ciso.diy
Synthetic Media & Deepfake Defense Kit preview
Governance deepfakesynthetic mediavoice cloningimpersonation

Synthetic Media & Deepfake Defense Kit

Thirty seconds of audio clones a voice. Defend your executives, staff and brand from cloned voices and fake video — and produce AI-generated content with the consent, disclosure and provenance every platform and regime now requires. Two halves: Defend and Produce.

What this actually gives you

  • The control against a cloned CFO is a callback, not a detector. No money, credential, data or access moves on a phone, video or message instruction without out-of-band verification through a channel the requester did not choose.
  • TAKE IT DOWN's 48-hour platform takedown became enforceable 19 May 2026; 33 states regulate election deepfakes; about a dozen give people a statutory right in their voice and likeness against AI replicas.
  • Build disclosure once. A visible caption, the platform label, C2PA credentials and a register row satisfy EU Article 50, the Chinese, Korean and Indian rules, the YouTube, TikTok and Meta policies, New York’s synthetic-performer ad rule and the state election statements together.
  • Most organisations are on both sides — a target of fakes and a producer of synthetic content. Anyone running user-generated content is also a host, with a third duty.
  • NCII is handled as an employee-safety incident first and a takedown second, with the affected person’s consent governing what gets reported.

The control against a cloned CFO is a callback, not a detector. That is the rule the whole Defend half is built on: no money, credential, data or access moves on a phone, video or message instruction without out-of-band verification through a channel the requester did not choose. Detection tools lose to better models every quarter. A callback to a number already in your directory does not.

Most organisations are on both sides of this. File 01's exposure profile asks eleven questions and almost everyone answers yes twice: you are a target of synthetic media, and you are a producer of it — AI presenters, dubbing, generated video, synthetic voice in your own marketing. Anyone running user-generated content is also a host, with a third duty.

What changed in 2026. TAKE IT DOWN's 48-hour platform takedown became enforceable on 19 May 2026, with the FTC behind it. 33 states regulate election deepfakes. About a dozen now give a person a statutory right in their own voice and likeness against AI replicas. EU Article 50 disclosure has applied since 2 August 2026, YouTube, TikTok and Meta labels are mandatory, and China, Korea and India have labelling regimes of their own.

Build disclosure once. The Produce half is anchored on a single practice — a visible caption, the platform's native label, C2PA content credentials, and a register row — that satisfies EU Article 50, the Chinese, Korean and Indian labelling rules, the YouTube, TikTok and Meta policies, New York's synthetic-performer advertising rule and the state election statements together. Doing it once per regime is how teams end up doing it inconsistently or not at all.

What you get

01 Exposure Profile & Regime Matrix (XLSX) — eleven questions returning your Defend, Produce and Host exposure, against fifteen regimes with status, duty and clock: TAKE IT DOWN, the FTC Impersonation Rule, state replica, election and NCII laws, New York's synthetic-performer ad rule, California SB 942, EU Article 50, the DSA, Chinese, Korean and Indian labelling, and platform policy.

02 Impersonation Monitoring & Takedown Register (XLSX) — the protected-assets inventory (people, brands, handles, domains — what a cloner has to work with), the incident register with hours-to-removal as the metric that matters, and the takedown and reporting contacts, to be filled in before you need them rather than found at 2 a.m.

03 Verification Protocol & Takedown Playbook (DOCX) — out-of-band verification rules per request type, the first-hour playbook, category paths for fraud, brand, reputation, NCII and political, executive-protection add-ons, the TAKE IT DOWN notice-and-removal process for anyone hosting UGC, and six communication templates.

04 Provenance & Disclosure Standard (DOCX) — what counts as synthetic, C2PA content credentials, disclosure wording per context including the New York and state election statements, a review-before-publish gate, provider and host duties, and an exceptions section that grants none for disclosure or consent.

05 Platform Disclosure Matrix & Content Register (XLSX) — per platform and jurisdiction: whether a label is required, how it is applied, the ad rules, whether C2PA is read, the political rule — plus a content register carrying consent, disclosure, credentials, label and sign-off for every piece you publish.

06 Likeness & Voice Consent Pack (DOCX) — when consent is required, the digital likeness and voice release, an employee addendum, a talent and synthetic-performer rider, documentation for a synthetic persona built from no one, and the consent register.

07 Leadership One-Pager (PPTX) — two slides: target and producer, then the plan, the exposure and the decisions, with owners named across Finance, Comms and the GC.

08 Practitioner Guide (PDF) — why 2026, the two halves, the regime map, verification, monitoring and takedown, employee safety, disclosure once, provenance, consent, platforms and UGC, metrics, a ninety-day plan, failure patterns and an FAQ.

deep01.json — regimes, categories, disclosure defaults and register schemas, machine-readable.

Non-consensual intimate imagery is handled as an employee-safety incident first and a takedown second, with the affected person's consent governing what gets reported and to whom. Most brand-protection products treat it as a content problem. It is not one, and the difference decides whether the person involved is supported or processed.

Pairs with the Cyber Insurance Application Readiness Kit for the payment-verification control an insurer will ask about, the Executive Tabletop Kit whose scenario 5 is the drill for exactly this, I've Been Breached when it becomes fraud or a breach, the EU AI Act Compliance Clock for Article 50 in its wider context, and the Agentic AI Security Program Kit for agents that publish content of their own.

A practitioner's toolset, not legal advice. The releases in file 06 and the statements in file 03 §6 are documents you execute or publish under your own name — have counsel review them, and note that pending federal bills and litigated state statutes are marked "verify final" rather than presented as settled.

What's included

  • Complete Library (.zip) — all formats included — fully editable
  • Instant download after purchase
  • Free updates — re-download when we release new versions
  • Practitioner License: unlimited client use (vCISO / MSP)

Choose your license:

  • Secure checkout via Stripe
  • All major cards accepted
  • 30-day satisfaction guarantee
Version 1.0
Last updated 2026-09-04
Pages 8