Earlier this week, I was on a panel at the Association of Certified Fraud Examiners Europe event. My role (on the panel) was to discuss risk assessment and the behavioural side of cybersecurity. In the early 2000s, I had my first interactions with InfoSec (as then was). Projects included tracking down foreign agents in companies servicing critical infrastructure and investigating a break-in (but no apparent theft) of a UK-listed entity with activities in Russia (fingers immediately pointed to Vlad’s security apparatus). I was to focus on the human angle. Why? Because approximately two-thirds of InfoSec breaches involved social engineering (a fancy phrase for human error, compromise, inaction, or exploitation).
In the intervening ~20 years, everything and nothing has changed. We still face the same adversaries. Like it or not, Europe has been asleep at the wheel for decades to a threat anyone with half a brain could see a mile off. At the conference, it was perhaps not a surprise that a co-panellist said, “We are at war… but there will be no peace treaty in this war.” Why did he say that?
- By some estimates (and the data is hard to assess), cyber fraud causes $190,000 of losses every second. In context, that would make cyber criminals the fourth-largest global economy.
- Russia, North Korea, China, and other state actors aren’t going away. We knew that then. But what’s happened since is the franchising of fraud, such that every self-respecting scumbag (especially organised criminal groups) wanted in on this lucrative swindle. Cyber fraud is now on every corner, McFraud.
- Tech got better. I’m sure most of you have heard about the Arup case, where an employee was invited to a Teams call populated by AI-generated avatars of the management team who pressured him into transferring £20m. It now takes a matter of seconds to record someone (voice or video) to clone their likeness. Around 40% of business email compromises are AI-generated. The data points continue, but you get the gist - tech has become an accelerant for fraud.
- According to some (I distrust unsourced “surveys”), 90% of organisations don’t have anyone dedicated to fraud prevention. Anecdotally, that sounds about right, and relying on folks in IT to combat cyber fraud is like asking an electrician to build a home (their skills overlap and are required, but they lack to time, capacity, skills, and perspective to see the whole picture).
So far, so bleak. What to do? If cybercrime is now a mega-country, we must think of it similarly. The risks you face in any mega-country are not uniform. They depend on what you’re doing, where (precisely), with whom, how, when, and why. Camping in bear country during spring without any deterrents confers different risks to wandering around a rough inner-city neighbourhood at 1am staring at your new iPhone.
One of the attendees at the event asked us what additional controls we’d recommend. None. Not without knowing more. The controls appropriate for a building society controlling billions of pounds of pensioners’ funds and with a consumer base that might be tech-vulnerable should differ (in key areas) from those of a nuclear energy facility.
Fraud is the forgotten risk child in every single investment project we work on. Most scale-up or mid-cap organisations (especially those in emerging markets looking for European financing) have anti-corruption (maybe money laundering) policies. Almost none can define fraud, let alone explain how they prevent it.
Cybercrime is fraud. It’s fraud enabled by human frailty, using technology as the vehicle. We are at war, but it’s a war of attrition, nibbling at our weakest points. To win and not be overwhelmed, we should stop thinking about it as something we can control and more like building immunity. Training our reaction to the threat, taking periodic vaccinations (penetration testing, blue-on-blue exercises, phishing testing, etc.), but mainly staying healthy (data and information hygiene, regular exercises, etc.). Most importantly, we should not rely on one team or function to ‘protect’ us all. Being in that 90% (without a dedicated fraud prevention resource) need not be a damning and defining statistic if we train our people properly. But we don’t (see the data above from our Fraud Prevention Scorecard).
They say the first casualty in any war is the truth. What if we flip that and see knowledge as power? Start the conversation with your people about where they might face risks as they navigate life in a (sometimes) hostile online mega-country.
Saying no, AI edition
I’ve spoken previously about the perils of relying on AI for accuracy (e.g. when a much-vaunted “deep research edition” entirely fabricated statistics about corruption in the renewable energy sector). But I do love it for tasks where I can (sometimes) procrastinate and prevaricate.
For example, I’m sometimes asked to do (or attend) something I don’t want to do (e.g., a freebie request that will take a lot of time/effort). Such a request hit my inbox while drafting the cyber fraud article. The sender is lovely, and we may collaborate on other things in the future, so I needed more than, “No, I’m sorry, this isn’t something for me.” When I posed this conundrum to Perplexity, it replied:
-
Direct and Grateful Response - “Thank you for considering me for this opportunity. While I appreciate the invitation, I must decline as I am currently focused on other commitments.”
-
Unavailable Due to Priorities - “I appreciate your invitation and the work you’re doing. Unfortunately, I won’t be able to participate at this time due to other priorities. Thank you for understanding.”
-
Not the Right Fit - “Thank you for reaching out. After careful consideration, I’ve decided not to join as I don’t believe this aligns with my current goals. Wishing you success with the initiative!”
-
Limited Capacity - “While it sounds like a great opportunity, I’m unable to commit due to limited capacity at the moment. Best of luck with everything!”
-
Respectful Decline Without Explanation - “Thank you for thinking of me for this network. I’m honored by the invitation but will have to respectfully decline at this time.”
The language doesn’t (yet 😬) sound like mine, so any response would need tweaking. But that’s not my concern. I hate lying. I’ve tried to remove even white lies, but especially convenient deceptions. For example, many years ago, I tried to dodge another meeting with someone who seemed to be IP harvesting. I lied, saying I was overseas. To my horror, we nearly ran into each other in a mall, and I had to crouch and hide behind some floral summer dresses in the ladies’ section of H&M. A low point and a lesson always to be honest, even when it’s uncomfortable.
With those AI prompts, some are lies or at least platitudinous half-truths. For example, no. 4 is true (I’m swamped), but it’s not why I’m declining. So, I spoke to Perplexity (I use voice prompts, so all this is done in a matter of seconds) to explain why I’m declining, not just ‘how to decline,’ and it got better (two awful options and one workable, as follows):
“Thank you for considering me for this opportunity. I appreciate the invitation, but I must decline. I’m currently at maximum capacity with my existing pro bono commitments, which include mentoring and other initiatives that align closely with my professional goals. Unfortunately, this initiative doesn’t overlap with my current focus areas or target audience, making it difficult to justify additional unpaid commitments.”
It’s simultaneously wooden and robotic (of course), which can be edited down quickly, but it’s forced me to be direct rather than spend 10 minutes drafting and re-drafting a reply.
Most of you (especially the in-house, and even more particularly those of you with legal backgrounds) seem to be asked to take on WAY more than is reasonable. I sense (and may be wrong here) that saying “No” can be tricky. If you’re stuck on how to do it, ask a bot!
