Cybersecurity blog Cybersecurity blog
The Importance of Cybersecurity Awareness For Finance Divisions: Trust No One
Facebook Twitter LinkedIn

The Importance of Cybersecurity Awareness For Finance Divisions: Trust No One

blank
Guðrún Vaka Helgadóttir
4 min read ∙ Jul 8, 2019
blank

Why You Should Always Double Check New Bank Information

This June we published a new cybersecurity awareness video to remind employees to always double check account numbers when paying out invoices.

We have a good reason to focus on cybersecurity awareness for finance divisions as we have heard multiple first-hand accounts of fraudsters sending out bogus invoices. They have also been known to worming their way into correspondence and taking over as soon as there is a mention of invoices or payment.

Cybersecurity awareness for finance division

The amounts stolen in this manner can range from a few thousand dollars to hundreds of thousands. Perhaps not surprisingly, there is very little that local authorities can do about it. International law enforcement usually doesn’t investigate these matters unless the amount is considerable. Even then the chances of getting your money back are slim to none.

How It’s Done

A finance division employee’s computer or a client’s computer might have been compromised by various means. Most likely it was done by a phishing or spear phishing email containing malicious links or attachments. Through that a hacker gained access to the employee’s email correspondence and could follow it closely. They can even glean the individual language and slang of the user.

When an invoice is sent out, the hacker grabs that email and sends out another email with their own account information. If the employee on the other end is not vigilant the sum will be paid out to the hacker and not the rightful receiver.

When this is discovered the hacker has covered their track and is gone with the funds. This is why companies need to pay special attention to cybersecurity awareness for finance division employees. There is a lot to loose.

Phishing email sent to financial division

Trust No One

It might sound cynical to say this but when it comes to invoices and account numbers, we should trust no one. Not even invoices issued in the name of companies we’ve been dealing with for years. If email accounts have been breached (or even if someone has gone through the company’s trash) it is possible for hackers to send out bogus invoices in the name of trustworthy companies. The only thing they’ve changed is the bank information for payment.

If the account number is the same as usual and has been paid to before without incident, it should be safe to continue with the payment. If a company suddenly changes its account number or you are making a payment to a new company the safest protocol to follow is to call that company directly and double check the invoice and the account number.

Find the number to call through the company’s official web page or an official directory. Don’t trust any information provided in an email until it has been verified that the sender is who they say they are.

Even Your Boss Needs Cybersecurity Awareness For Finance

accounting division double check account number

It’s not always invoices in the name of another company that are sent out. Sometimes it’s important emails from a boss or a very high-ranking individual within the company such as the CEO or the CFO. They demand that funds be moved from one account to another ASAP. Such frauds are also known as CEO scams or Whaling.

No matter how urgent they might sound, or how often similar orders might have come in the past, such emails should always be verified with a phone call. A good CEO should encourage such vigilance from his employers. It means that the effort spent on training for cybersecurity awareness for finance divisions has paid off. And it could wind up saving the company considerable sums.

blank
Guðrún Vaka Helgadóttir
4 min read ∙ Jul 8, 2019

Become cyber secure

You and your employees are going to love AwareGO. It’s a modern, cloud-based system for managing human risk, from assessment to remediation. We’ve made it super easy — schedule your first assessment or training in minutes.

Get started for free and give it a go right now.

You’ll love the way AwareGO can fit into your existing infrastructure. Our robust APIs, widgets, and content available in SCORM format make sure that the integration is seamless. We also integrate with Active Directory, Google Workspace, and popular tools like Slack and Teams.

Contact us and our experts will recommend the best way to integrate.

Upgrade your cybersecurity business by adding human risk management to your existing portfolio of services. Increase your deal size by leveraging Human Risk Assessment or offering Security Awareness Training to your current customers and creating a new revenue stream.

Contact us to become an AwareGO partner, and we will support you every step of the way.

Join top companies worldwide in the mission to make workplaces cyber-safe

Get started free
blank blank blank blank blank blank blank blank blank blank