Key takeaways
- Cyber threats for businesses: Cyber attackers are targeting finance departments in all businesses with sophisticated phishing attacks and impersonations of finance staff.
- Updating and managing IT systems: IT systems need to be updated regularly and should be constantly monitored by finance teams.
- How to improve cyber security: Businesses should use multifactor authentication and threat-monitoring tools, conduct regular access control reviews and align with UK Cyber Essentials Standards.
In the past 18 months, the finance team that Ruth Billen FCA manages has seen around a 50% rise in attempted phishing attacks – and her team is itself part of a cyber security business.
“It’s a regular feature of our monthly all-hands calls that I’m the company’s highest reporter of phishing attempts, because I get them all the time,” says Billen, CFO of Bridewell, one of the UK’s largest independent providers of cyber security solutions.
As the finance department is the team that holds all the money, it is the obvious place for cyber criminals to start to try to extract cash from a business. Billen receives multiple phishing emails per week; these are usually high-activity campaigns, often for low amounts of money. “We’ve seen organisations get targeted for significantly larger sums – again, through their finance teams,” Billen says.
Cyber attacks are becoming more sophisticated
Billen warns that such attacks are becoming ever more sophisticated. Finance staff are frequently spoofed via WhatsApp. Many phishing emails are now designed to resemble entire email chains – a ruse to trick staff into being less sceptical. Attackers are making phishing messages feel more professional by using artificial intelligence to root out classic spelling and grammar errors that once served as handy red flags.
In parallel, finance functions can also let their guard down through sloppy technology management. Paul Rolison ACA, Director of Cyber Strategies Ltd, recalls a company that had a spare terminal in its accounts department that was always on, but no one knew exactly what it did. The supplier that was meant to be in charge of firewall management also hadn’t installed any updates for six years.
“Lo and behold, attackers saw the gaping hole offered by that idling terminal and marched straight through,” says Rolison. “The only thing that saved the department’s systems was quick thinking. A member of staff walked past the terminal, noticed something odd on its screen and yanked out its network cable – just before the attackers were able to extract sensitive data.”
That sort of lucky spot by a passing colleague is unlikely to happen in the majority of businesses that are fully remote, Billen notes – that includes her own business. “As remote companies’ security depends on how employees manage their IT setups, their finance functions are naturally more susceptible to attacks.”
How to build resilience
With those points in mind, here are Rolison and Billen’s tips on how to hardwire cyber resilience into your finance function.
- Implement an Information Security Management System (ISMS): An ISMS is a centrally managed set of formal policies and procedures designed to help you safeguard sensitive data of every type, across your entire organisation, Rolison explains. “If you haven’t got one, get one,” he urges.
- Obtain Cyber Essentials certification: A foundational programme for embedding cyber awareness and protection into your business, Cyber Essentials is based around five core principles and again covers whole organisations. “It’s a self-certified process, and that’s what really wakes people up,” Rolison notes. “It compels you to ask searching questions about where your systems stand in relation to the five principles. You’d be amazed by how many companies don’t fully know what they’ve got in their IT infrastructure – or all the cloud services they’re using.” The Cyber Governance Code of Practice, issued by the UK Department for Science, Innovation and Technology, is also a good standard for businesses to follow.
- Enforce multifactor authentication (MFA): For Billen, requiring finance staff to go through multiple layers of verification to get to their desired part of the system is a must. And MFA – which you can learn more about here – should ideally be supported by password protection tools. Given attackers’ increasing use of WhatsApp as a gateway, MFA is now as important a safeguard on that widely used platform as it is on standard desktop software.
- Conduct regular access control reviews: On at least an annual cycle, Billen says, CFOs must look carefully at which team members have the highest and lowest access privileges. “This should be considered through the lens: ‘If X’ does get compromised, what could attackers get hold of?’ So, who has access to which areas of your systems – and do they still need it? Revoking access where appropriate can help to minimise your attack surface.”
- Use threat-monitoring tools – and pay close attention to them: Lots of businesses put tools in place to monitor cyber threats and think they are protected, Billen says, but if the outputs aren’t monitored, they’re of no use to you whatsoever. “A tool is only as good as the actions that stem from evaluating the information it provides.”
- Maintain an effective backup system – and test it regularly: “In my time at a previous business, we suffered a ransomware attack,” Billen says. “We knew our backup was in full working order because we’d recently tested it. By the time we restored our systems, we’d lost only a day’s work. But some companies that don’t run those tests can find that their backup doesn’t work as expected when an emergency strikes.” Alongside regular testing, make sure your backup is hosted on a different network to your main system, so it won’t also be compromised in an attack.
- Make training feel as real as possible: Bridewell carries out phishing simulations among its employees on a rolling basis. “The more complex and enticing they are, the better,” Billen says. “That way, they’re closer to what happens in the real world, and more revealing about how phishing attempts trigger certain responses. As an accountant, you are taught much about professional scepticism. That’s what you must maintain here.”
- Ensure team members can discuss cyber issues openly: Bridewell’s finance department has a very active Teams channel, and the team can raise any queries that come to mind, such as unfamiliar invoices. “Our culture is: there’s no such thing as a stupid question.”
Action on cyber security can boost growth
As part of ICAEW's campaign on backing business-led growth, we have outlined three key recommendations for government on cyber security:
- Establish a national cyber resilience fund for SMEs
- Enhance cyber security education and awareness
- Incentivise cyber insurance uptake
Cyber security awareness
Each year ICAEW marks global Cyber Security Awareness month with a series of resources and a podcast addressing the latest issues and how to protect your business.
- Cyber roundup: the risk of falling behind
- Eight steps to build a cyber resilient finance function
- Have your say on the future of insolvency rules for England, Scotland and Wales
- Setting up an AI agent correctly part 1: initial steps
- Practice Assurance Monitoring Report 2026 webinar – insights from our reviewers
Stay up to date
You can receive regular email updates from ICAEW insights, including weekly or monthly enewsletters. Subscribe to whichever works for you.
Sign up