MODULE 4 ยท LESSON 3
Free โ no login requiredSign in to track progress, save quiz attempts and enrol in the full course.
Sign in to track progress / enrolThe Verification Ritual
Everything so far has been diagnosis. This is the treatment, and it is deliberately mechanical.
Mechanical matters. Under pressure, with a senior figure apparently waiting and visibly impatient, judgement degrades in exactly the way the attacker intends. A procedure you can execute without deciding anything is the only kind that survives that moment.
The trigger
Run the ritual whenever a request carries the skeleton from the previous lesson, and always when it involves money, credentials, or data leaving the organisation. The trigger is the nature of the request, never the channel it arrived on and never how convincing it seemed.
The four steps
Step one: stop, and do not reply in the same thread.
The instinct is to respond where the message arrived. Resist it. Replying in the same channel, or calling a number contained in the message, keeps you inside a space the attacker controls. Nothing you learn there has any value.
Step two: switch to a channel you already had.
Contact the person using details you already possessed. The company directory, a number in your phone from before today, an internal profile, or by walking to their desk.
This single step defeats nearly every attack in this course, including the Arup fraud in its entirety. The attacker controlled the email and the video call. They did not control the organisation's own contact records.
Never a number, link or address supplied in the message itself. That is the entire trick, and it is presented as helpfulness.
Step three: ask something unscripted.
If you reach them and any doubt remains, reference a specific shared detail that is not published anywhere. Where you sat at last week's meeting. What was decided about a particular item. The name of a colleague who joined recently.
A synthesis of a public figure is built from public material and cannot answer private questions. Keep it specific and factual, avoid anything guessable, and note that a real colleague will answer instantly while an impostor will deflect, claim a bad connection, or return to the urgency.
Step four: if anything is still wrong, do not proceed, and report it.
Not "wait and see". Report it, because if you received it, colleagues probably did too, and Module 6 covers why speed changes outcomes so sharply.
The cost asymmetry
The reason the ritual is always worth running, and the argument to give anyone who resists it.
If you verify and the request was genuine, you have spent perhaps thirty seconds and experienced a moment of mild awkwardness. That is the entire downside, and in a healthy organisation there is not even awkwardness, because checking is normal.
If you skip verification and the request was fraudulent, the outcome ranges from an emptied account to a company wide breach to, in the Arup case, twenty five million dollars.
Those costs are not remotely comparable, and any decision procedure that treats them as comparable is broken. Over verify. Always. The maths is not close.
There is a corollary for anyone who manages people. If your staff hesitate to verify a request from you because they expect irritation, you have made your organisation cheaper to attack. The fix is to visibly welcome being checked. Say thank you when someone verifies a request you actually sent. That single habit, repeated publicly a few times, is worth more than an annual training module.
Code phrases
For the highest risk scenarios, agree a word in advance. It sounds theatrical until you consider the specific attack it defeats.
With your finance team. A spoken phrase required before any payment instruction is acted on, never written down in email or chat. An attacker with a perfect voice clone and a full picture of your business does not have it.
With your family. This one matters more than people expect. A common fraud is a call from a cloned voice of your child or parent, distressed, in trouble, needing money immediately. It works because it bypasses reasoning entirely and goes straight to panic. A few seconds of public audio is enough to build the clone.
A pre agreed word collapses that attack in one question. Choose something memorable and not guessable, and tell the people who need it in person.
Individual vigilance is fragile because it depends on the right person being alert on the right day. A few structural changes make the ritual work even when nobody is paying attention.
Make dual authorisation a threshold rule. Any payment above a defined amount, and any change to supplier bank details regardless of amount, requires a second named approver who verifies independently. Note the second half: altering stored bank details is the higher risk action, because it redirects every future payment rather than one, and it frequently has no approval requirement attached at all. This control alone would have stopped Arup.
Pre commit the callback numbers. Maintain an internal directory that is the only accepted source of contact details for verification, and state explicitly that numbers supplied in a request are never used. This removes the judgement call in the moment, which is where errors happen.
Rehearse it. A short exercise where a finance team practises receiving an urgent instruction from a senior figure and running the ritual is worth more than a slide deck. People perform under pressure the way they have practised, and a procedure never rehearsed is a procedure that will not be recalled.
Give it a name and a normal status. When verifying has a name that anyone can invoke without implying suspicion, the social cost drops to nearly zero. "I am just running the check" is a sentence that should be unremarkable, including when directed at the chief executive, and especially then.
Remove the reasons to bypass it. If the official payment process is slow enough that people routinely work around it under time pressure, the workaround is now your real process and it has no controls. Fix the friction rather than adding a policy that instructs people to tolerate it.
The pattern across all five is the same as everywhere else in this course: move the defence from something a person has to remember to something the system does anyway.
A supplier emails to say their bank details have changed and asks that future payments go to the new account. The email is well written and comes from the correct address. What is the appropriate response?
The verification ritual
Click to flipStop, switch to a channel you already had, ask something unscripted, and report if anything remains wrong. Mechanical by design, because judgement degrades under pressure.
Click to flip backWhen a request carries the skeleton, run four mechanical steps: stop and do not reply in the thread, switch to a channel you already had, ask something unscripted, and report if anything is still wrong. Mechanical is the point, because judgement is exactly what fails under manufactured pressure. The cost asymmetry makes over verifying always rational, thirty seconds against potentially everything, so managers should visibly thank people for checking rather than making it socially expensive. Agree code phrases with your finance team and your family in advance, because a cloned voice in distress defeats reasoning and a pre agreed word ends it in one question.