Home Insights & AdviceWhy London businesses still get email wrong
Aerial view of the London skyline on a clear day, looking across the city

Why London businesses still get email wrong

by Sarah Dunsby
2nd Aug 26 1:17 pm

Ask a London founder about their security posture and you will hear about penetration tests, compliance certifications, and cloud providers. Ask how many people can currently read the accounts inbox and the answer arrives more slowly. It’s usually a number nobody has checked since the last two members of the finance team left.

This is the gap that keeps costing British businesses money. Fraud losses continue to run into the hundreds of millions annually, and the overwhelming majority of it arrives not through some sophisticated intrusion but through a message that looked ordinary enough on a busy afternoon. Email remains the way money leaves companies that believed they were reasonably well protected.

The invoice that wasn’t an invoice

The mechanics are consistent across sectors. An attacker gains access to a mailbox, often at a supplier rather than the target, and simply watches. They learn the payment cycle, the tone of the correspondence, the names of the people involved.

Weeks later a genuine-looking message arrives in an existing thread advising of new bank details. Nothing about it triggers suspicion because almost nothing about it is fake, and the money is gone before the real supplier chases.

Why growing companies are exposed

Scale-ups are particularly vulnerable because process has not caught up with headcount. Approval that once meant walking to the next desk now happens across three time zones. Shared inboxes accumulate access, contractors keep credentials past the end of an engagement, and nobody owns the question of who can see what. The pressures on companies at this stage come up repeatedly in coverage of the capital’s start-up sector, where speed is rewarded and administrative discipline rarely is.

What actually reduces the risk

Two-factor authentication on every account, without exception for senior staff who find it inconvenient. A standing rule that changes to payment details are confirmed by telephone using a number already on file. Regular review of who holds access to shared mailboxes.

Choosing an email provider that encrypts message contents so they remain unreadable even to the provider adds a further layer, and it matters most for the correspondence carrying commercial terms and client data.

Knowing what you’re looking at

Staff who understand the pattern spot it far earlier than staff told simply to be careful. Police guidance covering the main categories of fraud and cyber crime is written plainly enough to circulate internally without translation, and it costs nothing. Reporting matters too, since the intelligence feeds back into disruption work that individual companies cannot do alone.

The uncomfortable question

Most businesses could not say with confidence who has access to their most sensitive inbox today. That’s a strange position for organisations that lock their doors and vet their suppliers carefully. The fix requires an afternoon rather than a budget, which makes the continued reluctance to look at it harder to explain than the risk itself.

Insurance is worth checking as well. Many cyber policies exclude losses arising from authorised payments, which is exactly what an invoice fraud produces, since somebody at the company did genuinely approve the transfer. Reading that clause before an incident is considerably more comfortable than reading it afterwards.

Leave a Comment

CLOSE AD

Sign up to our daily news alerts

[ms-form id=1]