Home / Current Issue / Paper 1714182
Deepfakes as a Cybersecurity Governance Problem: Legal Gaps, Institutional Risk, and Public Authority
Subject area: Science,Engineering and Technology · Area of research: Cybersecurity
Abstract
Deepfakes are increasingly treated as a problem of misinformation, media ethics, or individual harm. This article argues that deepfakes should instead be understood as a systemic cybersecurity risk to public institutions. By enabling realistic impersonation without technical intrusion, deepfakes undermine authentication, disrupt public communications, and weaken institutional authority. Existing legal frameworks address some downstream harms, such as defamation or fraud, but they do not adequately account for deepfakes as a threat to secure governance. This article examines how deepfakes challenge traditional cybersecurity models, evaluates the limits of current legal responses, and argues for integrating synthetic media risks into cybersecurity law, public-sector governance, and incident response frameworks.
Keywords
Deepfakes, Cybersecurity Governance, Institutional Trust, Public Sector Cybersecurity, Synthetic Media
References
[1] Borky, J.M. and Bradley, T.H. (2019). Protecting Information with Cybersecurity. Effective Model-Based Systems Engineering, [online] 1(1), pp.345–404. https://doi.org/10.1007/978-3-319-95669-5_10.
[2] Cisco (2025). What Is Threat Modeling? [online] Cisco. Available at: https://www.cisco.com/site/us/en/learn/topics/security/what-is-threat-modeling.html.
[3] Commonwealth of Pennsylvania (2025). Gov. Shapiro Signs New Digital Forgery Law. [online] Available at: https://www.pa.gov/governor/newsroom/2025-press-releases/gov--shapiro-signs-new-digital-forgery-law.
[4] Congress (2019). H.R.145 - 100th Congress (1987-1988): Computer Security Act of 1987. [online] Congress.gov. Available at: https://www.congress.gov/bill/100th-congress/house-bill/145.
[5] George, A. (2024). Defamation in the Time of Deepfakes. [online] Social Science Research Network. https://doi.org/10.2139/ssrn.4719803.
[6] Jampani, S.K. (2025). Social Engineering 2.0 Deepfake and Deep Learning-based Cyber-attacks (Phishing). International Journal For Multidisciplinary Research, 7(1). https://doi.org/10.36948/ijfmr.2025.v07i01.35527.
[7] National Conference of State Legislatures (2024). Deceptive Audio or Visual Media (‘Deepfakes’) 2024 Legislation. [online] www.ncsl.org. Available at: https://www.ncsl.org/technology-and-communication/deceptive-audio-or-visual-media-deepfakes-2024-legislation.
[8] NIST (2025). Cybersecurity Framework. [online] National Institute of Standards and Technology. Available at: https://www.nist.gov/cyberframework.
[9] Pedersen, K.T., Pepke, L., Stærmose, T., Papaioannou, M., Choudhary, G. and Dragoni, N. (2025). Deepfake-Driven Social Engineering: Threats, Detection Techniques, and Defensive Strategies in Corporate Environments. Journal of Cybersecurity and Privacy, [online] 5(2), p.18. https://doi.org/10.3390/jcp5020018.
[10] Ponemon Institute Research (2025). Deepfake Deception: How AI Harms the Fortunes and Reputations of Executives and Corporations | Ponemon-Sullivan Privacy Report. [online] Ponemonsullivanreport. Available at: https://ponemonsullivanreport.com/2025/04/deepfake-deception-how-ai-harms-the-fortunes-and-reputations-of-executives-and-corporations/.
[11] Romanishyn, A., Malytska, O. and Goncharuk, V. (2025). AI-driven disinformation: policy recommendations for democratic resilience. Frontiers in Artificial Intelligence, 8. https://doi.org/10.3389/frai.2025.1569115.
[12] Sekara, H. (2020). A Look at the Computer Security Act of 1987 | Tripwire. [online] www.tripwire.com. Available at: https://www.tripwire.com/state-of-security/computer-security-act-of-1987.
[13] Walsh, M. (2024). A Framework for Detection in an Era of Rising Deepfakes. Cybersecurity Engineering. https://doi.org/10.58012/e5sh-hp94.
[14] Yuille, T. (2025). ANALYSIS: Deepfake Election Laws Spread Amid Court Challenges. [online] @BLaw. Available at: https://news.bloomberglaw.com/bloomberg-law-analysis/analysis-deepfake-election-laws-spread-amid-court-challenges-12.
How to cite this paper
@article{1714182,
author = {Tomilola Ayeni},
title = {Deepfakes as a Cybersecurity Governance Problem: Legal Gaps, Institutional Risk, and Public Authority},
journal = {Iconic Research And Engineering Journals},
year = {2026},
volume = {9},
number = {8},
pages = {280-283},
issn = {2456-8880},
url = {https://www.irejournals.com/formatedpaper/1714182.pdf},
abstract = {Deepfakes are increasingly treated as a problem of misinformation, media ethics, or individual harm. This article argues that deepfakes should instead be understood as a systemic cybersecurity risk to public institutions. By enabling realistic impersonation without technical intrusion, deepfakes undermine authentication, disrupt public communications, and weaken institutional authority. Existing legal frameworks address some downstream harms, such as defamation or fraud, but they do not adequately account for deepfakes as a threat to secure governance. This article examines how deepfakes challenge traditional cybersecurity models, evaluates the limits of current legal responses, and argues for integrating synthetic media risks into cybersecurity law, public-sector governance, and incident response frameworks.},
keywords = {Deepfakes, Cybersecurity Governance, Institutional Trust, Public Sector Cybersecurity, Synthetic Media},
month = {February},
}