The people attackers pick are not the ones you protect

· · Security Commentary

Think about who in your business can approve a payment, change the bank details on a supplier record, or release a contract without a second person looking at it. Now think about how much of your security spending is pointed at those people, as opposed to at your servers and your IT accounts.

For most small businesses the honest answer is: almost none of it. That is the gap new research has just put a number against.

Zscaler's threat research team tracked 351 people compromised across 334 organisations at the opening stage of a single ransomware campaign, over one month. It looked at who those people were. The answer is not who most security budgets assume.

Who actually got picked

Sixty-two per cent held manager-level titles or above. The average age was 46.

The number that matters most, though, is this one: roughly 75% worked in accounting and finance, sales, operations, human resources, or marketing. Finance was the single largest group at 17.7%, then sales at 17.4%, then operations at 16.8%.

Not IT. Not the administrators. The people who run the commercial side of the business.

There is a headline going round that says ransomware gangs are targeting the IT manager. That is a misreading of this research, and it is worth correcting, because it points you at the wrong problem. Half the victims worked at companies in the industrial or technology sectors, which is a fact about the employers, not the individuals. The individuals were overwhelmingly in finance, sales, and operations roles.

Zscaler's framing of why is the useful part. Security teams define a privileged user as somebody with administrator rights: technical privilege. Attackers were selecting for something different, which the researchers call business privilege, the access and authority that comes with a job rather than with a system permission. As they put it, managers "may approve payments, oversee budgets and vendors, review contracts, access sensitive records, or coordinate work across business units".

An accounts payable manager cannot restart your server. They can pay an invoice. For an attacker who wants money, that is the more direct instrument, and it requires no technical escalation at all.

Why this changes the question

The standard mental model of an attack is a ladder: get in somewhere unimportant, then climb towards the administrator account, because the administrator can do anything. Most security advice, including plenty of ours, is built around slowing that climb down.

This research describes attackers who are not especially interested in climbing. They went to the person who already had what they wanted on day one. More than a dozen of the organisations had several employees compromised, and the pattern suggests working sideways across business functions rather than upwards through technical privilege.

Two practical consequences follow.

The first is that protecting only the technical accounts leaves the actual objective uncovered. Extra controls on your server logins do not affect whether your finance manager can be talked into changing a supplier's bank details.

The second is about what "reasonable steps" looks like if you ever have to demonstrate it. If the foreseeable route into your business runs through payment authority, then payment authority is where a director's attention is owed. That is a governance question, and it is not one you can hand to your IT provider, because your IT provider has no view of who signs off what.

A caveat on the evidence, because it matters. This is one vendor's analysis of one campaign over one month, and Zscaler sells services that address the problem it describes. Three hundred and fifty-one people is a reasonable sample but not a census, and a fuller report is promised in the next couple of months. Treat the exact percentages as indicative. The underlying observation, that commercial authority is a target in its own right, does not depend on them being precise, and it matches what fraud of this kind has looked like for years.

What to do about it

None of this needs new software. It needs decisions, most of which cost nothing but an afternoon.

Write down who can authorise a payment, and above what value a second person is required. Many small businesses have never made this explicit, which means the answer in practice is "whoever is asked". If you already have a limit, check whether people actually observe it when the request looks urgent.

Make bank detail changes verifiable out of band. Any change to a supplier's payment details gets confirmed by ringing a number you already held, never a number in the email requesting the change. This single rule defeats a large proportion of invoice fraud, and it needs to apply to everyone, including when the request appears to come from a director.

Give people explicit permission to slow down. Attacks of this kind work on urgency and on seniority. A finance manager who believes that questioning an unusual instruction from the managing director will get them in trouble is exactly the vulnerability being exploited. Saying out loud that nobody will ever be criticised for verifying a payment request is a real control, and it is free.

Extend the strong logins beyond the technical accounts. Second-step verification, the code or prompt after the password, is often applied first to administrator and IT accounts. On this evidence the finance, sales, and operations accounts need it just as much.

Include those functions when you test. If your phishing exercises or your incident rehearsals only involve IT, you are practising the scenario that is not happening.

The reassuring part is that none of this is exotic. It is the ordinary discipline of not letting one person move money alone, applied with the knowledge that somebody is now specifically looking for the place where that discipline is missing.

How Steelwise can help

Working out where authority sits in a business, and where a single person could move money or data without a second pair of eyes, is a security review that does not require touching your systems at all. Get in touch.

Further reading

← All filings