Professor Charles E Orbih

Paper presented at Eko Academia

October 3, 2026

Article Summary

Small businesses face a material risk of cyber-enabled payment fraud because routine financial activity depends on trusted relationships, digital accounts, and rapid decisions. This paper presents a practical 30-day security sprint designed for small businesses that need a manageable starting point rather than a complex technical program. The four-week approach focuses on protecting accounts, verifying payments, securing people and devices, and practicing incident response. It combines multifactor authentication, access review, supplier call-backs, two-person payment approval, basic device and backup practices, staff huddles, and a short fraud drill. The approach treats fraud prevention as an operating habit: when a message creates urgency, asserts authority, or demands secrecy, the appropriate response is to pause, verify through an independent channel, and report concerns quickly. The paper connects these measures to current small-business cybersecurity guidance and offers an implementation sequence that leadership can assign, monitor, and repeat.

Suggested WordPress tags: small business cybersecurity, business email compromise, payment fraud, multifactor authentication, incident response

Introduction

For many small businesses, the most consequential cybersecurity incident is not a dramatic technical breach. It is a familiar-looking request that causes a person to disclose a code, approve a payment, or accept changed bank details without an independent check. Email, messaging platforms, online banking, accounting applications, and mobile devices make ordinary operations faster, but they also create channels that criminals can impersonate or exploit. A practical security program must therefore protect both the accounts that move information and money and the decisions made by people who use those accounts.

The National Institute of Standards and Technology (NIST, 2024) frames cybersecurity risk management through the functions of Govern, Identify, Protect, Detect, Respond, and Recover. Those functions can sound expansive to an organization with limited staff and budget. The purpose of the 30-day security sprint is to translate them into four short, sequenced weeks of work. The sprint does not claim to eliminate fraud or replace legal, banking, or technical advice. Rather, it establishes a baseline of habits and controls that reduce the likelihood that one compromised credential or persuasive message becomes a financial loss.

The Payment-Fraud Problem for Small Businesses

Reported losses demonstrate the scale of cyber-enabled fraud, although figures from different reporting systems should not be treated as directly comparable. The Federal Bureau of Investigation, Internet Crime Complaint Center (FBI IC3, 2026) recorded 1,008,597 complaints and $20.877 billion in reported losses in 2025. Business email compromise (BEC) alone accounted for 24,768 complaints and $3.047 billion in reported losses. In Nigeria, the Nigeria Inter-Bank Settlement System Plc (NIBSS, 2026) reported ₦25.85 billion in digital-payment fraud losses in 2025 across 67,518 incidents. NIBSS also identified social engineering, including insider abuse, SIM-swap fraud, account compromise, and phishing, as the most prevalent technique described in its report.

These figures reinforce a practical point: fraud often targets the movement of money rather than only the confidentiality of information. A criminal may impersonate a supplier, executive, bank employee, or customer; reuse information from a compromised account; or apply pressure through a new phone number or a time-sensitive request. The FBI (n.d.) describes BEC as a financially damaging crime that relies on messages appearing to come from known sources. Typical examples include a vendor invoice with altered payment details or an executive request for an urgent purchase. The control objective is consequently straightforward: build a reliable pause into any high-risk request and verify it without relying on the message, number, link, or address supplied by the requester.

A Behavioral Response to Social Engineering

The sprint uses three cues to help staff recognize manipulation: urgency, authority, and secrecy. Urgency appears when a payment must be made immediately. Authority appears when the sender claims to be an executive, banker, or important supplier. Secrecy appears when the recipient is instructed not to tell a colleague or to bypass normal procedure. None of these cues proves fraud on its own, but their presence changes the correct workflow. Staff should pause the transaction, verify the request through a known and independently sourced contact channel, and report the concern to the person responsible for payments or incident response.

The FBI (n.d.) specifically advises organizations to verify payment and purchase requests in person when possible or by telephone, and to verify changes in account numbers or payment procedures with the requesting party. This supports a call-back rule: staff do not reply to the suspicious thread or use a phone number contained in it. Instead, they locate the supplier or colleague in a verified contact list and place a fresh call. The rule is simple enough to use under pressure and creates a record of who confirmed the change.

Thirty-Day Security Sprint

The proposed implementation sequence is shown in Table 1. The order is intentional. Week 1 reduces the chance that an attacker can use a stolen password alone. Week 2 introduces controls at the point where money moves. Week 3 reduces common device and staff vulnerabilities. Week 4 makes response responsibilities visible before an incident occurs. Each week should have a named owner, a completion date, and a short leadership check-in.

Table 1

Thirty-Day Security Sprint Implementation Plan

WeekPrimary objectiveImplementation activities
1Protect accountsEnable MFA for email, banking, accounting, and administrator accounts; review access; remove former staff; activate alerts and appropriate transfer limits.
2Verify paymentsAdopt two-person approval for defined payments and all bank-detail changes; maintain verified supplier contacts; apply the call-back rule.
3Secure people and devicesEnable updates and screen locks; separate guest Wi-Fi; back up essential records and test a restore; hold a short staff awareness huddle.
4Practice the responseConduct a fraud drill; begin a weekly reconciliation routine; assign incident roles; approve and post a one-page payment-security policy.

Note. Activities align with NIST Cybersecurity Framework 2.0 small-business guidance (National Institute of Standards and Technology, 2024).

Week 1: Protect Accounts and Limit Access

The first week focuses on accounts that can send messages, authorize payments, modify financial records, or administer other systems. Enable multifactor authentication (MFA) for email, internet banking, accounting systems, cloud storage, business messaging applications, and privileged administrator accounts. The Cybersecurity and Infrastructure Security Agency (CISA, n.d.) emphasizes that passwords alone are insufficient and recommends phishing-resistant MFA where available. For organizations that cannot immediately deploy security keys or other phishing-resistant methods, an authenticator application with number matching or a one-time code offers a stronger starting point than relying solely on email or text messages.

Access review is the second action. A small business should document who has access to business email, banking, accounting software, payment applications, social media pages, cloud files, and connected messaging accounts. Each person’s access should be tested with a simple question: Does this person still need this access to perform their current job? Former staff should be removed promptly, shared accounts should be retired where practical, and administrator privileges should be limited to the few people who genuinely need them. NIST (2024) similarly advises small businesses to restrict access to sensitive information to those who need it and to remove access when it is no longer required.

Finally, the business should activate transaction alerts and review payment limits. The appropriate limit varies by organization, but it should reflect normal business activity rather than the maximum amount a criminal could move in a single day. Alerts do not replace approval controls; they increase the likelihood that an irregular transfer is noticed early enough to be investigated or recalled.

Week 2: Verify Payments and Separate Duties

Week 2 addresses the moment of greatest financial exposure: the decision to send money. The core control is separation of duties. For payments above a business-defined threshold and for every change in supplier bank details, one person prepares the payment, and a different person approves it. This division of responsibilities reduces the chance that a single rushed, deceived, or compromised employee can complete a fraudulent transfer. The organization should write this threshold into its payment-security policy and review it as the business changes.

A verified supplier contact list is equally important. The list should include the supplier’s name, a known contact, a phone number, and any payment details that were previously confirmed through an independent channel. When new bank details arrive, the employee follows five steps: stop; look up the supplier in the verified list; call the known number; confirm the request; and report a suspicious message. Do not change payment numbers just because an email, SMS, or WhatsApp message looks familiar. Combining a known contact list with 2-person approval makes the call-back rule a repeatable financial control, rather than an informal preference.

Week 3: Secure People, Devices, and Essential Data

Week 3 focuses on technical hygiene. Enable automatic updates on business computers and mobile devices and require a screen lock on each device. The business should change the default passwords on its network equipment and provide a separate guest Wi-Fi network rather than allowing visitors to join the organization’s operational networks. NIST (2024) recommends regular patching, changing default manufacturer passwords, and prioritizing safeguards that reduce the likelihood of routine compromise.

The business should also back up essential information, including invoices, customer records, financial data, and the documents needed to operate after a disruption. A backup is not sufficient unless it can be restored. Perform a restoration to show evidence that the copy is available, usable, and understood by the person who will need it. NIST (2024) identifies both regular backup and backup testing as small-business priorities, linking protection activities to the later recovery function.

People are part of this control environment. A 15-minute weekly huddle can use one real scam example to ask three questions: What are the red flags? What would we do? How would we report it? The purpose is not to test staff or assign blame. It is to make verification a normal professional behavior and to reinforce three short rules: never share a password, OTP, or verification code; bank details do not change on one message; and when in doubt, pause and ask.

Week 4: Practice Response and Learn From Incidents

The final week assumes that some controls will fail and focuses on response. A 15-minute fraud drill can simulate a payment sent to a fraudulent account or an OTP disclosed to an impersonator. The team should identify who contacts the bank, who can pause pending payments, which messages and receipts must be preserved, who communicates with the supplier or staff, and which earlier control could have prevented the event. A rehearsal reveals missing contact information, unclear authority, and untested assumptions while the consequences are still low.

The first hour after suspected payment fraud requires rapid and organized action. The business should call the financial institution using an official number from a card, a bookmarked website, or another independently verified source, ask whether the transfer can be stopped or recalled, and request that the receiving account be flagged. It should then contain the issue by changing affected passwords, signing out linked sessions where possible, and pausing additional payments. Relevant emails, messages, receipts, and transaction records should be retained. The FBI (n.d.) likewise advises victims of BEC to contact their financial institution immediately and request contact with the receiving institution. Reporting requirements vary by jurisdiction and institution; the business should maintain current contact details and follow the directions of its bank and relevant authorities.

A concise payment-security policy consolidates the new controls. At minimum, it should define the payment threshold for two-person approval, require a verified call-back for bank-detail changes, prohibit the sharing of passwords and OTPs, require MFA on high-risk accounts, permit any employee to pause a suspicious payment, identify the escalation contact, and establish a reconciliation and review schedule. NIST (2024) recommends that small businesses identify incident-response responsibility and authority before an event and practice whether the response plan is feasible.

Governance, Measurement, and Continuous Improvement

A 30-day sprint is a beginning, not an endpoint. Leadership should maintain a short record of completion and assign a responsible owner for each recurring action. Useful measures include the percentage of high-risk accounts protected by MFA; the percentage of identified systems with a current access owner; the number of supplier contacts independently verified; the percentage of bank-detail changes supported by documented call-backs; the date of the most recent backup restoration test; the number of staff huddles conducted; and the date of the last fraud drill. These measures are not a substitute for risk judgment, but they make progress visible and give leaders an early indication that a control has lapsed.

The governance function also requires a respectful reporting culture. Employees should not be punished for raising concerns about an unusual message, a changed account number, or a request that appears to come from a senior person. NIST (2024) recommends that leadership communicate support for a risk-aware and continually improving culture. In small organizations, a visible commitment to verification is often more effective than a lengthy policy that staff cannot recall under pressure.

Conclusion

Small-business cybersecurity is often described as a technology problem, but payment fraud shows that it is also a workflow and decision problem. A stolen password, a spoofed invoice, a new WhatsApp number, or a request for an OTP becomes financially damaging when routine checks fail. The 30-day security sprint offers a modest but actionable response: protect high-risk accounts, verify payment changes through independent channels, strengthen everyday device and data practices, and rehearse the response before a crisis. By turning pause, verify, and report into an operating habit, businesses can make common social-engineering tactics less effective and improve their ability to contain loss when an incident occurs.During this Cyber Awareness Month, take all steps to ensure that you’re not overly exposed to internet scams and cyber fraud.

References

Cybersecurity and Infrastructure Security Agency. (n.d.). Require multifactor authentication. https://www.cisa.gov/audiences/small-and-medium-businesses/secure-your-business/require-multifactor-authentication

Federal Bureau of Investigation. (n.d.). Business email compromise. https://www.fbi.gov/how-we-can-help-you/common-frauds-and-scams/business-email-compromise

Federal Bureau of Investigation, Internet Crime Complaint Center. (2026). 2025 IC3 annual report. https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf

National Institute of Standards and Technology. (2024, February). NIST Cybersecurity Framework 2.0: Small business quick-start guide (NIST Special Publication 1300). https://doi.org/10.6028/NIST.SP.1300

Nigeria Inter-Bank Settlement System Plc. (2026, January 22). Digital payment fraud drops 51% to N25.85b, Lagos accounts for 63%. https://nibss-plc.com.ng/digital-payment-fraud-drops-51-to-n25-85b-lagos-accounts-for-63/

African Heritage Magazine    

Share.
Leave A Reply