AnyLearn
All lessons
Businessbeginner

Why This Role Is the Target, and How to Not Be the Story

Assistants sit where authority, access and urgency meet, which is exactly what impersonation fraud exploits. This lesson covers why the role is targeted, what changed when voice and video became cheap to fake, and the verification habits that hold up when a convincing executive is asking you to move quickly.

Updated · AI-authored, review-gated · how lessons are made

Not signed in: your progress and quiz score won't be saved.
Progress1 / 8

The role sits on the fault line

Lesson one described the assistant as a gatekeeper. That position is valuable to an organisation for the same reasons it is valuable to an attacker.

What an assistant has that an attacker wants. Access to the executive's accounts, calendar and correspondence. Knowledge of what is happening, including things not yet public. Standing to make requests of other people in the organisation, who will act on them. And in many organisations, the ability to initiate or approve payments and to change details on them.

What an assistant is trained to do that makes exploitation easier. Respond quickly. Act on instructions from someone senior without interrogating them. Handle things discreetly, without involving others. And solve problems rather than escalate them.

Every one of those is a professional virtue, and every one of them is exactly what a social engineering attack needs.

That combination, privileged access plus a professional obligation to be responsive to authority, is why this role is disproportionately targeted rather than incidentally caught.

Which means security awareness for an assistant is not a generic training module. It is a specific, role-shaped problem: how do you stay responsive and discreet, which is your job, without those qualities being the vulnerability.

The answer, developed through this lesson, is a small number of habits applied without exception, particularly to the requests that most feel like exceptions.

Full lesson text

All 8 steps on one page, for reading, reference, and search.

Show

1. The role sits on the fault line

Lesson one described the assistant as a gatekeeper. That position is valuable to an organisation for the same reasons it is valuable to an attacker.

What an assistant has that an attacker wants. Access to the executive's accounts, calendar and correspondence. Knowledge of what is happening, including things not yet public. Standing to make requests of other people in the organisation, who will act on them. And in many organisations, the ability to initiate or approve payments and to change details on them.

What an assistant is trained to do that makes exploitation easier. Respond quickly. Act on instructions from someone senior without interrogating them. Handle things discreetly, without involving others. And solve problems rather than escalate them.

Every one of those is a professional virtue, and every one of them is exactly what a social engineering attack needs.

That combination, privileged access plus a professional obligation to be responsive to authority, is why this role is disproportionately targeted rather than incidentally caught.

Which means security awareness for an assistant is not a generic training module. It is a specific, role-shaped problem: how do you stay responsive and discreet, which is your job, without those qualities being the vulnerability.

The answer, developed through this lesson, is a small number of habits applied without exception, particularly to the requests that most feel like exceptions.

2. The shape of the request

Business email compromise has been among the costliest categories of cybercrime tracked by the FBI's Internet Crime Complaint Center for years, and the attacks share a structure that is worth being able to recognise cold.

Authority. The request appears to come from someone whose instructions you would not normally question. A chief executive, a chief financial officer, a senior partner, or a major client.

Urgency. It must happen now. A deal is closing, a payment deadline is passing, a regulator is waiting. Urgency is not incidental; it exists to prevent the checking that would defeat the attack.

Secrecy. Do not discuss this with anyone. Framed as confidentiality about a sensitive deal, and functioning to isolate you from the colleague who would say that looks wrong.

A channel change. The request arrives somewhere slightly unusual, or asks you to continue somewhere else. This moves you away from systems that might flag it and from people who might see it.

And an irreversible action. A payment, a change of bank details, a credential, a document release. Something that cannot be undone once done.

The key insight is that these four appear together because each defeats a different defence. Authority defeats your judgement. Urgency defeats your process. Secrecy defeats your colleagues. The channel change defeats your systems.

So the practical detector is not any one element. It is the combination. A genuinely urgent request from your executive is normal. An urgent, secret, irreversible request that arrived on a new channel is an attack until proven otherwise, and that pattern recognition is worth more than any technical control.

3. What changed: the Arup case

Until recently, the practical defence against impersonation was that a voice or a face was hard to fake. That assumption is gone, and there is a documented case that shows exactly how.

In 2024, the engineering firm Arup confirmed it was the company behind a fraud reported by Hong Kong police. An employee in the firm's Hong Kong office received a message appearing to come from the United Kingdom-based chief financial officer, describing a confidential transaction.

The employee was suspicious. That detail matters: the ordinary defence worked initially.

To resolve the doubt, the employee joined a video conference. On the call were people who looked and sounded like the chief financial officer and several other colleagues. All of them were synthetic. Reporting on the case indicates the attackers built them from publicly available footage of those executives, who had appeared in online conferences and company videos.

Satisfied by the call, the employee made fifteen transfers totalling around twenty-five million dollars to five Hong Kong accounts. The fraud was discovered later, when the employee checked with headquarters.

Three lessons sit in that sequence.

The employee's suspicion was correct, and the video call was what overrode it. The verification step chosen was the one the attacker controlled.

The source material was public. Any executive who speaks at conferences or appears in company video has provided what is needed, and this cannot be prevented by the assistant.

And it took a multi-participant live video call. This is not a future risk being anticipated. It has already happened at scale.

4. Out-of-band verification

The single habit that defeats all of this, and the reason it works.

An attacker controls the channel they contacted you on. If they emailed you, they control that thread. If they called, they control that number. If they set up a video call, they control who appears on it.

So verification performed inside that channel verifies nothing. Replying to the email, calling back the number in the signature, or asking the person on the video call to confirm they are real are all requests routed to the attacker.

Out-of-band means confirming through a channel you established independently. The mobile number you already had for your executive, from your own records, not from the message. A call to the finance team through the internal directory. Walking to someone's desk.

The rule that follows is simple and it must be unconditional: any irreversible action requested through any channel is confirmed through a different channel you chose, before it happens.

Unconditional is the important word. Every property of these attacks, the seniority, the urgency, the confidentiality, exists to make you treat this instance as the exception. A rule with exceptions provides no protection, because the attack is specifically engineered to produce one.

And note what this costs: about ninety seconds. That is the entire price of the defence.

flowchart TD
A["Request arrives: payment, credentials, details change"] --> B["Attacker controls this channel"]
B --> C["Reply to the email"]
B --> D["Call the number in the signature"]
B --> E["Ask the face on the video call"]
C --> F["Verifies nothing: routed to the attacker"]
D --> F
E --> F
A --> G["Out-of-band: a channel you established"]
G --> H["Known number from your own records"]
G --> I["Internal directory, or in person"]
H --> J["Verified, then act"]
I --> J

5. Getting the executive to agree in advance

The verification rule only works if it survives contact with a genuinely impatient executive, and that is an agreement to make before it is needed rather than a stand to take during an incident.

The conversation to have, once, in calm conditions. Explain that you will verify any irreversible request through a known channel, every time, including when it appears to come from them, including when it is urgent, and including when they have said not to tell anyone. Ask them to agree that they will not be annoyed by this, and that if they ever are, that itself is a signal something is wrong.

Why this matters practically. Without that agreement, the assistant faces a live choice between appearing to distrust their executive and skipping the check. Under time pressure, with a senior person waiting, most people skip the check. The agreement removes the social cost, which is the actual barrier.

What to agree specifically.

A verification channel: which number you will call, which is your record and not one supplied in a message.

A shared phrase, optionally, for use when a callback is impractical. Low-tech and effective, because it is not derivable from public material.

That the executive will never ask you to bypass the check, so that a request to bypass it is itself the alarm.

And that genuine urgency accommodates ninety seconds. Anything that cannot survive a short verification call was never a legitimate business requirement.

Make the same agreement with the finance team, since payment instructions are the highest-value target and the assistant is frequently the conduit.

6. What you publish about your executive

An aspect of the role worth reconsidering, because assistants often control the material that makes impersonation possible.

The Arup attackers used publicly available footage. That is the general case rather than a detail: synthetic voice and video need source material, and executives generate it through conference talks, webinars, podcasts, video interviews and company marketing.

Most of that is genuinely valuable and should not stop. But assistants frequently make the small decisions about what gets published, and a few are worth making deliberately.

What raises exposure. Long, clean, single-speaker audio, which is the ideal training input. Video showing the executive in varied lighting and angles. Recorded internal all-hands material, which is both good source data and, because it is internal in tone, more convincing when misused.

What also matters and is less obvious. Publishing detailed travel or schedule information, which tells an attacker when the executive is unreachable. That window is when the fraudulent request arrives, and it is not a coincidence.

The proportionate response is not secrecy. It is awareness of the two things that actually help.

Assume the executive's voice and appearance can be convincingly reproduced, and design your verification around that assumption rather than around detecting fakes.

And be careful with unavailability. Not announcing publicly that the executive is on a long flight, in a board meeting all day, or unreachable removes the window an attacker prefers.

That second one costs nothing and is routinely given away in an out-of-office message.

7. Do not try to spot the fake

A tempting but mistaken approach deserves explicit warning, because assistants are frequently taught it.

Much awareness training lists tells: unnatural blinking, odd lip synchronisation, strange lighting, flat audio, a lag before responses. Learning these feels like acquiring a defence.

The difficulty is threefold.

They are transient. Every published tell is a defect being actively engineered away, so a list of them has a short shelf life and becomes wrong rather than merely outdated.

They produce false confidence, which is the dangerous failure. An assistant who has checked for the tells and found none now believes the call is genuine, and proceeds with more confidence than if they had never learned the list. In the Arup case the employee's initial correct suspicion was overcome by a video call; a tell-checking habit would have supplied exactly that false reassurance.

And they push you into the attacker's channel. Examining the call for authenticity is verification inside the channel the attacker controls, which the previous step established verifies nothing.

The correct posture is to stop trying to assess authenticity at all. It does not matter whether the person on the call is real. What matters is whether the request has been confirmed through a channel you chose.

That reframing is what makes the defence durable, because it does not depend on the current quality of synthetic media. Generation can improve indefinitely without weakening a rule that never looked at the media in the first place.

If you take one thing from this lesson: verify the request, not the person.

8. The habits, and what to do if it happens

The whole lesson reduced to practice, and then the part nobody plans for.

The habits.

Any irreversible action is verified out of band, through a channel from your own records, every time, without exception for seniority, urgency or confidentiality.

Bank detail changes are treated as the highest-risk request there is, verified with the counterparty on a number you already held, never one supplied in the message requesting the change.

A request not to tell anyone is treated as a signal rather than an instruction. Legitimate confidentiality does not require you to bypass a control.

Urgency raises suspicion instead of lowering scrutiny, which is the inversion the attack depends on.

And voice and video are not identity. Recognising someone is no longer evidence of who they are.

If it happens anyway, and it happens to careful people. Speed matters more than anything else, because funds are sometimes recoverable in the first hours and rarely afterwards. Tell the bank immediately, then your finance and security teams, then your executive. Do not spend time establishing what occurred first; report while it is still reversible.

And do not conceal it out of embarrassment. That instinct is understandable and it is what turns a recoverable incident into a total loss.

A final point worth holding on to. In the documented cases, the people deceived were not careless. They were conscientious employees responding to what appeared to be a legitimate instruction from someone entitled to give it. Being had by a good attack is not a failure of intelligence, and organisations that treat it as one guarantee the next one is reported too late.

Check your understanding

The lesson ends with a 5-question quiz. Take it in the player above to see your score.

  1. Why is the assistant role disproportionately targeted?
    • Assistants receive less security training than other staff
    • Privileged access combines with a professional obligation to be responsive, discreet and quick with authority
    • Assistants use less secure software
    • Their email addresses are easier to guess
  2. Why do authority, urgency, secrecy and a channel change appear together?
    • They are artefacts of automated attack tooling
    • They make the message appear more formal
    • Each defeats a different defence: your judgement, your process, your colleagues, and your systems
    • They are required to bypass email filtering
  3. In the Arup case, what overcame the employee's correct initial suspicion?
    • A forged legal document
    • Pressure from a colleague in the same office
    • An email from the CFO's genuine address
    • A video call with synthetic versions of the CFO and colleagues, built from public footage
  4. Why is learning deepfake 'tells' a poor defence?
    • They are transient, they create false confidence, and checking them keeps you inside the attacker's channel
    • They require specialist equipment to detect
    • They only apply to video, not audio
    • They are proprietary to detection vendors
  5. What should the standing agreement with the executive establish?
    • That the assistant will report all suspicious messages weekly
    • That verification happens every time, that the executive will never ask to bypass it, and that genuine urgency accommodates ninety seconds
    • That the executive will avoid public speaking
    • That all payments require two assistants to approve

Related lessons