In its Week 32 bulletin, Switzerland's National Cyber Security Centre (NCSC) closed out a four-part summer awareness series with an interactive public quiz asking visitors to distinguish genuine photographs from AI-generated images across three categories — streets, landscapes, and people. The exercise was framed as public education, but the underlying message is squarely a corporate security problem: NCSC's own materials note that more than one image per category may be AI-generated, and that the tell-tale artefacts researchers rely on — inconsistent shadows, malformed hands, repeating textures — are shrinking with every model generation. For Swiss enterprises, this is not a curiosity. It is direct evidence that the human visual-verification step embedded in countless fraud-prevention and executive-impersonation controls is degrading in real time, and that awareness programmes built around "look for the giveaway" advice are approaching their expiry date.
Why visual literacy alone is no longer a control
Most Swiss enterprise anti-fraud training still leans on a variant of the same instruction: scrutinise the image, listen for audio artefacts, watch for unnatural blinking in video calls. NCSC's own quiz demonstrates the flaw in that model — when a national cybersecurity authority builds a public test specifically to show how hard reliable detection has become, it is implicitly conceding that the skill it is teaching has a shrinking half-life. Deepfake voice cloning now requires only seconds of source audio, and synthetic video convincing enough to pass a casual video call is achievable with consumer-grade tools. A staff-training programme anchored on "spot the fake" as the primary defence is training people to fail gracefully, not to prevent fraud.
Executive impersonation is the highest-value target
The commercial risk concentrates around a narrow set of high-value scenarios: a fabricated video or voice call from a CEO or CFO instructing an urgent wire transfer, a synthetic recruiter profile used to extract credentials or install malware (a pattern already documented in state-linked campaigns), and cloned voices used to bypass call-centre or help-desk identity verification that still relies on "does this sound like the right person" as an implicit check. Swiss financial institutions, insurers, and treasury functions are the most exposed because they combine the two ingredients that make this attack class profitable: time-pressured, high-value transactions and a hierarchical approval culture where a request that appears to come from a senior executive is less likely to be questioned. Any help-desk or treasury process that still authenticates a caller primarily by voice recognition or by video presence should be treated as already compromised in threat-model terms, regardless of whether an actual incident has occurred.
Building a control that does not depend on human pattern-matching
The sustainable fix replaces visual and auditory judgment with out-of-band verification that a synthetic media attack cannot intercept. A wire-transfer instruction that arrives by video call, however convincing, should trigger a callback to a pre-registered number — not a number provided in the same communication — before execution. Help-desk password resets and access-recovery requests should require a verification factor the attacker cannot synthesise from public data or a few seconds of scraped audio, such as a pre-agreed passphrase or a hardware-bound authentication step. Swiss organisations updating their NCSC-aligned incident-reporting playbooks should also explicitly add "suspected synthetic-media fraud attempt" as a reportable category, distinct from generic phishing, so that pattern data can be aggregated at a national level the way ransomware and vulnerability exploitation already are.
Rolling out training that reflects the actual threat
A useful staff-training update starts by acknowledging what NCSC's own quiz demonstrates: even a motivated, attentive participant will misjudge some genuine images as synthetic and some synthetic images as real, and the error rate only grows as models improve. Rather than asking staff to become better forgery detectors, training should teach them to recognise the situational pattern that precedes a synthetic-media fraud attempt — urgency, an unusual request channel, pressure to bypass a normal approval step, or a request that arrives outside standard business communication norms. Pairing that behavioural training with the process controls above closes the gap that visual literacy alone cannot: an employee does not need to correctly identify a deepfake if the payment process makes the deepfake irrelevant to whether money actually moves. Swiss compliance and HR teams refreshing annual security-awareness modules should treat this as the headline update for the coming cycle, not a minor addendum to existing phishing content.
◆ Key Takeaway
NCSC's own public quiz shows that visual and auditory deepfake detection is no longer a reliable human skill. Swiss fraud-prevention controls need to shift from "train staff to spot the fake" to out-of-band verification processes that make synthetic-media convincingness irrelevant to the outcome.
- Replace voice- or video-based caller authentication in help-desk and treasury workflows with a factor an attacker cannot synthesise, such as a pre-agreed passphrase or hardware token.
- Mandate callback verification to a pre-registered number for any high-value payment instruction received by phone or video call, regardless of apparent seniority of the requester.
- Update executive-impersonation training to explicitly state that visual and audio realism is no longer a reliable indicator of authenticity.
- Add "suspected synthetic-media fraud" as a distinct, named category in internal incident-reporting workflows and NCSC-aligned notification processes.
- Run internal, controlled deepfake-simulation exercises for staff handling payments, treasury, or executive communications, rather than relying solely on generic phishing simulations.
- Review recruiter- and job-offer-themed social engineering guidance, given documented state-linked use of synthetic recruiter personas to target employees directly.
- Brief boards and finance leadership specifically, since executive-impersonation fraud targets the approval authority these roles hold, not just front-line staff.
NCSC's decision to build public education around a problem it cannot fully solve with awareness alone is itself the signal Swiss enterprises should act on. The organisations that update their verification architecture now, rather than waiting for a successful executive-impersonation fraud to force the issue, will be the ones whose defences do not depend on an employee correctly guessing whether the CFO on the call is real.