The future of UK farming
Will Sherring, a Manager in our Business Team, explores how recent announcements from the Budget will impact the agriculture sector, and provides insight as to how those affected may overcome these challenges.
Prevention is cheaper than a cure
Businesses of any size and nature are susceptible to cyber attacks and should remain aware of the key threats they may face without sufficient infrastructure and awareness.
Often, smaller businesses, or those not in the public eye, may consider themselves immune; however, the unfortunate truth is that all businesses are attractive targets for different forms of cyber attack. Smaller businesses can be more vulnerable due to their lack of formal policies and controls, making them more commonly targeted than one might initially think.
Price Bailey aims to inform you of and prepare you for the continuing dangers of cyber threats, debrief you on various real-life examples of cyber-crimes suffered by businesses, and advise you on steps every business should take to avoid cyber attacks.
Below, we detail some recent cyber incidents we have observed and provide recommendations on how you can be better prepared to combat them:
We frequently see that businesses lack sufficient controls and expectations regarding fraud when handling changes to employee bank details. This is an extremely common form of fraud, and all businesses should be aware of, and prepared to address, it.
Typically, this involves a fraudster emailing from a fake personal account, asking your payroll department to change an employee’s bank details to a new, fictitious set. The request, appearing to come from the employee, may be queried, but sometimes the query is sent to the same email address, or another form of communication controlled by the fraudster, leading to a false confirmation.
Once the details are changed, the victim usually discovers the fraud when they are not paid on the next payroll run, by which time it is often too late.
False requests to change employee bank details are relatively simple but have unfortunately caught out many of our clients.
Invoice fraud involves intercepting and altering a purchase invoice’s payment details so the intended supplier’s payment is instead paid to a fraudster’s account. This type of fraud is preventable by both the supplier and the payer, though each has different responsibilities to mitigate the risk.
As a supplier, ensure a segregation of duties between those who can change your bank details and those who approve these changes.
As a payer, be cautious about changes to payment details that haven’t been communicated by your regular account contact.
For charity or NFP clients who provide grants, this also applies to grant payment details, especially when recipients request a bank account change. Any such request should be verified through multiple sources to ensure it is legitimate and not fraudulent.
If in doubt, seek additional forms of verification.
Phishing involves criminals using scam emails, texts, or calls to trick victims into releasing sensitive information. Typically, this includes links to harmful websites which steal data, malicious attachments, or false instructions.
Phishing is notoriously difficult to prescreen because the harmful website link isn’t always evident in the email. The responsibility therefore falls on the recipient to identify the scam.
All employees should be wary of unusual emails, especially those containing links to external websites or requests for data entry, to avoid unintentionally giving away information.
Advanced hackers can lock you out of your own system if they obtain the right information. System ransom attacks often result from phishing emails or similar information leaks.
Hackers typically demand a cash sum to unlock the system, leaving the business unable to operate while they deliberate. This can be devastating, leading to significant time and money spent resolving the issue.
A key preventative measure is to have regular backups of your key systems stored in a separate location. While this doesn’t reduce the risk of a ransom attack, it can minimise or even eliminate the impact if one occurs.
It is important to note that hackers can still make financial gains even if a ransom is not paid, as they can sell your data on the dark web. In the event of significant data breaches, especially ransomware attacks, the Information Commissioner’s Office (ICO) should be informed, so it can assist with appropriate further actions.
In addition to awareness of the threat and internal vigilance, proactive management, education and a company-wide security culture will go far in countering the threat, while at the same time ensuring more trained eyes to help counter potential attacks and enhance overall business resilience. Specific measures you should consider include:
Those unaware of modern cyber attacks may believe that having a strong IT team with appropriate firewalls and monitoring facilities is sufficient to eliminate the threat of attacks. This lack of knowledge can make them prime targets for scammers. Adequate training and a culture of awareness within your environment are essential for stronger prevention.
From a cyber perspective, a business is only as strong as its weakest link. Therefore, consistent awareness among all staff is imperative in the fight against cyber crime.
Contact us today to find out more about how we can help you
Will Sherring, a Manager in our Business Team, explores how recent announcements from the Budget will impact the agriculture sector, and provides insight as to how those affected may overcome these challenges.
With the rate of CGT under a BADR claim increasing from 6 April 2025, now could be a good time for business owners looking to exit. Find out more...
Although awareness around men’s mental health is growing, there remains a significant gap between how men perceive their own mental health and the reality of the challenges they face. Why does this disparity exist? Read more in our blog here...
Tax Investigations Partner, Andrew Park, provides a round up of the most recent and significant contentious tax news.