
The email looks legitimate.
It appears to come from a vendor your company works with regularly. The message explains that their banking information has changed and asks your accounting department to send the next payment to a new account.
The employee follows the instructions.
Days later, the real vendor calls asking why their invoice hasn't been paid.
The money is gone.
This type of fraud, often referred to as business email compromise (BEC) or social engineering fraud, has become a serious risk for organizations of every size. And unlike the image many people have of a cyberattack, criminals don't necessarily need sophisticated software to get inside your business.
Sometimes they simply need one convincing email.
Business email compromise typically involves a criminal impersonating someone the recipient trusts.
That could be your:
The criminal may request a wire transfer, change payment instructions, ask for sensitive information, or create a false sense of urgency.
Today's scams can be especially convincing because criminals may research businesses, employees, vendors, and leadership online before making contact.
With AI-generated writing, voice cloning, and other technology becoming more accessible, identifying fraudulent communications based solely on how they "look" or "sound" is becoming increasingly difficult.
This is where businesses can encounter an unpleasant surprise.
A business may have cyber insurance, a commercial crime policy, or other coverage and assume any computer-related fraud is automatically protected.
That isn't necessarily the case.
Coverage for social engineering, fraudulent instructions, computer fraud, funds transfer fraud, and cyber incidents can differ significantly depending on the policy and endorsements.
Limits and exclusions can also vary.
Rather than waiting until after money disappears to determine how your policy responds, these exposures should be discussed during your risk assessment.
Insurance provides an important financial backstop, but proactive risk mitigation should begin before a transaction occurs.
One of the simplest controls businesses can establish is independent payment verification.
If a vendor emails new banking instructions, don't verify the change by replying to that email.
Instead, call the vendor using a phone number already stored in your records or obtained through a trusted source.
Businesses should also consider procedures such as:
A five-minute verification process could prevent a devastating financial loss.
Technology can help protect your business, but cybersecurity isn't solely an IT responsibility.
It's a business risk.
Your accounting procedures, employee training, vendor relationships, cybersecurity controls, and insurance coverage should work together as part of a larger risk-management strategy.
The goal isn't simply to have insurance available after fraud occurs.
The goal is to make your organization harder to fool in the first place.
Ask your team this question: If a trusted vendor changed their banking instructions today, what would we do before sending the money?
If the answer isn't clear, you've identified a risk worth addressing.
Contact one of the Risk Advisors at Fortis Risk Group for a comprehensive policy and risk review. We'll help you evaluate your cyber and financial fraud exposures, identify potential insurance gaps, and discuss proactive risk controls that can help protect your business before one fraudulent email becomes an expensive mistake.
