Cyber Risk Isn't Just an IT Problem

An email arrives from a supplier.

They’ve changed their bank account details. The name is familiar, the invoice looks right and there’s nothing particularly unusual about the request.

The payment is made.

Later, you discover the supplier never sent the email.

Cyber incidents don’t always start with an obvious attack on your systems. For a small firm, it can be something as ordinary as a convincing email, a compromised password or someone clicking a link they thought was legitimate.

That’s why cyber security isn’t only an IT consideration. It’s also part of protecting your firm’s finances, information and ability to keep operating.

Get the basics in place

Some of the most useful protections are also relatively straightforward.

Use strong, unique passwords for important systems and avoid sharing logins between team members. Turn on multi-factor authentication where it’s available, particularly for email, online banking, accounting software and cloud storage.

Keeping software and devices updated is important too, as updates can address known security weaknesses.

Then consider your backups. What information does your firm rely on every day, and could you access a secure copy if your usual systems became unavailable?

These measures won’t remove every risk, but they add useful layers of protection around the systems your firm depends on.

Take extra care around payments

Emails relating to invoices and payments deserve particular attention because scammers can make them look like familiar, everyday requests.

A supplier may appear to provide new bank account details. A director may seemingly request an urgent payment. An invoice may look almost identical to one you normally receive.

If payment details change unexpectedly, verify them using contact information you already trust rather than relying on the details contained in the message.

The same applies when a request feels unusually urgent. Taking another minute to check gives you a chance to confirm that the instruction is genuine before money leaves the account.

Give your team confidence to check

Technology is only one part of cyber security. Your team also plays an important role.

It helps if everyone knows some of the common warning signs, including:

  • unexpected links or attachments

  • sudden changes to payment instructions

  • requests for passwords or login information

  • unusual pressure to act quickly

  • login pages that look different from normal

  • messages that don’t sound quite like the supposed sender

Just as importantly, people should know it’s okay to stop and verify something.

Creating a culture where a team member feels comfortable questioning an unusual request can be one of the simplest ways to add another layer of protection.

Keep system access up to date

As people move into different roles, their access to business systems should change with them.

Periodically review permissions for online banking, accounting software, email, shared drives and other important platforms. Team members should have the access they need for their current responsibilities, rather than permissions that have accumulated over several years.

When someone leaves the firm, removing their access should be part of the departure process.

Have a plan for disruption

It’s also worth thinking ahead to how the firm would respond if something did happen.

Who would you contact if you lost access to an important system? Who would take responsibility if a suspicious payment was identified? Could the firm continue operating while access was restored?

Having those conversations ahead of time means fewer decisions need to be made under pressure.


Stay one step ahead of cyber risk

Cyber security can have financial and operational implications, so it deserves a place in your wider business risk planning.

If you’d like to discuss how your firm is prepared for financial or operational disruption, talk to your usual Bennetts Proactive advisor or call 07 573 8446

Next
Next

Trust Is Important. So Are Checks and Balances.