Emergency Response
Immediate Actions (First 24 Hours)
Hour 0-2: Contain
-
DOCUMENT everything
- Screenshot/download the deepfake
- Record URLs and timestamps
- Note all distribution channels
-
ALERT key stakeholders
- Security team
- Legal counsel
- PR/Communications
- Executive leadership
-
PRESERVE evidence
- Save original files
- Capture metadata
- Document chain of custody
Hour 2-6: Assess
□ Identify the deepfake type
□ Determine distribution scope
□ Assess potential damage
□ Identify affected parties
□ Evaluate legal implications
Hour 6-24: Respond
- Issue takedown requests
- Contact platforms (social media, hosting)
- Notify affected individuals
- Prepare public statement (if needed)
- Activate crisis communication plan
Response Team Structure
Incident Commander
├── Technical Lead
│ ├── Detection & Analysis
│ └── System Security
├── Legal Counsel
│ └── Takedown Requests
├── Communications Lead
│ └── Public Messaging
└── Security Lead
└── Containment
Platform Takedown Requests
Template
Subject: Urgent Takedown Request - Deepfake Content
Platform: [Name]
Content URL: [Link]
Type: Deepfake/Manipulated Media
Affected Party: [Name]
Evidence:
- Original content: [Link]
- Forensic analysis: [Attached]
- Legal basis: [DMCA/Platform Policy]
Request immediate removal.
Contact: [Your details]
Urgency: CRITICAL
Next Module: Prompt Injection Attacks →