Financial Services3 min read

Your Real Threat Model Is a Convincing Email About a Wire

Financial firms spend on perimeter security and lose money to a plausible message and a rushed approval. The controls that stop it are procedural, cheap, and usually missing.

Ask a financial services firm what it is defending against and you will hear about ransomware, nation-state actors, and the regulatory consequences of a breach. All real.

Now look at what actually costs firms money. It is a message that appears to come from a client, or a partner, or the managing director, asking for funds to move, arriving at a moment when moving quickly seems reasonable.

The attacker did not break anything. They read the room.

Why it works on competent people

Business email compromise succeeds because it exploits the way the firm already operates, not a technical weakness.

The message is plausible because the attacker has been reading the mailbox for weeks and knows the deal, the names and the tone. The timing is right because they waited for a real transaction. The urgency is genuine because closings have deadlines. And the person who approves it is senior enough that nobody wants to slow them down.

Training helps at the margin. It does not solve this, because the failure is not ignorance. Competent, trained, sceptical people approve these under time pressure, and they always will.

The controls that actually work

Verification out of band, with no exceptions for seniority. Any change to payment instructions is confirmed by voice to a number already on file, never a number in the message. The important word is "no exceptions." A control that a managing director can waive under pressure is the control failing exactly when it is needed.

Two people for money movement above a threshold. The threshold should be low enough to catch the transactions that would hurt. Dual approval defeats the entire premise of the attack, which relies on one person's judgement in one moment.

Multi-factor authentication everywhere, including the gaps. Staff email is usually covered. The exceptions are what get used: shared mailboxes, service accounts, legacy protocols that do not support it, and the partner who found it inconvenient.

Mailbox rule alerting. Attackers create inbox rules to hide their tracks, moving replies to a folder nobody opens. Alerting on rule creation is a small configuration change and it is one of the highest-yield detections available to a small firm.

A rehearsed response for the first hour. Recovery of a misdirected wire depends almost entirely on speed. Who calls the bank, who calls the client, who preserves the mailbox. Written down, on a card, not improvised.

None of these are expensive. Most are configuration and procedure. That is precisely why they get skipped in favour of a product purchase that feels more like progress.

The cover question nobody checks until it matters

Many firms assume their cyber policy covers this. Frequently it does not, or it covers it under a separate social engineering endorsement with a much lower sublimit, and often conditioned on the firm having a documented callback verification procedure.

That is worth reading before a claim rather than during one. If the policy requires a verification procedure, the procedure has to exist, be documented, and be followed, or the endorsement does not respond.

Where this sits in the bigger picture

The pattern here is general. The controls that reduce the most expensive risks in a professional firm are usually procedural, cheap and unglamorous, and they lose the budget argument to products. Somebody has to make the case for the boring ones, and it helps if that person does not sell either.