Free Diagnostic — Accounts Payable
Your two-person rule can't stop what it can't see.
A full kill-chain self-check of your AP workflow and supplier payment process, from invoice ingestion to the final payment run. Ten controls, plain English, no technical background needed. Score yourself in under ten minutes.
$227M+
Lost to invoice fraud (AU, 2023)
72 Hrs
Maximum bank recall window
30–40%
Recovery rate with fast action
$10
Cost of AP credentials online
Instant Access — Ten Controls
Score Your AP Workflow
Answer each control honestly: Yes, No or Unsure. Each "No" is a gap attackers already know how to find, and "Unsure" counts as No: not knowing is the finding.
How Invoices Enter Your Business
S1The front door is open, is anyone watching it? Every fake invoice attack starts here.
Invoice Receipt ★
Do you require suppliers to submit invoices via a secure portal (e.g. Peppol e-invoicing) rather than as PDF email attachments? PDF invoices can be intercepted and bank details changed in minutes using cheap AI tools; the document looks identical.
Email Spoofing Protection (DMARC) ★
Is DMARC configured on your email domain and set to "reject" mode? Without enforcement, anyone can send an email that looks like it came from your CEO or CFO: the most common vector for fake payment approvals.
Stolen Credential Monitoring
Do you monitor whether your AP team's login credentials have been stolen and are being sold online? AP credentials sell for as little as $10, letting an attacker study supplier relationships for weeks before striking.
Who Can Log In, and What Can They Do?
S2Attackers don't break in. They log in. Standard multi-factor authentication can be bypassed.
Device Trust ★
Is your accounting system access strictly limited to pre-approved, registered company devices? Restricting to known devices blocks an attacker even when they hold valid credentials.
Separation of Duties ★
Do you strictly enforce separation of duties, ensuring the person changing vendor records cannot also approve payments? One person controlling both gives an attacker complete end-to-end control.
Your Supplier & Vendor Records
S3Your supplier list may already be a target. A fraudulent bank account on this list is as valuable as direct system access.
Adding New Suppliers ★
Do you independently verify a new supplier's bank details against a verified database (e.g. Eftsure) before adding them? Calling the number in the email may just connect you to the scammer.
Bank Detail Changes ★
When a supplier requests a bank account change, are payments to them suspended until independently verified? Attackers time change requests to land just before a large payment run.
Inactive Supplier Review
Do you regularly check whether suppliers in your system still have active ABNs and valid insurance? A deregistered ABN left active is a direct fraud vector.
The Final Step Before Money Leaves
S4Even if every other control has failed, this is your final opportunity to catch a fraudulent payment.
Pre-Payment Verification ★
Before each payment run, do you verify supplier bank details against a source independent of your own accounting system? Checking only your own system cannot catch fraud already inside it.
Payment File Integrity
Is your payment batch file cryptographically verified to detect modifications between generation and bank upload? A single-character change in a batch of 200 payments is invisible to human review.
Your Risk Level
0/10 No / Unsure
Answer all ten controls to see your result.
0 of 10 answered
Already Seeing Something?
If working through this raised a real concern, an unexplained payment, a supplier bank change you cannot verify, a login that should not exist, do not wait for certainty. A compromise assessment establishes, discreetly and fast, whether something is underway.
See Cyber Investigations →