AnyLearn
All lessons
Businessbeginner

Verifying the Request, Not the Person

If recognition no longer establishes identity, verification has to move to the channel. This lesson builds the practice: out-of-band confirmation, which requests need it, designing protocols people will actually follow under pressure, the household version, and what to do in the first hour after something goes wrong.

Updated · AI-authored, review-gated · how lessons are made

Not signed in: your progress and quiz score won't be saved.
Progress1 / 8

The one idea

Everything practical in this cursus reduces to a single principle, and it is worth stating before any of the detail.

An attacker controls the channel they contacted you on. If they emailed you, they control that thread and any reply address in it. If they called, they control that number and anyone who answers a callback to it. If they set up a video call, they control who appears on it. If they messaged you on a platform, they control that account.

Therefore any verification performed inside that channel verifies nothing. Replying to ask are you sure, calling the number in the signature, or asking the face on the screen to confirm they are real are all questions routed to the attacker, who will answer yes.

Out-of-band verification means confirming through a channel you established independently. A number you already had, from your own records or the corporate directory. A separate messaging system. Walking to someone's desk. Calling the organisation's published switchboard rather than a number you were given.

The reason this defence is durable, unlike every detection-based approach, is that it never examines the message. It does not matter how convincing the email is, how accurate the voice is, or how many synthetic colleagues appear on the call. The check happens somewhere the attacker is not.

Generation can improve without limit and this still works. That property is rare in security and it is why the rest of this lesson is about making the habit reliable rather than about improving anyone's judgement.

Full lesson text

All 8 steps on one page, for reading, reference, and search.

Show

1. The one idea

Everything practical in this cursus reduces to a single principle, and it is worth stating before any of the detail.

An attacker controls the channel they contacted you on. If they emailed you, they control that thread and any reply address in it. If they called, they control that number and anyone who answers a callback to it. If they set up a video call, they control who appears on it. If they messaged you on a platform, they control that account.

Therefore any verification performed inside that channel verifies nothing. Replying to ask are you sure, calling the number in the signature, or asking the face on the screen to confirm they are real are all questions routed to the attacker, who will answer yes.

Out-of-band verification means confirming through a channel you established independently. A number you already had, from your own records or the corporate directory. A separate messaging system. Walking to someone's desk. Calling the organisation's published switchboard rather than a number you were given.

The reason this defence is durable, unlike every detection-based approach, is that it never examines the message. It does not matter how convincing the email is, how accurate the voice is, or how many synthetic colleagues appear on the call. The check happens somewhere the attacker is not.

Generation can improve without limit and this still works. That property is rare in security and it is why the rest of this lesson is about making the habit reliable rather than about improving anyone's judgement.

2. Which requests need it

Verifying everything is not workable and would be ignored within a week. The rule has to be scoped tightly enough that people actually apply it.

The test is irreversibility. If the action cannot be undone once taken, it gets verified. If it can, it does not need to.

What that captures.

Any payment, and particularly any change to payment details. Supplier bank detail changes are the highest-value target in most organisations, and they arrive looking entirely routine.

Any credential, code or approval prompt.

Any grant of access to a system, building or account.

Any release of data: customer records, personnel information, documents.

Any purchase of gift cards or vouchers, which remains common because they are irreversible and untraceable.

And any change to where something is delivered or where a payroll payment goes, which is a quieter version of the same fraud.

What it excludes, deliberately. Ordinary correspondence. Requests for information already public. Scheduling. Anything you could reverse in an hour with an email.

That scoping matters more than it appears. A rule covering everything gets abandoned; a rule covering six specific categories can be followed permanently. And the six categories cover the overwhelming majority of actual losses, because fraud requires an irreversible action by definition. If the attacker could be undone, there is nothing in it for them.

So the sentence to remember is short. Irreversible means verified, through a channel I chose.

3. Designing a protocol people will follow

A verification rule fails on the social cost of applying it, not on the technical difficulty. The design has to remove that cost in advance.

The barrier is real and specific. An employee facing a convincing, urgent request from someone senior must choose between appearing to distrust them and skipping the check. Under pressure, with a senior person waiting, most people skip it. That is not a failure of training; it is a rational response to the incentives in the room.

So the protocol has to be agreed before it is needed, publicly, at the top.

What the agreement contains. That irreversible requests are always verified, including from the chief executive, including when urgent, including when confidential. That nobody will be criticised for checking, and that being annoyed by a check is itself a warning sign. That leadership will never ask anyone to bypass it, so a request to bypass it is the alarm. And that genuine urgency accommodates ninety seconds, because no legitimate business requirement fails on a short callback.

The channels are named in advance too: the directory, the number in the finance system, the known switchboard. Not a number supplied in the request.

And a shared phrase is a legitimate low-technology option, agreed in person, for cases where a callback is impractical. It cannot be derived from public material, which is exactly what makes it work.

The test of whether a protocol is real. Has the most senior person in the organisation been visibly verified, and did they respond well? If not, the rule is theoretical, and it will fail the first time it matters.

flowchart TD
A["Irreversible request arrives"] --> B["Social cost: checking looks like distrust"]
B --> C["Under pressure, most people skip the check"]
C --> D["Remove the cost in advance"]
D --> E["Leadership agrees publicly: always verify, no exceptions"]
D --> F["Nobody is criticised for checking"]
D --> G["A request to bypass the check is the alarm"]
D --> H["Channels named in advance: directory, finance system, switchboard"]
E --> I["Test: has the CEO been visibly verified, and did they respond well?"]

4. The controls that do not depend on people

Verification habits are necessary and they should not be the only defence, because any control depending on a tired person under pressure will eventually fail.

The process controls that matter most, roughly in order of value.

Separation of duties on payments. The person who sets up a payee is not the person who approves the payment. This alone defeats most of these frauds, because the attacker would need to compromise two people.

A fixed procedure for bank detail changes that does not depend on who asked. Verification with the supplier on a number held before the request, a waiting period, and a second approver. Applied to every change without exception, because the exception is the attack.

Payment thresholds requiring additional approval, set low enough to catch the realistic fraud rather than only the catastrophic one.

Phishing-resistant authentication. Hardware security keys and passkeys defeat credential phishing structurally, because the credential is bound to the real site and cannot be relayed through a proxy page. This is the single most effective technical control available against the credential half of the problem, and it removes an entire attack category rather than mitigating it.

And limiting what any one account can do, so that a compromise is contained rather than total.

The framing that matters for anyone designing this. Human verification and process controls address different halves. Verification catches the request that reached a person. Process controls catch the case where verification did not happen, because someone was busy, new, or having a bad day.

An organisation relying only on people being careful has decided that no one will ever be careless, which is not a decision it can enforce.

5. The household version

These attacks reach people at home, and the domestic versions are in some ways more damaging because there is no process to fall back on.

The pattern that has caused the most harm. A call, apparently from a family member, in distress. They have been in an accident, been arrested, lost their phone, or are stranded. They need money immediately and they are upset. The voice is theirs.

Why this works so well. It removes deliberation entirely, because a distressed family member produces an emotional response that suppresses checking, and the request is framed so that hesitating feels like abandoning them. Attackers also frequently add a reason not to contact anyone else: do not tell mum, I will be in trouble.

Other domestic versions include calls apparently from a bank's fraud team, requests to move money to a safe account, and messages apparently from a child on a new number.

What protects a household, and it costs nothing to set up.

Agree a family phrase, in person, that any real emergency call must include. Not a birthday or a pet's name, since those are frequently public.

Agree that you will always hang up and call back on the number you already have. Say in advance that this is what everyone will do, so nobody is offended by it.

And talk to older relatives specifically, because they are targeted disproportionately and because the advice they received historically was about recognising a scam by how it sounded.

The framing that works for family conversations. This is not about being suspicious of each other. It is agreeing a way to prove it is really you, in advance, because voices can now be copied.

6. The first hour

Something will eventually get through, and what happens in the following hour determines the size of the loss. Most of that hour is currently wasted on the wrong things.

What to do, in order.

If money moved, contact the bank immediately. Before investigating, before telling anyone internally, before establishing what happened. Funds are sometimes recallable in the first hours and rarely afterwards, and every minute spent understanding the incident is a minute the money is still moving.

If credentials were entered, change that password from a different device and revoke active sessions. Changing the password alone does not remove an attacker who already has a session.

Then report internally, through whatever route exists, even if you are not sure anything happened.

Then preserve evidence rather than deleting it. The message, the headers, the number, the timestamps. People delete the embarrassing email, which removes what investigators need.

And then work out what happened, which is the step people start with.

The cultural condition that makes any of this work. People must be willing to report immediately, and they will not if the response is punitive. An organisation where clicking a link means public embarrassment has chosen slow reporting, and slow reporting is what turns a contained incident into a total loss.

So the message from leadership has to be explicit and repeated. Reporting fast is the behaviour we want, we will thank you for it, and nobody has ever been disciplined here for reporting something.

And the thing to hold on to individually. In the documented cases, including Arup, the people deceived were conscientious employees responding to what looked like a legitimate instruction. Being caught by a good attack says nothing about your competence, and treating it as shameful is exactly what makes the next one worse.

7. Training that might actually work

Given that detection training has stopped working, it is worth saying what should replace it, because most organisations will keep running some programme.

Teach the structure rather than the signals. The combination of authority, urgency, secrecy, a channel change and an irreversible action is what identifies an attack, and it is stable. Bad grammar is not.

Teach the verification habit as a procedure, not as vigilance. Vigilance degrades and cannot be sustained; a procedure applied to six named categories can be followed indefinitely. The behaviour you want is not people being alert. It is people making a phone call.

Make it specific to the role. What an accounts payable clerk should verify is different from what a developer should, and generic training is generic because it is cheap rather than because it is effective. The finance team needs the bank detail procedure; the engineering team needs to know about approval prompts and package installation.

Practise the awkward conversation. The hard part is not knowing to verify. It is saying to a senior person, I am going to call you back on the number I have. Rehearsing that sentence, out loud, is more useful than an hour of content.

Measure reporting rather than clicking, as the previous lesson argued.

And include the personal and family versions, both because it protects people and because it is the part they will actually engage with. Training that helps someone protect an elderly parent gets remembered; training about corporate policy does not.

The honest summary. The goal is not a workforce that spots fakes. That is unattainable and getting more so. It is a workforce that has one reliable habit and an environment where using it is easy.

8. The practice, assembled

Everything in this lesson, reduced to what a person and an organisation should actually do.

For an individual.

Irreversible means verified. Payments, payment detail changes, credentials, approval prompts, access, data releases, gift cards.

Verify out of band, on a channel from your own records. Never a number, link or callback supplied in the request.

Treat urgency as a reason for more scrutiny rather than less, and treat a request for secrecy as a signal rather than an instruction.

Deny and report any approval prompt you did not initiate, because it means someone already has your password.

Do not try to assess whether a voice or face is real. It is not a question you can answer and it is not the question that matters.

Agree a family phrase, and talk to older relatives.

And if something goes wrong, call the bank first and report immediately, before understanding it.

For an organisation.

Leadership agrees the verification rule publicly, submits to it visibly, and states that a request to bypass it is the alarm.

Separation of duties on payments, and a fixed bank detail change procedure with no exceptions.

Phishing-resistant authentication, which structurally removes the credential attack rather than mitigating it.

Train the structure and the habit, role by role, and measure reporting speed.

And make reporting safe, loudly and repeatedly, because the cultural condition determines whether every other control gets the chance to work.

The whole cursus in one line. Stop trying to tell what is real, and start verifying through somewhere the attacker is not.

Check your understanding

The lesson ends with a 5-question quiz. Take it in the player above to see your score.

  1. Why does out-of-band verification remain effective as generation improves?
    • It uses encrypted channels attackers cannot intercept
    • It never examines the message, so the check happens somewhere the attacker is not
    • It relies on detecting synthetic artefacts in audio
    • It requires attackers to compromise multiple accounts
  2. What scopes the verification rule so people will actually follow it?
    • Applying it only to requests from outside the organisation
    • Applying it only above a monetary threshold
    • Applying it to anything marked urgent
    • Applying it to irreversible actions, which is about six named categories
  3. What actually causes verification protocols to fail?
    • The social cost of appearing to distrust a senior person under time pressure
    • Employees forgetting the procedure
    • Technical difficulty in reaching the right number
    • Attackers spoofing the verification channel
  4. Why do hardware keys and passkeys defeat credential phishing structurally?
    • They require biometric confirmation
    • They generate longer codes than authenticator apps
    • The credential is bound to the real site and cannot be relayed through a proxy page
    • They expire after a single use
  5. What should happen first if money has moved?
    • Preserve the evidence
    • Establish what happened
    • Notify the executive team
    • Contact the bank, before investigating anything

Related lessons

Business
beginner

The Tells Are Gone: What Actually Changed About Attacks

Security awareness training taught people to spot bad grammar, odd domains and generic greetings. Those signals are gone. This lesson covers what generative tools changed about attacks, what they did not change, and why detection-based defence was always the weaker half.

8 steps·~12 min
Business
beginner

Why This Role Is the Target, and How to Not Be the Story

Assistants sit where authority, access and urgency meet, which is exactly what impersonation fraud exploits. This lesson covers why the role is targeted, what changed when voice and video became cheap to fake, and the verification habits that hold up when a convincing executive is asking you to move quickly.

8 steps·~12 min
Business
beginner

The Risk You Bring In: Your Own AI Tools

The other direction of the problem. Employees using AI tools create exposure through data leaving the organisation, prompt injection turning an assistant against its user, malicious extensions, and code suggestions nobody verified. This lesson covers what to worry about and what is overstated.

8 steps·~12 min
Programming
advanced

The Runtime Stack, and What Isolation Is Worth

One command hides four layers of software and a set of standards that made them interchangeable. This lesson takes the stack apart, then asks the question the whole path has been building toward: given a shared kernel, how much is container isolation actually worth, and what has to be added before it is a security boundary.

8 steps·~12 min