Practical Ways Business Owners Can Fight the Threat from Fraud Online
Right – I’ll get the scary stats out of the way first so I can move quickly onto practical steps you can take today to arm your business against the risk of any weak link allowing criminals the ability to carry out fraud online against you.
● Your biggest risk if you have an online sales portal is remote purchase fraud which increased in the UK by 31 per cent to £224.1 million between January and June 2016 (though the banks detected and prevented 6 in 10 attempts, which is pretty good going).
● Over a quarter of businesses have already fallen victim or experienced attempted scams in last two years
● Prime targets for the “social engineering” type of fraud online are senior management in SME’s and employees in large companies
● Seven in ten UK businesses leaders and managers (69 per cent) have admitted they have not taken any action to protect their business and employees from financial fraud
● America’s small businesses are not immune though – according to the Association of Certified Fraud Examiners (ACFE) there, companies with less than 100 employees lose approximately $155,000 as a result of fraud each year and small businesses also have a higher fraud rate than larger companies
HOW TO FIGHT BACK AGAINST FRAUD ONLINE
As I’ve written elsewhere on the subject, the banks and payment processing companies have a vested interest in ensuring that remote payment methods and internet banking are secure. They work to protect both parties in the transaction as well as ensuring the exponential growth of online sales continues – and they have been effective!
This increased transaction security is making cybercriminals rethink their approach – which means they are increasingly using methods of deception to obtain passwords and login information from unwitting individuals.
Since “phishing” as a practice is 20 years old, you’d think we’d all be wise to it by now but the fraudsters have really upped their game and will target your staff with genuine-looking and viable-sounding emails or phone calls in the hope of finding a “bite” in someone who will be fooled into giving up sensitive information.
PROTECT YOUR CARDS AND BANK ACCOUNTS FROM FRAUD ONLINE
● If you don’t have one already, implement a procedure that needs multiple signatures and sign-offs before any payment is made.
● Likewise, since we’re all busy and generally trust our staff, you could be forgiven for not checking every transaction on your bank statements. That said, it would make sense if keep more of an active eye on your money by keeping a regular eye on the transactions appearing via your internet banking.
● If you need further incentive, allocating the task of paying bills each month back to yourself will ensure you do the first part whether you like it or not!
● On your website, change online checkout procedures to be more risk averse. In the short term, it could be refusing to deliver an item to anywhere but the customer’s registered home address but this long term will lose you sales so look to implement a protocol which will flag high risk transactions before authorisation takes place. A real customer won’t mind a quick phone call or text message to confirm it’s really them making the purchase.
STAFF TRAINING ABOUT FRAUD ONLINE – AND FOR FREE
Some resources that may be useful:
http://www.nationalarchives.gov.uk/information-management/training/information-assurance-training/
https://www.theirm.org/knowledge-and-resources/thought-leadership/cyber-risk/
http://www.nationalarchives.gov.uk/sme/
file:///C:/Users/ASUS/Documents/Writings/national_cyber_security_strategy_2016.pdf
Listed above are some additional reading on the subject from the UK government, including some excellent free resources to help small and medium sized businesses fight the threat of fraud online, including free training for your staff – good luck!