Cyber Risk Became a Finance Problem
The second largest category of reported cyber loss targets your payment process, not your firewall.
Cyber risk is usually filed under IT, which is where the budget sits and where the expertise is assumed to live. That filing is defensible for most of the threat landscape and wrong for one category in particular, which happens to be an expensive one.
The FBI’s Internet Crime Complaint Center logged 1,008,597 complaints in 2025, with reported losses of $20.877 billion. Business email compromise accounted for $3,046,598,558 of that, the second largest loss category behind investment fraud at $8.6 billion.
The proportions are the interesting part. BEC made up 24,768 complaints, which is under two and a half percent of all complaints filed, and just under 15 percent of all reported losses. The average reported loss per BEC complaint was roughly $123,000.
Those are not the economics of a software vulnerability. They are the economics of a payment being sent to the wrong account.
The attack is aimed at a process you own
IC3 describes business email compromise as a scam targeting businesses or individuals working with suppliers, or businesses that regularly perform wire transfer payments. It is carried out by compromising email accounts and other forms of communication, including phone numbers and virtual meeting applications.
Read that last clause slowly, because it undermines the obvious control. If the instruction to verify a payment change by calling the number on file is itself compromised, the callback is theater. The same goes for confirming on a video call with someone who looks and sounds like the person you expect.
What actually defeats this is not better email filtering. It is a payment process that treats any change to banking details as a privileged transaction requiring verification through a channel the attacker does not control, using contact details that predate the request.
That is a finance control. It sits in the vendor master, the approval matrix, and the payment run. Nobody in IT can write it for you.
Confidence is running ahead of exposure
Marsh surveyed more than 2,200 cyber risk leaders across 20 countries and eight global regions for its Cyber Catalyst report on cyber investment priorities.
Nearly 75 percent of organizations expressed high confidence in their overall cyber risk management strategies. In the same survey, 70 percent reported experiencing at least one material third-party cyber incident in the past year.
Those two findings can both be true without contradiction, and that is what makes the pairing worth sitting with. An organization can run a genuinely strong internal program and still be exposed through a supplier, a payment counterparty, or an outsourced function. Confidence measured on your own controls does not describe the surface you are actually exposed on.
The regional spread is worth a second look too. Confidence ran at 83 percent across India, the Middle East and Africa, and at 50 percent across Asia. A 33 point range on the same question, against a threat that does not respect borders, suggests confidence is measuring something other than exposure.
Marsh also found 66 percent of organizations planning to increase cybersecurity investment in the coming year, with 26 percent planning increases of 25 percent or more. Money is moving. The question for a CFO is whether any of it is moving toward the payment process.
The variable you control is response time
This is the part of the report that gets the least attention, and for a finance audience it is the most useful thing in it.
The IC3 Recovery Asset Team, established in 2018, works with financial institutions and FBI field offices to freeze funds from fraudulent transfers. In 2025 it was engaged on 3,900 incidents, covering $1,163,919,846 in attempted theft, and froze $679,013,183. That is a 58 percent success rate.
More than half the money involved in those incidents was frozen. Freezing is not the same as money back in the account, but it is the step that makes return possible. The gap between the attempted total and the frozen total was roughly $485 million.
The FBI’s own instruction is unambiguous. If you discover a fraudulent transfer, time is of the essence. Contact your financial institution immediately, request a recall of the funds along with any necessary indemnification documents, and file a complaint at ic3.gov with full transaction details regardless of the amount lost.
Now picture the first hour after someone discovers a wire has gone to the wrong place. They tell their manager. The manager wants to understand what happened before escalating. Somebody suggests calling IT. A meeting gets scheduled. Every one of those steps is reasonable, and together they spend the window the recovery figures depend on.
Prevention is the better outcome and deserves the investment. But prevention is probabilistic and recovery is procedural, and the procedural part sits entirely inside finance.
What to build before you need it
Five things, none of which require a technology purchase:
1. A standing rule that any change to vendor banking details is verified out of band, using contact details held before the request arrived, by someone other than the person who received it
2. A documented approval threshold above which a second, independent verification is required, with no exception path for urgency
3. A named person and a backup who are authorized to call the bank and request a recall without seeking approval first
4. The bank’s fraud line and your account team’s direct numbers stored somewhere reachable outside email, because email may be the compromised channel
5. A written first-hour runbook, rehearsed at least once, that names who calls the bank, who files at ic3.gov, who notifies the insurer, and who informs leadership, in that order
The ordering in that last item is deliberate. Informing leadership first feels responsible and spends the window. The bank call is the step that puts a recall in motion, and the FBI is explicit that speed is what determines whether funds can be frozen at all.
The questions worth asking this month
October is a reasonable moment to raise this, because cybersecurity attention is already elevated and the finance angle usually goes unmentioned. Four questions that will tell you where you stand:
• How many people can change banking details in the vendor master, and what verification is required of them?
• When did we last test whether an urgent payment request from a known supplier would actually be challenged?
• Who in this room is authorized to call the bank and request a recall at 6pm on a Friday?
• Which of our third parties could originate a payment instruction we would act on?
That fourth question is the one that connects to the Marsh finding. If 70 percent of organizations had a material third-party incident last year, the relevant exposure is not only your own controls but the controls of every counterparty whose instructions you honor.
The board is already asking, or about to
This lands on the board agenda whether or not finance raises it first.
KPMG’s On the 2026 Board Agenda lists assessing whether the company’s cybersecurity governance framework and processes are keeping pace among its seven priorities for the year. Its seventh priority is revisiting risk oversight responsibilities and how they are allocated among committees, and KPMG notes that many boards are reassessing which committee has the time, expertise, and skill sets to take on data governance and perhaps cybersecurity.
That reallocation matters for a CFO. If cybersecurity oversight migrates toward the audit committee, the questions arrive in the room where finance already presents, and they arrive addressed to the person presenting. We covered the wider shift in our piece on board readiness for private company CFOs.
The useful move is to bring the payment control picture to the committee before someone asks for it. A short standing item covering who can change banking details, what verification applies, and what the first hour looks like is a stronger position than being asked and having to go find out.
What happens after is also finance work
Prevention and recovery get the attention. The weeks that follow are almost entirely a finance exercise, and they go better when someone has thought about them in advance.
The insurance claim comes first, and cyber policies vary considerably in whether social engineering and funds transfer fraud are covered, at what sublimit, and subject to what verification conditions. A policy that requires documented out of band verification before payment will apply that condition at claim time. Reading that clause while a claim is open is the wrong moment to discover what it says.
Then the accounting. A loss of this kind raises questions about period recognition, whether any recovery is probable enough to record, and how the gross loss and any insurance recovery are presented. If the amount is material, there is a disclosure question alongside it, and in a private company there may be lender notification obligations in the credit agreement.
None of this is exotic. It is simply work that nobody has assigned until it arrives, and it arrives at the point when the finance team is already absorbed in the recovery effort.
Why this belongs to finance
The case is not that CFOs should run cybersecurity. It is narrower and harder to argue with.
The second largest reported loss category in the FBI data attacks a process finance owns, defeats the verification controls finance designs, and is mitigated primarily by a response finance executes. The reporting line for the budget does not change any of that.
A CFO who has verified the vendor master controls, named the person who calls the bank, and rehearsed the first hour has done more to reduce expected loss from this category than another round of security awareness training will. That is an uncomfortable thing to say during Cybersecurity Awareness Month, and the IC3 numbers support it.
Risk and controls come up in our programming throughout the year, and the finance side of cyber exposure is a conversation worth having with peers rather than vendors. Join us at an upcoming session
Disclosure: Marsh McLennan is an FEI Dallas chapter sponsor. Its published research is cited here on the same basis as any other source.


Leave a Reply