Security & Deepfake Defence — bespoke protection for companies | Bruncsoft Bruncsoft What we defend against How we work The study Contact Bruncsoft Security · bespoke Your people are the target now, not your firewall. A convincing fake of your CEO costs an attacker a few minutes and a public video of them talking. We do bespoke security work inside companies against deepfakes and AI-assisted fraud: fake video calls that authorise payments, cloned voices on the phone, fake candidates in remote interviews, synthetic documents in identity checks. This is not a product you install. We look at how your company actually approves money, hires people and hands out access, find the places where trust is granted on the strength of a face or a voice, and rebuild those places so that a perfect fake still fails. Talk to us about your company Read our research brief → What we defend against Four attacks that are documented, cheap to run, and already happening to companies the size of yours. Payments The executive on the video call An employee joins a call where everyone present is synthetic and is told to move money urgently. This is the best-documented class of attack, and the single largest known loss was US$25 million from one call. Phone The cloned voice A few seconds of public audio is enough to clone a voice well enough for a phone call. The request is always the same: something urgent, something confidential, something that skips the usual approval. Hiring The candidate who does not exist Remote interviews are passed by a face that is generated in real time. The prize is not the salary — it is an employee laptop, a VPN certificate and access to your internal systems. Identity The synthetic customer Selfie and document checks are answered with generated faces and forged papers. If you onboard customers or partners online, your verification step is a target in its own right. $25M Single largest documented loss from one deepfake video call (Arup, 2024) 1 in 5 Biometric fraud attempts that now involve a deepfake $40B Projected US losses to gen-AI-enabled fraud by 2027 Figures and their sources are set out in our research brief, Deepfakes & Startups — including who measured them and how much weight they deserve. How we work Every engagement is bespoke, but it runs in the same five steps. Find where trust is granted We map the moments where your company acts on the belief that someone is who they appear to be: payment approvals, supplier bank-detail changes, hiring and onboarding, password and MFA resets, access to production. Those moments — not your network — are the attack surface. Rebuild those moments so a perfect fake fails Every measure here is the same idea in different clothes: the request and its confirmation must travel by different routes. The attacker controls the route the request arrived on — so the confirmation has to come from somewhere else. You call back — you don't reply to what arrived. A request comes in by email, chat or video call? You confirm it by ringing that person on the number you already hold in your own records. Never the number, link or address that arrived with the request — that is exactly the part an attacker controls. That is what "call back" means: you start the call, to a contact nobody handed you. Two people above an agreed amount. A payment over a set threshold needs a second person who was not in the original conversation — so a deepfake would have to convince two people on two different channels. A phrase agreed in advance. For urgent requests, a word the real person knows and a deepfake has never heard. A supplier's bank details never change on the strength of an email. Only after a call to the number in your contract — not the one in the email. The goal is simple: no single video call, voice or message can move money or grant access on its own. Build the technical parts This is where we are a software company rather than a consultancy: approval flows and payment limits wired into the systems you already use, verification steps in your hiring and onboarding, an internal tool where none exists, logging that makes an attempt visible afterwards. We build it, deploy it and hand it over. Train the people who have to use it A procedure nobody remembers under pressure is not a procedure. Short, specific training for the roles that are actually targeted — finance, HR, IT support, assistants and executives — followed by a drill: a simulated urgent request, run with your consent, so you learn how your team behaves before an attacker does. Write down what happens when it does happen Who is called first, how a payment is stopped, which logs to preserve, what is said to the bank, to staff and to customers. An incident plan is worth most in the twenty minutes when nobody can think straight. What we will not sell you Two things worth saying before you spend money — ours included. Deepfake detection is not a solution. Detectors are trained on yesterday's generators, degrade on compressed video calls, and their vendors' accuracy numbers come from their own test sets. We deploy detection only where it demonstrably helps, and never as the thing standing between an attacker and your bank account. Process beats technology here. The attacks above all work by getting a human to skip a step. The defence that holds is the one where no amount of convincing removes the second channel — and that is cheap compared to the tooling that gets sold against this threat. We are not a law firm or an auditor. We do practical engineering, training and process design. If you need a formal certification or a legal opinion, we will say so and work alongside whoever provides it. Bruncsoft is a small studio, and you talk to the person doing the work. That is the reason we are fast, and also the reason we say plainly when something is outside what we do. Who this is for Companies that move money on request Finance teams small enough that one person can start a payment and an approval can be chased over chat. Companies hiring remotely If a person can be interviewed, onboarded and given a laptop without anyone meeting them, hiring is a way in. Companies verifying customers online Anywhere a selfie or a photographed document is accepted as proof of who somebody is. Startups with informal approvals Speed is the point of a small team — and it is exactly what these attacks are built to exploit. Start with a conversation Tell us how your company approves payments, hires and grants access. We will tell you where we would start, what it would take, and whether you need us at all. Scope and price are agreed individually, as with everything we build. Contact Bruncsoft Read the study first → © 2026 Bruncsoft™ · bruncsoft.com · Contact · Deepfakes & Startups Bruncsoft™ is a brand, not a company.