When the Fake CEO Speaks First: The Deepfake Crisis Plan your Board Needs Now
When the fake CEO speaks first: the deepfake crisis plan your board needs now
In January 2026, the Bombay Stock Exchange issued an urgent warning to investors. Fabricated videos of its chief executive were circulating online, promoting stock tips he had never given. The face was his. The voice was his. The advice was invented. This was not a distant hypothetical, and it points to a change every board should treat as immediate.
The World Economic Forum ranks misinformation and disinformation among the most severe short-term global risks for the third year running, second only to geoeconomic confrontation in its January 2026 assessment. Generative tools have lowered the cost of producing convincing fakes to near zero. A single laptop can now manufacture a video that used to require a studio. For a listed company, a founder-led startup, or any organisation whose value rests on trust, that changes the shape of reputational risk.
The threat has a balance-sheet cost
Deepfakes have crossed from novelty to weapon. Security analysts describe synthetic content engineered to erode confidence among investors, customers, and partners. The attack does not need to fool everyone. It only needs to seed enough doubt to move a share price, stall a funding round, or send a customer to a competitor.
The pattern is now frequent enough to track. One January week alone brought three high-profile synthetic-media crises into the headlines. Each followed the same logic. A fabricated clip appears, it spreads through social channels and messaging apps, and screenshots outrun any correction. By the time the real company responds, the fake has already been seen, shared, and believed by thousands.
For Australian founders and executives, the exposure is direct. A fabricated video of a chief executive announcing a product recall, a data breach, or a change of strategy can reach staff, customers, and journalists within minutes. The company then faces a choice with no comfortable option. Stay silent and the fake fills the vacuum. Respond and risk amplifying a clip many people had not yet seen.
Smaller companies are not too small to be targeted. Early-stage founders often assume synthetic attacks are a problem for household names, yet a startup mid-raise is an easier and more rewarding target. Its audience is concentrated among a handful of investors and partners, its reputation is young and still forming, and it rarely has a communications plan in a drawer. A single convincing fake, sent to the right five people at the wrong moment, can do more damage to a Series A company than to a listed one with a crisis team on retainer.
Why deepfakes break the standard playbook
Most crisis communications training assumes the problem is a true event handled badly: a product fault, a leak, an executive misstep. The organisation controls the facts, so the task is to acknowledge, explain, and correct. A synthetic-media crisis inverts that. The event never happened, yet the evidence looks real.
This creates a trust problem that text cannot solve. Video and audio carry the weight of proof in most people's minds. When audiences treat synthetic content as evidence, a written denial sounds like exactly what a guilty party would say. The burden of proof lands on the victim, and proving a negative in public is slow, technical, and unconvincing to a scrolling audience.
Speed compounds the problem. A fabricated clip is designed to travel, and platform algorithms reward the emotional reaction it provokes. The organisation, meanwhile, has to verify what it is seeing, brief legal counsel, and clear a statement. That gap between the attack and the answer is where the damage settles. Relying on a well-written statement alone is now a liability, because the response has to move at the speed of the platforms carrying the fake.
The preparedness gap
Here is the uncomfortable part. Fewer than half of businesses hold a formal, documented crisis communications plan at all. Of those that do, almost none have written a plan for the specific case where the crisis is a convincing fake of their own leadership. The playbook on the shelf assumes the facts belong to the company. A deepfake assumes the opposite.
Boards tend to treat deepfakes as a technology problem, so the question goes to IT or cyber security. Detection tools have a role. They cannot decide who speaks, on what channel, in what tone, and within what window. Those are communications decisions, and they need to be settled before the crisis, not invented during it. A board that has never rehearsed a synthetic-media scenario will spend its most valuable minutes debating process while the fake keeps spreading.
What a workable plan looks like
A deepfake response plan does not need to be long. It needs to be decided in advance and small enough to run under pressure. Four elements carry most of the weight.
A verification chain. Name in advance who confirms whether a piece of content is genuine, and how fast they can do it. This usually pairs a technical check with a simple human one, such as a known executive confirming they never recorded the clip. The goal is a defensible answer within minutes, not hours, so the company can respond with confidence rather than caveats.
Pre-cleared channels and holding language. Decide now where the company will speak first: its own site, its verified social accounts, a direct note to staff and investors, or all three at once. Draft holding language before any crisis, with the specifics left blank. Owned channels are the one place the company controls the message completely, so they carry the correction while journalists check their inboxes.
A spokesperson ready for camera. Because the fake is visual, the strongest correction is often visual too. A brief, calm, on-camera statement from the real executive does what a press release cannot. It re-establishes the genuine person in the genuine setting. That only works if the spokesperson has been prepared and the studio-free setup has been tested in advance.
A stakeholder call list. Regulators, key investors, major customers, and priority journalists should hear from the company directly, before they see the fake elsewhere. A pre-built list with named owners turns a scramble into a sequence. The organisations that recover fastest are usually the ones whose most important audiences got a personal message early.
The first 60 minutes decide the story
Synthetic-media crises are won or lost in the first hour, so the plan should read as a sequence rather than a policy. The opening move is verification, because a public response before the company knows what it is dealing with can validate a fake or deny a truth. The second move is containment on owned channels, where a short, clear correction goes live on the site and verified social accounts while the fake is still circulating. The third move is direct contact with the audiences who can least afford to be wrong about the company, which usually means regulators, major investors, and priority journalists in that order.
Australian organisations carry an extra layer of obligation here. A listed company that becomes the subject of a market-moving fake may face continuous-disclosure questions from the ASX, and a rushed or contradictory public statement can create a second problem on top of the first. Financial-services and other regulated clients have their own notification duties. A response plan built with legal and compliance input, and agreed before any incident, keeps the communications answer and the regulatory answer aligned instead of in conflict. That alignment is hard to improvise while a fabricated clip trends.
Rehearsal is what turns a document into a capability. A short tabletop exercise, run once or twice a year, walks the board and the executive team through a realistic scenario and exposes the gaps that only appear under pressure. Who has the authority to authorise the on-camera statement at 11pm on a Friday. How fast can the verification call actually happen. Which channels are ready to publish without a developer. Teams that have answered these questions in a calm room answer them far faster in a real one, and the difference shows in the coverage.
Preparation is the reputation dividend
The organisations that come through a synthetic-media attack with their credibility intact share one trait. They decided how to respond before they needed to. The plan converts a moment of panic into a rehearsed sequence, and it gives the board the one thing a fast-moving fake tries to steal, which is time to respond on its own terms.
This is where a communications partner earns its place. At Third Hemisphere, crisis and issues work centres on preparation: mapping the scenarios a client is most exposed to, agreeing the verification chain and the channels in advance, and readying spokespeople so the first genuine response is calm and fast. For founders in capital markets, climate, and deep tech, where a single fabricated clip can rattle investors mid-raise, that preparation is a direct protection of enterprise value.
The technology behind deepfakes will keep improving, and detection will always lag creation by a step. The defensible position is not perfect detection. It is a board that has already decided who speaks, where, and how fast, so that when the fake CEO speaks first, the real one is close behind.
The single takeaway: A deepfake attack is a communications crisis wearing a technology costume, and the only reliable defence is a response plan your board has agreed and rehearsed before the fake appears.