One Control, Tested
Out-of-Band Verification for Urgent Requests
This control mandates out-of-band verification to stop CEO fraud and business email compromise by requiring a second channel for all urgent payment requests.
The control: A culture where staff can question unusual executive requests
What it stops This control prevents a T1656 attack path from reaching its objective. It blocks the success of an impersonation attempt where an attacker mimics a senior leader to force a bypass of standard controls. Specifically, it stops a junior accountant or HR administrator from modifying payroll details or initiating a wire transfer based on a single urgent email. It disrupts the momentum of social engineering by introducing a point of friction. When staff are permitted to question authority, the urgency demanded by the attacker becomes a red flag rather than a command. This prevents the immediate execution of high-risk tasks that lack a proper audit trail or secondary approval.
What it does not stop It does not stop an attack using a legitimately compromised executive account. If the email originates from the real mailbox, staff usually assume the request is valid regardless of how unusual it is. It also fails against high-quality deepfake audio that mimics a known voice over the phone. Technical filters for look-alike domains are often ignored when a staff member believes their job depends on speed. A user may see an external sender warning but proceed because they fear the CEO's temper more than a phishing alert. This control is not a replacement for hard technical blocks or mandatory multi-signature requirements for payments over 5,000 pounds.
What it looks like when it is working Working controls manifest as out-of-band verification. A staff member receives an urgent request via email and responds by sending a separate message on a corporate chat app or making a phone call to the executive. IT sees an increase in reports of look-alike domains, such as those adding a single character to the company name. The logs for high-value transfers show no correlation between urgent email spikes and process bypasses. There is evidence of staff requesting a ticket number or a formal procurement request before acting on a directive. It looks like a brief, professional delay while identity is confirmed through a second channel.
How to prove it Execute a controlled impersonation test this quarter. Send a simulated urgent email to twelve employees across finance and payroll. Use a look-alike domain that differs from the corporate domain by one letter. The email must demand a change to an executive's bank details for an upcoming payment, citing extreme urgency and confidentiality. A pass is achieved if 80 per cent of the targeted staff use an out-of-band method to verify the request before attempting to comply. Record the total number of recipients, the count of those who complied without verification, the count of those who reported the email to security, and the exact method used for successful verification.
Where this control appears
- Phishing to executive communications compromiseA targeted lure compromises an executive or assistant mailbox, which is quietly monitored to harvest sensitive correspondence and impersonate leadership for further reach.
Sources
Every link here is checked before publication.