidents themselves do surface: through insurer reports, regulator alerts, and conversations on the edge of a trade show. Never through a named account.
Three mechanisms lock that speech down, each perfectly rational on its own. None of them is embarrassment.
Disclosure law decides when you may speak
Regulation FD and the SEC’s four-business-day materiality clock govern the timing and the format of what gets said about a material incident. Everyone hears it at the same moment, in a controlled form. Speaking freely outside that window about something that may have touched the accounts exposes the company to an allegation of selective disclosure.
Corporate counsel knows this ground well. They do not let the finance chief improvise on a panel. The refusal applies a rule nobody wants to test in front of the regulator, well before it serves any communications purpose.
Cyber insurance makes silence a condition of coverage
Read the policy, not the broker’s summary. Incident confidentiality clauses are standard. The insurer needs the matter contained long enough to negotiate with third parties, to control how information surfaces, and to stop a spontaneous statement by one insured from creating an unfavourable precedent across the whole book.
Testifying publicly before settlement therefore opens a discussion about the coverage itself. Facing a seven-figure loss, that calculation resolves quickly, and it always resolves the same way.
Telling the story builds the other side’s case
The third lock is the sharpest. UCC Article 4A allocates the loss on a wire transfer according to whether the security procedures in place were “commercially reasonable”, a test about procedures that actually execute rather than people who were briefed. The SEC’s 2023 cybersecurity rules add a second exposure by making the governance of those procedures a board-level disclosure item.
Under that standard, a public account explaining how the incident unfolded amounts to documenting, in advance and in your own words, that the procedures were thin. No litigator recommends that keynote.
Three locks that stack
Each mechanism has its own logic: what you are allowed to say, what your insurer permits you to say, and what saying it costs you later in court. They do not offset one another, they add up. The result is a collective body of experience on synthetic-identity fraud that sits at zero, at the exact moment that experience would be worth the most.
The silence of other finance leaders protects nobody. It only removes the warning signals that would have let the next company prepare.
The one public measurement available
Since the victims stay quiet, what remains is the laboratories. In March 2025, researchers from CSIRO, Australia’s national science agency, and Sungkyunkwan University published an analysis of 51 deepfake detectors, sixteen of which were tested under real-world conditions. None of the sixteen reliably identified real-world deepfakes.
That is the only solid datapoint finance teams currently hold about their own exposure. It says that the tool meant to catch the human error does not catch it.
What the governance layer adds on top
Boards no longer treat this as an IT line item. The SEC’s rules put cyber risk oversight in the filing the board signs, and European companies operating under the NIS2 directive face administrative fines reaching 10 million euros or 2% of worldwide turnover for essential entities, with management bodies named personally on cyber governance.
The combination is uncomfortable. The obligation hardens, the case law hardens, and the pool of shared experience stays empty.
The question that gets argued in court
If the incident lands next month, what do you put in front of a judge? An awareness programme and a manual double sign-off describe intentions. What the 2026 standard examines is technical controls that execute without depending on the vigilance of an employee under pressure, and the irrefutable traces they leave behind.
That is the one part of the file the silence of others will not help you build.
Size your exposure
The BEC risk calculator estimates your company’s annual incident probability and expected loss in six questions, with a published methodology and sourced coefficients. No data leaves your browser.