
The Internet became the Attack Surface. Defense has to Catch up.
The threshold most enterprises haven't reckoned with
In one anonymized case from Outtake internal analysis, a global consumer brand had more than ten scam domains impersonating it in a single day. One event-themed fraud campaign had already generated an estimated $130,000 in fraudulent sales before the security team caught it.
The team found it manually. Their existing tools did not flag it.
That is not a story about one unlucky company. It is what the open internet looks like once it becomes the enterprise attack surface, and once AI ends up in the hands of people exploiting the trust a company has spent years building.
For a decade, security had a clear job: protect the inside. Endpoints, identities, networks, cloud, email. The industry got good at it. So the attackers moved. They went where the doors were still open: the open internet, where your brand is visible, your executives are exposed, your products are copied, and your customers decide in seconds whether what they are looking at is really you.
The scale problem
The internet has already crossed a threshold most enterprises have not fully reckoned with. Automated traffic now makes up more than half of measured web requests. AI bot activity has increased over the past year. The result is an external environment where deception can be generated, distributed, tested, and rebuilt faster than most human-led programs can respond to.
The report, produced by Cybersecurity Insiders with support from Outtake, surveyed 1,138 security and risk leaders. Only 7% describe their program as leading. 53% had an executive or employee impersonated, and 47% faced coordinated multi-channel campaigns. A separate 47% faced confirmed or suspected synthetic-media impersonation, and 42% say attacks now move faster than detection.
This is the new digital risk baseline. What used to look like isolated impersonations and one-off fraud now behaves like a coordinated, industrial-scale operation.
The asset under attack is trust: trust in your executives and employees, trust in your brand, trust in the workflows that move money, and trust in the channels customers use to reach you.
Entity is the new perimeter
The cybersecurity industry spent the last decade perfecting the art of protecting things it controls: endpoints, networks, cloud infrastructure, identity access management. Zero trust became the rallying cry. MFA became table stakes.
And yet the most damaging digital trust attacks do not need to breach a firewall.
A finance worker can be tricked by a synthetic executive on a video call. A customer can be routed from a fake social account to a phishing domain registered last Thursday. A vendor can receive a message from what appears to be the CFO. A prospective hire can apply through a cloned careers portal. A customer can pay for a fake support site because it looks more official than the real one.
No malware. No firewall event. No endpoint alert. Anattacker wearing the company's face.
That is why identity alone is too narrow a frame. The external perimeter is made up of the entities a company exposes to the world: brand, people, locations, and products. They live across social platforms, domains, marketplaces, app stores, ads, dark web forums, and public and monitored messaging channels.
Security teams are no longer protecting infrastructure alone. They are protecting the trust that lets a customer believe the account, the domain, the message, the face, and the offer are real.
The executive impersonation problem
Executive and employee impersonation is no longer rare. The report puts it at 53% of organizations in the past year.
Outtake's 2026 State of Executive Impersonation Report looked closer at where those attacks actually land. Drawn from a sample of 270 named executives and 43,035 impersonation alerts observed across 2025, the pattern is specific, not evenly spread. More than half of the alerts, 53.83%, came from fake profiles on social platforms. Video and visual platforms accounted for another 35.05%. Open community forums made up 6.84%, and executive lookalike domains made up 3.57%.
Attackers are using synthetic media to impersonate executives on live video calls, in voice messages, across social platforms, and inside professional networks. The old signals that helped people spot fakes are disappearing. Bad grammar, distorted images, and awkward phrasing are no longer reliable tells.
Response speed is where most programs fail operationally, not just technically. An attacker can stand up a credible impersonation in minutes. Most legacy digital risk protection programs still respond in days, and to the single artifact in front of them, not the campaign behind it.
For Pershing Square, Outtake scanned more than 11,000 social profiles and eliminated over 400 executive impersonations targeting Bill Ackman and the firm.
Most executive protection programs were built around physical security, personal travel risk, and access control. None of that protects against a convincing fake LinkedIn profile of a CFO soliciting wire transfers from vendors, or a cloned executive voice authorizing an urgent payment.
The CISO has a firewall. The executive has an external perimeter.
Why point solutions keep failing
Here is the uncomfortable part: the tools most enterprises have deployed are losing this fight.
Not because the teams running them are not talented. Not because the vendors do not care. Because the architecture was built for a different era.
Classic Digital Risk Protection was built around a manual motion. Scan for something wrong. Flag it. Route it to an analyst. File a takedown. Wait. That worked when attacks were slower, more isolated, and easier to identify as single artifacts.
That internet is gone. Prior-generation tools remove artifacts. Prior-generation models scale with queues and manual review, so their cost to defend rises with the scale of the attack while the attacker's cost falls. Those two lines never meet.
Today, a single visible artifact is rarely the whole attack. Behind a spoofed domain, fake social account, synthetic persona, or synthetic video is an operation: shared infrastructure, reused templates, monetization paths, ad networks, messaging channels, operator behavior, and staged assets waiting for the next wave.
Most programs still stop too early. The report found that 34% close cases at takedown without pursuing the adversary behind them. Only 16% map the broader campaign or attempt attribution. Just 5% conduct full campaign attribution. Most lack what we call narrative intelligence.
The same campaign can return under a new face. The artifact was removed. The operation survived.
Next-Gen DRP is not faster manual work
Next-Generation Digital Risk Protection (Next-Gen DRP) is not the old approach accelerated. It is a different model: machines doing the work, humans setting the judgment.
It starts by indexing the open internet continuously, scoped to the entity surface a company exposes: brand, people, locations, and products. It then runs intelligence over that index so every signal can be investigated, connected, attributed, remediated, and learned from.
The outcome is not an alert pile. It is a Threat Graph. One signal can lead to the broader operation: fake accounts, domains, ads, personas, shared infrastructure, operator patterns, blast radius, and choke points that can collapse the campaign.
This is the shift from takedown to operator-level remediation. Many tools stop at the artifact. Next-Gen DRP has to dismantle the operation.
Two capabilities make that real. Adaptive Workflows surface narrative intelligence from the noise, then route each threat to the action that fits: takedown, impersonation protection, monitoring, or a SOAR handoff. Reinforcement Learning gets smarter with every interaction, sharpening detection and generating the evidence packages that takedowns and external correlation depend on.
Agent vs. agent
There is no version of this story where a team of human analysts, scanning manually and submitting platform forms, outruns adversarial AI running coordinated impersonation attempts across domains, social, ads, app stores, dark web, and public and monitored messaging channels.
The math does not work. The model does not scale.
An AI-native platform changes the operating model. Agentic Search maps the full digital footprint and auto-registers new assets as they appear, reducing blind spots across impersonation protection, disinformation security, and narrative intelligence. Recon turns one signal into the whole operation. Triage enriches, prioritizes, and feeds the Digital Reservoir. Remediation acts at the network level and closes the loop. Every incident improves the next response.
The report shows why that loop matters. Only 7% have end-to-end visibility from reconnaissance through fraud. Only 11% sustain highly coordinated cross-team response at attack tempo. A separate 5% correlate external signals with internal fraud data in real time. The detection-to-response window has moved past what humans can close by hand.
At machine speed, response has to become a connected loop: detection, investigation, attribution, takedown, verification, and learning. Humans set policy, judgment, and escalation thresholds. Agents execute approved operational steps that can no longer be sustained manually.
Digital trust is the mission
When a customer clicks what they believe is the company's login page, they are extending trust. When a prospective hire applies through what they believe is the careers portal, they are extending trust. When an investor wires funds to what they believe is the company's treasury account, they are extending trust. When an employee follows instructions from what appears to be an executive, they are extending trust.
The brands that get hurt are not the ones without a security team. They are the ones without visibility into the attack surface that lives outside their walls.
Digital Risk Protection (DRP) is the market security leaders are funding now. Digital Trust is the outcome the market is converging toward. Outtake enters as Next-Generation Digital Risk Protection (NGDRP) because that is the problem buyers need solved today, and scales on a model built for continuous operation, not one-off response: agents working continuously, intelligence compounding over time, Threat Graphs replacing alert piles, and operator-level remediation replacing one-off takedowns.
The perimeter did not die. It expanded into the open internet. The defense has to expand with it.
