1. Do you require layered verification for all financial requests?
Money has to change hands before somebody can steal it. Building airtight protocols around any alterations to payment requests can stop well-intentioned changes from becoming disastrous.
- Require two people to approve any change to standing payment instructions. The more eyes on each transaction, the more likely you are to catch something unusual.
- Implement a “call-back protocol” in which accounts payable staff must use a previously verified communication channel to confirm any unusual requests, especially if those requests come from executives. Never use the contact info provided in the communication requesting the change.
- Require staff to verify all banking changes, unusual or not, using a known, previously validated phone number.
2. Do you enforce strict email security controls?
Most email systems have built-in controls to help reduce the chances of a successful phishing attack. Make sure you understand what tools are available in your system – and turn them on.
- Use email banners that flag external senders with messages such as, “This email originated outside the organization.” Encourage your staff to pay close attention to these flags, especially when messages include links.
- Enable tools that open email links and attachments in a safe, isolated environment so malicious files can’t infect employees’ computers.
- Your email host should offer guidance on setting up email authentication tools (e.g., SPF, DKIM and DMARC) which do behind-the-scenes checks to confirm an email actually came from the address in the “from” field.
3. How strong is your vendor management process?
I prefer for organizations to formalize protocols for vendors that make legitimate requests to update contact and bank account information. Having a formal process in place makes it more difficult for criminals to try to force you to take unnecessary shortcuts.
- Maintain a centralized, verified vendor directory that includes approved contact methods so your teams have a single, easily accessed source of truth for that information.
- Require vendors to follow a secure change-request protocol to change the information in that directory (for example, a written request followed by phone verification).
4. Do you encourage a “pause and validate” culture?
Criminals often circumvent protocols by pressuring people to move quickly. To defend against that tactic, I recommend training staff to slow down if they feel pressured, rushed or manipulated.
- Establish a hard rule that all financial approvals must follow established accounts payable workflows and protocols, without exception, no matter who makes the request.
- Make it safe to question unusual requests, no matter who they appear to come from, even if the sender appears to be a high-ranking executive from your organization or an external one.
- Reinforce the message that no one will be punished for taking steps to prevent fraud
5. How strong are your technology controls?
Use technology to your advantage. AI-based controls can detect patterns of fraudulent behavior and help reinforce good security practices.
- Use AI-based fraud detection to flag unusual behavior or payment deviations so your team can follow up on them.
- Enable and enforce multi-factor authentication and disable outdated email access protocols (such as IMAP and POP) that can allow users – or attackers – to bypass it.
6. Do you conduct regular fraud simulations?
It’s better to catch weak spots in your defenses through tests than through experience. Keep your staff and your protocols up to date.
- Run realistic business email compromise and invoice fraud tabletop exercises with accounts payable, treasury and executives.
- Test staff regularly using simulated fraud attempts in addition to phishing tests.
7. Have you segregated duties in finance operations?
I advise against placing all the responsibility to detect and prevent potential fraud on a single person. Two people working together have a better chance of identifying an unusual request than one person working alone.
- Different employees should be responsible for approval, accounting/reconciling and asset custody.
- No single person should be able to initiate, approve and record transactions.
8. Do you monitor financial accounts daily?
Since every transaction is an opportunity for fraud, regular monitoring is critical. The sooner you catch something unusual, the sooner you can take action to mitigate it.
- Set up real-time alerts for outgoing wires or ACH changes.
- Ensure daily reconciliation to shorten the time window for detecting fraud.
Stay on top of cybersecurity controls
Cybersecurity is an ongoing, multifaceted effort in every organization. Identifying threats and assembling controls to mitigate those threats is the first crucial step. Reviewing controls and shoring up additional areas of weakness should be a regular, ongoing process as well.