Each safety staff has a model of the identical nightmare: an worker receives a message that appears and sounds precisely prefer it got here from the boss — after which acts on it. Irrespective of how a lot coaching an organization supplies, one thing finally slips by way of the cracks, leaving the IT division scrambling. This underscores the significance of preparedness throughout the risk lifecycle.
Throughout a current webinar sponsored by Doppel and hosted by its chief technique officer, Bobby Ford, two NFL expertise leaders, Costa Kladianos, EVP and head of expertise for the San Francisco 49ers, and Christina Morillo, senior director and head of data safety for the New York Giants, walked by way of how AI has rewritten the social engineering playbook heading into the 2026 season. Their environments are excessive, however the classes apply on to any enterprise.
The risk didn’t change, however the economics did.
Social engineering stays one of the accessible methods for attackers to focus on a corporation. Generative AI has modified the velocity, scale, and believability of those assaults. “I don’t suppose that threats created by AI are a brand new factor,” Morillo stated. “I simply suppose that AI made it a bit of bit easier. Like, this course of may probably take minutes, whereas prior to now it might have taken a day or two or three.”
She additionally pointed to the collapse within the talent required. “Earlier than, we used to simply speak about script kiddies, and also you needed to know which instruments to make use of. Now it doesn’t actually take a lot. You may go to any of those fashions, and the instruments are good there. Simply pay $20 a month, and also you’re in.”
Ford cited analysis indicating that AI-enhanced phishing can produce increased click-through charges and that AI-assisted impersonation is growing. The velocity and scale of those assaults involved each executives, who stated the quantity dealing with sports activities organizations was already substantial.
The opposite change is in high quality. “Earlier than, it was once, ‘I’m from this nation, ship me your checking account, and I’ll ship you a billion {dollars},” Morillo stated. “Now it might be coming from a vendor, a accomplice, or somebody you’re employed with, and it will not be them. They’re simply very, very convincing now.”
Kladianos framed the deepfake downside in phrases most enterprises underestimate: the extra public your persons are, the extra uncooked coaching materials an attacker has. “Everybody is aware of who George Kittle and Christian McCaffrey are, and that makes them simple targets,” he stated. “It’s very simple to go on there, use social media, and deploy a deepfake, and it’s extremely convincing. The attention check is one thing, however they’re getting extremely good.”
Substitute your CEO’s keynote movies, your CFO’s earnings name audio, and your gross sales staff’s LinkedIn presence, and the publicity stays similar. The assault floor now extends far past methods IT controls, encompassing impersonated executives, pretend accounts, lookalike domains and cryptocurrency scams on exterior platforms.
Extra must-read AI protection
Sensible recommendation for IT and safety leaders
A number of defensible practices emerged that don’t require an NFL price range.
Make verification a course of, not a judgment name. Kladianos’ warning concerning the after-hours request is the session’s most transferable perception: “The assaults come at any time, and so they can come when your guard is down. That 2 a.m. name — I must get in, I want to do that.” His reply is gates and governance, and refusing to deal with low-friction requests as low threat. “That you must do this for stuff you take into account small, like password resets. They’re not small. That’s the gateway to what you’ve in your group. Safe your assets such as you safe your cash, as a result of they’re the identical factor.”
Morillo’s model makes use of out-of-band affirmation by default. “Certainly one of our gamers simply referred to as. How do I validate that that’s who that’s? They might spoof his quantity, they may spoof his no matter.” Her staff depends on face-to-face contact and pre-established facet channels for high-consequence requests. In apply: cash motion, credential resets, MFA enrollment, and entry escalation ought to all be confirmed on a second channel the requester didn’t select.
Cease assuming the attention check scales. Kladianos’s prescription is to battle hearth with hearth, pairing AI-based detection with human evaluation and steady training — a three-part mannequin he likens to scouting expertise, teaching instruments, and participant improvement. “You set all three collectively, and now you’re going to win video games.”
Make reporting simpler than clicking. This is without doubt one of the easiest probably high-value adjustments on the listing. “It shouldn’t be onerous for somebody to report,” Kladianos stated. “It needs to be simpler to report than to click on the phishing hyperlink.” Friction in your reporting workflow is a safety management you’ve quietly disabled.
Take away the disgrace. Morillo recognized the actual purpose reviews don’t arrive. “There’s at all times this sense of like, I did one thing improper, I’m embarrassed.” Her repair: make it secure to textual content her, name her, or stroll into her workplace and say, “I clicked on this, I entered my credentials, I’m sorry” — then reply with out punishment. “The response can be an enormous piece of that puzzle.” She additionally makes consciousness coaching private fairly than company: “I make it about that is what occurs at residence, that is what occurs together with your checking account, so it might resonate.”
Work the basics year-round as a substitute of constructing a guidelines. When requested what belongs on a preseason safety test, Morillo pushed again on the premise. “If you happen to keep prepared, you don’t should prepare,” she stated, citing steady assessments, penetration testing, MFA protection audits, patch cadence evaluations, and safety coaching that’s routinely triggered the second an account is created. “Simply because they’re fundamentals or fundamentals doesn’t imply they’re easy to do.”
Combine your instruments, even in case you can’t consolidate them. Morillo was blunt concerning the actuality of tooling: there isn’t a single pane of glass; threat and GRC platforms hardly ever combine cleanly; shadow IT and shadow AI create blind spots; and a platform can grow to be a single level of failure. Kladianos supplied this counterpoint: “Each system has to speak to one another. If you happen to’re having disparate methods right here and there, you possibly can miss one thing.”
Share intelligence together with your rivals. One continuously missed apply is peer collaboration. The executives stated NFL golf equipment change indicators of compromise, vendor assessments and notes about safety instruments. “We’re aggressive on the sphere, however we’re not aggressive behind the scenes,” Morillo stated. Kladianos supported this, explaining that if the Giants arrived at Levi’s Stadium with an incident, “we might 100% hop in and we’d each work collectively on that risk” whereas the sport was underway.
Get management buy-in, or don’t trouble. “If you happen to don’t have management’s buy-in, you don’t have something; it’s going to crumble,” Kladianos stated, crediting 49ers CEO Al Guido’s assist. His recommendation for incomes it: translate technical threat into enterprise threat, set up a cross-functional cybersecurity governance committee, and cease framing safety as a expertise downside. “It’s not an IT downside, it’s a enterprise downside.”
The road that ought to comply with IT leaders into their subsequent price range dialog is his description of the job: “Cybersecurity is sort of a referee — it’s greatest once you don’t discover it.”
For IT leaders, the fast takeaway is to determine which requests require secondary verification, check how simply staff can report suspicious messages and make sure that admitting a mistake triggers assist fairly than punishment. AI could make impersonation cheaper and extra convincing, however established verification procedures and speedy reporting can nonetheless restrict the injury.
Learn extra: A ClickUp API key uncovered by way of automated emails exhibits how routine enterprise workflows can inadvertently expose credentials and create broader safety dangers.
