An accounting employee gets an email that looks exactly like it's from the CEO, urgently requesting a wire transfer to a new vendor account to close a time-sensitive deal. The tone is right, the urgency is right, even the email signature is right — because the whole thing is fake, sent from a lookalike domain by someone who spent a few weeks studying the company's public communications. Within twenty minutes, $40,000 is gone and unrecoverable. This exact scenario plays out at small businesses constantly, and the single control that stops it almost every time is shockingly simple: requiring a second, independent person to approve any large payment before it goes out.
Why email alone should never authorize a wire transfer
Email is trivially easy to spoof, and even when an account is genuinely compromised rather than spoofed, an attacker sitting inside a real email inbox can send instructions that look completely legitimate because they are, in fact, coming from the real account. Treating any single email — regardless of how convincing, urgent, or seemingly authoritative — as sufficient authorization for a wire transfer or large payment is the single biggest vulnerability in how many small businesses handle money movement. The fix isn't a smarter spam filter; it's a process that doesn't depend on email being trustworthy in the first place.
What dual approval actually means in practice
Dual approval means that no payment above a defined threshold can be released based on one person's authorization alone — a second person, independent of whoever initiated or received the request, must separately verify and approve it before funds move. Critically, this second approval needs to happen through a channel other than the one the original request came through: if the request arrived by email, verification should happen by phone, using a number already on file rather than one provided in the suspicious message itself, not by replying to the same email thread.
Setting a threshold that actually gets used
A dual approval requirement that applies to every single payment, no matter how small, quickly becomes a bottleneck that people start finding ways around. Setting a specific dollar threshold — calibrated to what the business can actually absorb losing without serious damage — above which dual approval is mandatory keeps the control meaningful without grinding routine, low-risk payments to a halt. This threshold should be low enough to catch the kind of fraud attempts that actually target small businesses, which are often calibrated by the attacker to look like a plausible, not-too-alarming amount.
Building in a callback verification step for new payees
Beyond dual approval, any payment to a new vendor or a changed bank account for an existing vendor deserves its own separate verification step: a phone call to a known, previously verified contact at that vendor, using a number from existing records rather than anything provided in the request itself. Business email compromise scams frequently work by claiming a vendor has "updated their banking information," and this single callback habit catches the overwhelming majority of these attempts before any money moves.
Why urgency is the biggest red flag, not a reason to skip the process
Fraudulent payment requests are almost always wrapped in manufactured urgency — a deal that will fall through, a vendor threatening to halt shipment, an executive who's unreachable but needs this handled immediately. Legitimate business rarely requires bypassing a payment control to meet a deadline, and training employees to treat urgency itself as a signal to slow down and follow the verification process, rather than a reason to skip it, closes off the exact psychological lever these scams depend on.
Making the policy stick even when the requester outranks the approver
One of the most common ways dual approval controls fail in practice is that a junior employee is uncomfortable pushing back or asking for verification when the request appears to come from a senior executive. Explicit, visible support from ownership — making clear that following the verification process is expected and protected even when it means questioning an apparent request from the CEO — is what actually makes the policy hold up under real pressure rather than just existing on paper.
Extending the same logic to changes in payroll and vendor banking details
The same dual-approval and callback-verification principles apply just as strongly to an employee's direct deposit change request or a vendor's updated banking information as they do to one-time wire transfers, since both are common targets for the same category of fraud. Any change to where money automatically flows deserves the same independent verification as a one-time large payment, since the ongoing nature of payroll or recurring vendor payments can make this kind of fraud even more costly if it goes undetected for more than one cycle.
This kind of control costs almost nothing to implement — it's a policy and a habit, not a piece of software — and it closes off one of the most financially damaging fraud vectors small businesses actually face. The businesses that get hit hardest by wire fraud are almost never the ones with a formal dual-approval process in place; they're the ones that assumed a convincing email was proof enough.
Comments
Post a Comment