Security awareness for finance staff: email compromise, payment diversion and fast reporting
For accounts payable, payroll, credit control and bookkeeping staff, and the managers who approve payments. Complete 'Business email compromise and payment fraud' first. That course covers the basics of changed bank details and gift-card requests. This one practises them on realistic inbox material: lookalike domains, hidden inbox rules, payroll changes, executive pressure, requests for employee tax data, and what to do in the first hour after money has gone. Reporting routes are given for the US and the UK. Your organisation's payment and approval procedures always come first. This course is not legal advice.
- Level
- Intermediate
- Length
- About 73 minutes
- Contents
- 5 lessons · final exam
- Status
- Published · updated 10 Oct 2026
Skills you'll practise
- Identify signs of email compromise in a finance inbox, including lookalike domains, reply-to changes and hidden inbox rules
- Verify payment-instruction and payroll changes through an independent channel before acting
- Choose the right response when a payment request bypasses normal approval, including executive impersonation
- Recognise requests for employee tax or payroll data as fraud attempts that need the same checks as payments
- Report a suspected or completed fraudulent payment immediately through internal and external routes
Course outline
- 1.Identifying signs of email compromise in a finance inboxLesson · 15 min
- 2.Verifying payment and payroll changes through an independent channelLesson · 14 min
- 3.Responding when a payment request bypasses normal approvalLesson · 12 min
- 4.Recognising requests for employee tax and payroll dataLesson · 8 min
- 5.Reporting a fraudulent payment immediatelyLesson · 9 min
- 6.Security awareness for finance staff: email compromise, payment diversion and fast reporting: knowledge checkKnowledge check · 14 questions
- 7.Security awareness for finance staff: email compromise, payment diversion and fast reporting: practical exerciseKnowledge check · 1 question
- 8.Final exam10 questions · passing it completes the course, so people who already know the material can test out
Sources it draws on
The lessons and questions are written from these references, so learners can go back to the original.
- FinCEN Advisory FIN-2019-A005: Updated Advisory on Email Compromise Fraud Schemes Targeting Vulnerable Business Processes (16 July 2019)
- U.S. Secret Service: Business Email Compromise (BEC)
- UK NCSC: Phishing attacks: defending your organisation (reviewed 13 February 2024)
- UK NCSC: Phishing scams: how to spot scam emails, texts and calls
- UK NCSC: Report a scam email (and where to report if you've lost money)
- CISA: Avoiding Social Engineering and Phishing Attacks (1 February 2021)
See it with your own jobs and topics
Tell us about your team and we'll walk you through setup, from choosing jobs to your first skills check.