Free Diagnostic — Accounts Payable

Your two-person rule can't stop what it can't see.

A full kill-chain self-check of your AP workflow and supplier payment process, from invoice ingestion to the final payment run. Ten controls, plain English, no technical background needed. Score yourself in under ten minutes.

$227M+

Lost to invoice fraud (AU, 2023)

72 Hrs

Maximum bank recall window

30–40%

Recovery rate with fast action

$10

Cost of AP credentials online

Instant Access — Ten Controls

Score Your AP Workflow

Answer each control honestly: Yes, No or Unsure. Each "No" is a gap attackers already know how to find, and "Unsure" counts as No: not knowing is the finding.

How Invoices Enter Your Business

S1

The front door is open, is anyone watching it? Every fake invoice attack starts here.

Invoice Receipt

Do you require suppliers to submit invoices via a secure portal (e.g. Peppol e-invoicing) rather than as PDF email attachments? PDF invoices can be intercepted and bank details changed in minutes using cheap AI tools; the document looks identical.

Email Spoofing Protection (DMARC)

Is DMARC configured on your email domain and set to "reject" mode? Without enforcement, anyone can send an email that looks like it came from your CEO or CFO: the most common vector for fake payment approvals.

Stolen Credential Monitoring

Do you monitor whether your AP team's login credentials have been stolen and are being sold online? AP credentials sell for as little as $10, letting an attacker study supplier relationships for weeks before striking.

Who Can Log In, and What Can They Do?

S2

Attackers don't break in. They log in. Standard multi-factor authentication can be bypassed.

Device Trust

Is your accounting system access strictly limited to pre-approved, registered company devices? Restricting to known devices blocks an attacker even when they hold valid credentials.

Separation of Duties

Do you strictly enforce separation of duties, ensuring the person changing vendor records cannot also approve payments? One person controlling both gives an attacker complete end-to-end control.

Your Supplier & Vendor Records

S3

Your supplier list may already be a target. A fraudulent bank account on this list is as valuable as direct system access.

Adding New Suppliers

Do you independently verify a new supplier's bank details against a verified database (e.g. Eftsure) before adding them? Calling the number in the email may just connect you to the scammer.

Bank Detail Changes

When a supplier requests a bank account change, are payments to them suspended until independently verified? Attackers time change requests to land just before a large payment run.

Inactive Supplier Review

Do you regularly check whether suppliers in your system still have active ABNs and valid insurance? A deregistered ABN left active is a direct fraud vector.

The Final Step Before Money Leaves

S4

Even if every other control has failed, this is your final opportunity to catch a fraudulent payment.

Pre-Payment Verification

Before each payment run, do you verify supplier bank details against a source independent of your own accounting system? Checking only your own system cannot catch fraud already inside it.

Payment File Integrity

Is your payment batch file cryptographically verified to detect modifications between generation and bank upload? A single-character change in a batch of 200 payments is invisible to human review.

Your Risk Level

0/10 No / Unsure

Answer all ten controls to see your result.

0 of 10 answered

Already Seeing Something?

If working through this raised a real concern, an unexplained payment, a supplier bank change you cannot verify, a login that should not exist, do not wait for certainty. A compromise assessment establishes, discreetly and fast, whether something is underway.

See Cyber Investigations →

Close the gaps your own team can't mark for you.

Fixed fee, agreed scope, led personally by a former enterprise CISO.