enterprisesecuritymag

A featured contribution from Leadership Perspectives, a curated forum for enterprise security leaders, nominated by our subscribers and vetted by the Enterprise Security Magazine Editorial Board.

Alliant Insurance Services

Protecting Your Business from Cybercrime

David Finz, Senior Vice President, Alliant Insurance Services

Internet crime is rising, with the FBI logging over 21,000 complaints in 2023, resulting in over $2.9 billion in losses. The increasing sophistication of cybercrime, particularly social engineering, poses a significant threat to businesses.

These attacks, often disguised as legitimate requests, can lead to substantial financial losses and highlight the critical need for robust cybersecurity measures and adequate cyber insurance coverage.

Understanding the Cybercrime Threat Environment

Social engineering, also known as fraudulent impersonation, involves fraudsters gathering information to create convincing requests, often for wire transfers or changes to vendor bank details. This usually includes extensive research, potentially through social media or gaining access to a company's email servers. The plausible nature of these schemes means they often go undetected until funds are irrecoverably transferred, frequently overseas. Social engineering differs from funds transfer fraud, where attackers directly hack into systems and use banking credentials.

Business Email Compromise (BEC) occurs when fraudsters gain access to legitimate email accounts to orchestrate unauthorized payments. These compromised accounts can belong to the company, its clients or banks. Scammers monitor emails for pending transactions and then send fraudulent wire instructions that appear legitimate but use a slightly altered domain name. Once transferred, the funds are immediately unrecoverable.

Invoice Manipulation happens when a fraudster sends a phony invoice to a customer, impersonating a legitimate vendor. The customer then misdirects payment to the fraudster, leaving the actual vendor with an uncollectible receivable.

Creating a Culture of Cybersecurity Awareness

Reducing your company’s exposure to social engineering attacks involves taking proactive measures to educate employees and protect systems. Fraudsters exploit the natural urge to trust others and be helpful.

Employees should scrutinize email and voice communications for authenticity, carefully examining wire instructions. Pre-arranged wire transfer protocols should be used to confirm legitimacy. When conducting telephone verifications, be alert for unusual word choices or inflections that might indicate a “deep-fake” recording.

Companies should implement heightened security controls to thwart cybercrime:

Email Security: Employing end-to-end encryption and implementing strong employee password policies with multifactor authentication. Purchasing near-identical domain name spellings can prevent fraudsters from using similar names.

• Workforce Management: Requiring regular cybersecurity training, including identification of mock phishing and smishing attacks, with additional training for those who fall for them. An offboarding program for departing employees, including hardware return and access privilege removal, is also vital.

• Communication with IT: Foster collaboration with internal or outsourced IT teams and ensure immediate alerts to senior management about incidents.

• Limit Account Access: Strictly limit those authorized to initiate funds transfers and segregate duties for all outgoing wire transfers.

• Verification: Multiple forms of authentication are required for all fund transfer instructions.

  • The IT team should check for further email compromise or bad actors. Risk management should determine insurance coverage and consult with insurance brokers. Finally, document every step: keep records of emails, case numbers and call logs.

• New Customer and Vendor Setup: Establish procedures to verify new parties before transactions.

• Callback Procedures: Require employees to call back customers or vendors at predetermined phone numbers before executing transfers or change requests.

• Documentation: Document specific funds transfer destinations and protocols for recurring transactions.

• Restrict Company Account Use: Clients must transfer directly or through an escrow agent.

• Vendor Protocols: Require higher-level approval for changes to vendor records and confirm all change requests with a different person.

• Consistent Procedures: Create consistent procedures and controls across all offices and practice areas.

Developing an Incident Response Plan

Immediate action is crucial in a fraudulent payment incident, and you should act within 24-72 hours for a greater chance of recovery. Notify your bank's fraud department immediately and request a SWIFT or wire recall. Request your bank initiate a Financial Fraud Kill Chain (FFKC) request and contact the recipient bank to freeze the fraudulent account. Obtain written confirmation of your own bank's actions.

Report incidents to law enforcement agencies that can assist:

• File a report with the FBI's Internet Crime Complaint Center (IC3).

• For wires over $50,000, call your local FBI field office for immediate intervention.

• Contact the Secret Service's Cyber Fraud Task Force if the FBI is unreachable.

• For international wires, request coordination with foreign counterparts.

• Obtain a police report or case number from your local police department.

Understanding Cyber Insurance

Contract wording in a cyber insurance policy can limit a company's exposure to vendor security failures. Essential security standards should be embedded in service agreements.

Companies should seek higher limitations of liability and exceptions for deliberate misconduct by vendors and ask to be named as an “additional insured” on vendor cyber and professional liability policies. Provisions that waive an insurer's right to subrogate against a vendor should be resisted. Contracts should also include attestations of vendor compliance with basic security controls, such as multifactor authentication, encryption, regular penetration testing and formal incident response plans.

Partnering with an experienced insurance broker specializing in cyber risk is crucial to ensure cyber coverage is comprehensive and tailored to your specific risks, to help avoid costly gaps and unexpected liabilities.

It Takes a Village

Internally socializing information about an attack is vital to preventing repeat offenses, and every department plays a role. The accounting team should stop payments to fraudsters and be wary of bogus “recovery service” emails. Scammers may pose as “recovery agents,” so teams should beware of follow-up fraud attempts.

The IT team should check for further email compromise or bad actors. Risk management should determine insurance coverage and consult with insurance brokers. Finally, document every step: keep records of emails, case numbers and call logs.

The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.