Skip to main content
Guidance

Cyber Security Toolkit for Boards

Resources to help Boards implement the actions outlined in the Cyber Governance Code of Practice.

Page 19 of 27

Implementing effective cyber security measures

Put in place defences that will protect your critical assets against the biggest threats.



A charity organisation was first aware there was an incident when their bank contacted them querying a change in a suppliers bank details.

Their CISO explained, ‘We checked the Finance Manager’s email account and discovered that a rule had been set up to divert any email containing the words ‘payment’, ‘invoice’, ’bank details’ etc to the Really Simple Syndication (RSS) feeds folder. At this point the fraudster doctored the body of the email and the invoice attachment with the fraudulent bank details. It was believable as the main body of the email had clearly come from a known supplier as it was answering questions that only they could have known. We thought at this point that we had narrowly missed making a payment to a fraudulent bank account.’

Another supplier emailed a week later to chase payment of an invoice which the organisation thought they had paid. On checking the payment details they discovered the payee’s account details were different to those on the invoice.

‘Looking back, the Finance manager had noticed that people were saying that they had emailed her but they were taking a day or two to come through but it was just thought to be a lag with the system. This will be a red flag alert going forward.’

Immediate Action Taken

  • Finance Manager called the bank and alerted them to the fraud
  • We reported to Report Fraud in order to obtain a crime reference number
  • We reported to The Charity Commission as a serious incident

Lessons learned/further actions

  • We updated our processes and procedures

    •   Weekly checks on email account to check no rules have been set
    •   check email ‘safe senders’ to make ensure authentic
    •   check the location of any logins to Office 365 to ensure no activity on the account
    •   check RSS Feed folder for rogue emails
    •   Bank detail for new and updated suppliers to be verified by a phone call

  • If making a payment online and bank details don’t match, phone and check with the payee that the details are correct
  • Implemented multi factor authentication for logging into Office 365

Published

Reviewed

Version

3.0