Arup's CIO Rob Greig later said he created a real-time deepfake of himself in 45 minutes using open-source software, demonstrating the low entry barrier. The employee acted correctly by trying to verify the request, but he changed the communication channel rather than the source of trust, as both the email and the video conference were controlled by the same attackers. Experts from Garda and MIREA Russian Technological University predict a shift in attacks from pre-edited videos to real-time voice and image substitution. The article proposes six rules for protection: the secrecy of a request should raise suspicion, confirmation of unusual orders through an independent channel involving a second person, a multi-factor procedure for large transactions, written recording of decisions that cannot be made based on a single call, similar logic for personal life, and awareness that video and voice are no longer standalone proof. It is also noted that NGFW cannot detect a deepfake in an encrypted video stream, so protection should be built on a multi-layered approach, including financial regulations.