RiskCompli

← All insights

Compliance By SafeCompli · 28 May 2026

Does Your "Meet Our Team" Page Put Your Staff at Risk? I'm Genuinely Not Sure.

Originally published on SafeCompli, our parent brand. Reproduced here for RiskCompli readers.

Does Your "Meet Our Team" Page Put Your Staff at Risk? I'm Genuinely Not Sure.

A video by Dr. Catherine Knibbs, a child safety and online harms specialist in the UK, circulated this week about something deeply disturbing. Schools are being blackmailed with AI-generated videos created from ordinary photographs taken off school websites. The National Crime Agency and the Internet Watch Foundation have both confirmed the threat is real. Some schools are already removing pupil photographs entirely.

It hit hard as a parent.

But once I'd sat with it for a while, it got me thinking from a different direction entirely.

The Business Parallel Nobody Seems to Be Talking About

How many businesses have a "Meet Our Team" or "About Us" page? A face, a name, a job title — put there in good faith, because it humanises the business and builds trust with potential clients.

One photograph is now enough to generate a convincing deepfake video of a real person.

We already know this isn't theoretical in a business context. In January 2024, Arup — a British engineering firm — lost $25 million when a finance employee joined what appeared to be a video conference with the company's own CFO and senior colleagues. Familiar faces. Familiar voices. All deepfakes, generated from publicly available images of real people.

That was financial fraud. But the technology is identical to what is now being used against schools. The only difference is what the attacker chooses to do with the output.

The Question I Can't Cleanly Answer

What happens when the attack is aimed not at the company's bank account, but at the individual themselves?

A director. A team manager. A member of staff who happens to appear on the website. If someone were to generate fake explicit content of that person from a professional headshot, and threaten to distribute it unless money was paid — what would the impact be on them personally?

From a health and safety standpoint, psychological wellbeing is as much within scope as physical safety. There are documented cases where deepfake sextortion has had catastrophic consequences for victims. The FBI has issued a formal public warning about it. Dentons, the global law firm, issued a specific alert about deepfake extortion schemes targeting executives in July 2025.

This is not a fringe concern anymore.

Where I Actually Land

Honestly? I don't have a clean answer, and I'm not sure anyone does yet.

Removing team photographs removes the human face of a business. For smaller businesses especially, that matters. People work with people they trust, and a face and a name help build that before the first conversation even happens.

But the risk calculus has shifted. And I'm not sure most businesses have properly sat with the question of whether publishing named, photographed staff members on a public website — something that would have seemed entirely unremarkable two years ago — now carries a different kind of liability.

Is it a foreseeable risk to an individual's psychological wellbeing? Probably. Does that mean employers need to think about it differently? I think it does.

But what the right answer looks like in practice — whether that's removing photos, using illustrations instead of real headshots, building response plans for staff who are targeted, or something else entirely — I don't think there's a settled view on that yet.

I'm putting this out there because I'm genuinely curious what others think, particularly those running businesses where staff photographs are prominent. Has this crossed your mind? Has your business made any changes?

I'd rather this be a conversation than a post with a neat conclusion that doesn't really exist.

www.safecompli.co.uk

Sources: