Phishing Is a Process Problem, Not a Technology Problem
The story is always roughly the same. An email arrives from a supplier saying their bank details have changed. It looks right. The logo is right, the signature block is right, it is even a reply to a real thread. Somebody in accounts updates the record, the next payment goes out, and nobody notices for three weeks.
Nothing about that involves clever technology. It works because there was no step in the process that would have caught it.
Filters are necessary and insufficient
Email filtering catches the obvious volume, the badly written attempts and the known bad senders. That is worth having, and every business should have it switched on.
The messages that cause real losses are the ones filters are least equipped to judge. A short, plausible, well written email from a real person's compromised account, referencing a real invoice, sent at a believable time. There is nothing technically wrong with it. The content is the attack.
So the control has to sit somewhere else, in what your business does before money moves or access changes.
The three requests worth protecting
Almost every costly incident of this kind is one of three requests.
- Change where money goes. New bank details, a different account, an urgent payment to a new supplier.
- Change who can get in. A password reset, access for a new contractor, a mailbox rule, a phone number on an account.
- Send something sensitive. Payroll data, customer records, a copy of a contract, the employee list.
You do not need a broad security programme to protect these. You need a documented rule for each one, and enough consistency that following it is not a judgement call.
The control that works is boring. Verify the request through a channel the requester did not choose.
Out of band verification, in plain terms
Whoever sent the request also chose the channel. If you reply to the email, you are trusting the thing you are trying to check.
The rule is to verify using contact details you already hold, from a record that existed before the request arrived. Phone the number on the signed contract, not the number in the signature. Speak to the person, not to a voicemail. For an internal request, walk over or use a different system.
Two details make this actually work. It applies to everyone including the owner, because impersonating the boss is the most common version. And nobody has to explain why they are doing it, because it is the rule rather than an accusation.
Reduce the number of people who can be targeted
If four people can change bank details, you have four chances to get this wrong. If one can, and that one has a required second approval, you have a much narrower target.
The same logic applies to access. Fewer administrators, fewer shared logins, fewer standing permissions that nobody reviews. This is ordinary operational hygiene, and it happens to be the most effective thing you can do about social engineering.
Make the pause acceptable
Urgency is the tool every one of these messages uses. The payment is due today. The client is waiting. I am about to get on a flight.
That pressure only works if your culture treats a delay as a failure. So say the opposite out loud, in advance and more than once. Nobody will ever be in trouble for taking twenty minutes to verify a payment change. A late payment is an inconvenience. A misdirected one is a loss.
Managers have to mean this, because the first time somebody is chased for being slow, the control is gone.
Plan for the click
Somebody will click eventually, and the goal is a fast report rather than a perfect record.
Have one obvious place to report, staffed by a person who responds quickly and kindly. Write down the first three steps for the common cases, a payment that has gone out, credentials that were entered, an attachment that was opened. Those three steps are usually contact the bank, change the password and revoke sessions, and tell the named person who decides what happens next.
The businesses that recover well are not the ones that never get caught. They are the ones where somebody said something within the hour.
Review it like any other process
Put the payment change rule and the access change rule in writing, with a named owner. Review them twice a year and after anything that nearly worked. Check occasionally that the verification step was actually used the last time a supplier changed details, because a rule nobody follows is just a document.
We are a business consulting firm, not a security vendor, and this is exactly the part we help with. Writing the approval and verification steps into the way the business already works, giving them an owner, and making sure they survive contact with a busy week.
Almost none of this is about email. It is about who is allowed to change what, and how you check.
Want the payment and access rules written into how your business already works? Book a consultation, or visit www.expertechsolution.com.