7.3 Cyber Security Threats, Vulnerabilities, and Defensive Controls
Key Takeaways
- Finance functions are prime targets for Business Email Compromise (BEC) and ransomware due to their direct authority over cash disbursements and possession of sensitive payroll and banking data.
- The 3-2-1 backup strategy (3 copies of data, across 2 different media types, with 1 immutable offsite copy) provides resilience against catastrophic ransomware encryption and hardware failure.
- Logical security combines MFA, encryption at rest and in transit, firewalls, and least-privilege role-based access; encryption methods and configurations should match the information and threat rather than rely on marketing labels.
- Administrative controls, including strict out-of-band payment verification protocols and continuous employee security awareness training, are essential to counter human-targeted social engineering attacks.
7.3 Cyber Security Threats, Vulnerabilities, and Defensive Controls
Finance departments and professional accountancy practices manage an organization's most liquid assets and critical data. They control commercial bank accounts, authorize electronic fund disbursements, maintain proprietary financial plans, and custody sensitive payroll records containing employee personally identifiable information (PII). Consequently, finance teams represent high-priority targets for organized cyber criminals, hostile state actors, and opportunistic fraudsters.
The Cyber Threat Landscape and Common Attack Vectors
Cyber threats exploit both technological vulnerabilities in software architecture and cognitive vulnerabilities in human psychology. Modern accounting teams must recognize common attack vectors:
1. Phishing and Credential Harvesting
Phishing is a broad social engineering attack conducted via email, SMS (smishing), or instant messaging. Cyber criminals distribute deceptive communications impersonating trusted entities—such as HMRC, major clearing banks, or software vendors (e.g., Microsoft 365, Xero). The communications contain malicious links leading to spoofed login portals designed to harvest user credentials, or attachments harboring malicious code.
2. Spear Phishing and Business Email Compromise (BEC) / CEO Fraud
Spear phishing is an intensely researched, targeted attack aimed at specific individuals possessing financial authorization powers. In corporate accounting, this manifests as Business Email Compromise (BEC) or CEO Fraud:
- Mechanics: An attacker compromises or closely spoofs the email account of a chief executive, finance director, or established external supplier.
- Modus Operandi: The attacker emails an accounts assistant or purchase ledger clerk requesting an urgent, confidential wire transfer to a "new" bank account to facilitate a time-sensitive corporate acquisition, or claims that an existing regular vendor has changed its banking details.
- Psychological Triggers: The communication exploits workplace authority, extreme urgency, and confidentiality, pressuring the finance clerk to bypass normal internal verification controls.
3. Malware and Ransomware
Malware (malicious software) includes viruses, worms, keyloggers, and spyware designed to infiltrate corporate networks undetected.
Ransomware is an acute threat to corporate accounting. Once executed—often via an employee opening an infected email attachment or clicking an exploit link—the ransomware quietly traverses the internal network, locates primary accounting databases, ERP servers, and mapped shared drives, and uses strong encryption to lock the files. The perpetrators demand a multi-million-pound ransom (typically in cryptocurrency) in exchange for the decryption key. Furthermore, modern attackers engage in double extortion: exfiltrating proprietary financial records and client payroll data before encryption, threatening to publish the sensitive data publicly if the ransom is not paid.
4. Social Engineering and Pretexting
Social engineering relies on human deception rather than technical hacking. In pretexting, an attacker fabricates an elaborate scenario—impersonating an external IT support technician, an auditor, or a bank fraud investigator—to persuade a finance worker to reveal multi-factor authentication codes, reset passwords, or install remote-access tools on internal workstations.
5. Denial of Service (DoS / DDoS) and Man-in-the-Middle (MitM)
- Denial of Service (DoS / DDoS): Attackers flood accounting web portals or corporate servers with massive traffic surges, overwhelming server bandwidth and forcing systems offline during critical operational windows (such as payroll cut-off or VAT filing deadlines).
- Man-in-the-Middle (MitM): Attackers intercept unencrypted communications between a user's workstation and an online banking portal or cloud accounting server, eavesdropping on confidential financial exchanges or manipulating payment instructions in transit.
Defensive Controls Architecture
A resilient defense-in-depth security framework groups controls into three complementary layers: Physical, Logical / Technical, and Operational / Administrative.
Physical Controls (Tangible Barriers) ➔ Logical Controls (Digital Architecture) ➔ Administrative Controls (Governance & Protocols)
1. Physical Security Controls
Physical controls provide tangible barriers preventing unauthorized physical access to hardware, network infrastructure, and physical accounting records:
- Server Room Access Management: Dedicated on-premise servers, network switches, and backup drives must be housed in locked, climate-controlled server rooms protected by electronic keycards, biometric scanners, and continuous CCTV surveillance.
- Clean Desk and Clear Screen Policies: Employees must lock physical paper records containing financial or payroll data in fireproof cabinets when stepping away from workstations. Operating systems must be configured to lock computer screens automatically after a brief period of inactivity (e.g., three minutes).
- Device Security and Disposal: Laptops and mobile workstations used in open office environments should be secured with physical Kensington cable locks. Decommissioned media should undergo an approved secure-erasure or destruction process. Degaussing is suitable only for compatible magnetic media; solid-state media may require verified secure erase or physical destruction.
2. Logical and Technical Security Controls
Logical controls use software, mathematical cryptography, and network engineering to protect digital assets:
- Multi-Factor Authentication (MFA): Passwords alone are vulnerable to credential stuffing, brute-force attacks, and phishing. MFA requires users to supply two or more independent authentication factors before gaining system access:
- Knowledge factor: Something the user knows (e.g., a complex passphrase).
- Possession factor: Something the user has (e.g., a smartphone authenticator app generating time-based one-time passwords [TOTP] or a physical FIDO2 hardware security key).
- Inherence factor: Something the user is (e.g., fingerprint or facial biometrics).
- Role-Based Access Control (RBAC) and Least Privilege: Under the Principle of Least Privilege (PoLP), users receive only the minimum access rights necessary to perform their specific job functions. In an ERP system, access must be partitioned using Role-Based Access Control (RBAC). For example, a purchase ledger clerk can draft supplier invoices but cannot approve them; a payroll officer can enter overtime hours but cannot alter bank disbursement files.
- Cryptographic Encryption:
- Encryption at Rest: Protecting stored databases, workstation solid-state drives, and backup media using Advanced Encryption Standard (AES) with 256-bit keys. If a laptop is stolen, encrypted data remains unreadable.
- Encryption in Transit: Securing data moving across external networks using modern Transport Layer Security (TLS 1.3) protocols, neutralizing Man-in-the-Middle eavesdropping.
- Endpoint Detection and Response (EDR) and Next-Gen Firewalls (NGFW): Deploying continuous behavioral monitoring software on all employee endpoints to isolate suspicious executable files and block unauthorized network traffic.
Input, Processing, and Output Integrity Controls
Information security also protects the integrity of accounting data throughout processing:
- Input controls: required fields, format/range checks, sequence checks, duplicate detection, batch totals, and authorisation before master-data or transaction entry.
- Processing controls: control totals, run-to-run reconciliation, exception reports, reasonableness checks, audit logs, and restricted program changes so data is processed completely and accurately.
- Output controls: reconcile reports to source/control totals, restrict distribution, review exception reports, label versions, and securely transmit or dispose of outputs.
Access controls and least privilege limit who can perform each stage, while a properly configured firewall filters unauthorised network traffic. These controls complement backups and malware defence; no single control proves data integrity on its own.
3. Operational and Administrative Controls
Administrative controls encompass managerial governance, staff training, and organizational protocols:
- Mandatory Out-of-Band Callback Verification: To defeat Business Email Compromise, finance policies must strictly prohibit modifying supplier bank details or executing off-cycle urgent payments based solely on email instructions. Clerks must perform an independent out-of-band verification: telephoning the supplier's verified finance department using a pre-existing, independently sourced telephone number (never the contact number listed on the incoming email request).
- Employee Security Awareness Training: Conducting regular, interactive training and unannounced simulated phishing tests. Training cultivates a culture of vigilance where staff proactively identify and report suspicious communications.
- The 3-2-1 Data Backup Strategy: Critical financial ledgers, tax records, and ERP databases must be protected against ransomware and catastrophic hardware loss by adhering to the industry-standard 3-2-1 Backup Rule:
- Maintain at least 3 complete copies of the data (one primary production copy and two distinct backup copies).
- Store the backups across at least 2 different storage media types (e.g., local network-attached storage [NAS] and magnetic tape or solid-state disk array).
- Keep at least 1 backup copy completely offsite in a geographically separate cloud data centre or an air-gapped, immutable storage repository that ransomware cannot reach over the local network.
- Disaster Recovery (DR) and Business Continuity Planning (BCP): Establishing formal procedures to restore IT infrastructure and finance operations following a catastrophic failure. Plans define two essential operational metrics:
- Recovery Point Objective (RPO): The maximum acceptable data loss measured in time (e.g., an RPO of 1 hour means the organization cannot afford to lose more than 1 hour of posted accounting transactions).
- Recovery Time Objective (RTO): The maximum acceptable duration of system downtime before financial operations must be fully restored (e.g., an RTO of 4 hours to restore payroll systems before statutory payment cut-offs).
Categorization of Defensive Controls
| Control Classification | Primary Objective | Specific Accounting Environment Example | Primary Cyber Threat Mitigated |
|---|---|---|---|
| Physical Controls | Prevent tangible access to hardware and paper records | Biometric locks on server rooms; Kensington cable locks on finance laptops | Hardware theft; unauthorized physical tampering; office intruder snooping |
| Logical / Technical | Prevent digital infiltration, unauthorized access, and eavesdropping | Mandatory Multi-Factor Authentication (MFA); AES-256 encryption at rest; Role-Based Access Control | Credential harvesting; brute-force attacks; Man-in-the-Middle interception |
| Administrative / Operational | Direct human behavior and establish organizational response protocols | Mandatory telephone callback protocol for bank detail changes; 3-2-1 backup rule | Business Email Compromise (BEC); ransomware extortion; human social engineering |
An accounts payable assistant receives an urgent, flagged email purportedly sent by the company's Chief Executive Officer (CEO). The email states that the CEO is currently engaged in highly confidential corporate acquisition negotiations in Singapore and instructs the assistant to immediately transfer £85,000 to a newly specified international supplier bank account to secure the transaction. The email emphasizes that the assistant must not discuss the matter with the finance director or colleagues due to strict non-disclosure obligations. What cyber threat does this represent, and what is the mandatory control response?
A mid-sized logistics firm experiences a major ransomware infection over a weekend. The malware successfully encrypted the company's primary on-premise accounting server and compromised the mapped network-attached storage (NAS) backup drive located in the adjoining server room cabinet. When the finance team arrives on Monday morning, the accounting software is completely inaccessible. Which backup architecture would have enabled the firm to restore its financial ledgers without paying the ransom?
A newly appointed financial controller is reviewing user permissions within the company's enterprise resource planning (ERP) system. The controller discovers that all four accounts assistants in the finance team have been granted global 'Super-User Administrator' rights, allowing each assistant to set up new vendor profiles, input purchase invoices, amend existing supplier bank account details, and authorize BACS payment runs. Which fundamental security and internal control principle is being breached, and what is the appropriate remedy?