Skip to main content

For business

The people are the perimeter

Most business fraud does not defeat a firewall; it asks one employee to do something ordinary, quickly, and slightly out of procedure.

Business fraud that costs money usually arrives as a normal request on a busy day: a payment detail change, a request from a senior person who is travelling, a supplier chasing an invoice that needs attention now.

The defence is not suspicion of everything. It is a short, universally known rule that applies to the specific decisions where money leaves the company, and the certainty that following the rule will never be criticised.

The three approaches that do most of the work

  • Payment detail change: a supplier, a landlord or a contractor asks for a new account number, usually with a plausible reason. The change is the fraud, and it is often invisible until the real supplier asks why the invoice is unpaid.
  • Authority impersonation: a message from a director or a manager who cannot be reached, requesting a transfer, a gift card purchase or a file, with an explanation for the secrecy.
  • Invoice pressure: a genuine-looking invoice, or a duplicate of one that was already paid, with a deadline attached. The deadline exists to suppress verification.

What actually reduces it

  • Any change to payment details is verified by callback to a number already in the system, not the one supplied with the request.
  • Two people, one of whom is not in the conversation, for anything above an agreed amount.
  • A written rule that nothing is paid on a same-morning deadline without a second check.
  • Staff know exactly where to check a link or an address, and know that checking is free, fast and never counted against them.
  • Near misses are reported and reviewed, because a near miss is the cheapest training the company will ever get.

Where the free checks fit

  1. 1Train on real messages, not on slides: staff check a suspicious link themselves and see the reasons in their own words.
  2. 2Check the sender domain whenever a supplier writes from a domain that is new to you.
  3. 3Check links before anyone opens them, especially in messages that reference a payment or a delivery.
  4. 4Check the phone number when a message asks for a call back, because a call-back request is usually the mechanism rather than a detail.
  5. 5Onboarding includes a domain check for every new supplier, so the habit starts before any money moves.

There is no team console and no centrally managed watchlist here: those need the account backend, which is not built. The checks above are free and need no account, and none of them lets an administrator see an individual employee's checks.

Frequently asked questions

Should I monitor what my staff check?

No. A security tool that reports on individuals stops being used, and used is the only state that helps. Encourage checking by making it free of consequence.

Is staff training enough on its own?

Not on its own. Training without a verified-callback rule for payment changes leaves the most expensive path open. Training plus one enforced rule covers most of it.

What is the single most valuable rule?

Any change in payment details is confirmed by calling a number you already held. It is cheap, it is memorable, and it blocks the fraud that costs the most.

Written by The BaitScan team

Last updated September 16, 2026

Results are automated risk estimates based on public indicators and heuristics.