Most organisations know that scams are a threat.

Employees receive warnings about suspicious links. Posters advise them to check the sender. Training modules explain phishing, impersonation and social engineering. Occasionally, a simulated fraudulent email is sent to see who clicks.

These activities can improve awareness. But awareness is not the same as resilience.

A person may know exactly how scams work and still make the wrong decision when an urgent request appears to come from a senior leader, an important client or a distressed colleague. They may notice something unusual but remain silent because they are afraid of appearing difficult. They may report a suspicious message, only to discover that nobody knows who should respond.

An organisation becomes resilient when it can prevent avoidable harm, recognise an attack early, respond without confusion and recover without concealing what happened.

That requires more than alert employees. It requires a system designed for the reality that people can be pressured, authority can be imitated and trusted communication channels can be compromised.

Awareness Is a Starting Point, Not a Control

Scam prevention is often presented as an individual test: the organisation provides information, and the employee is expected to identify the deception.

This approach places too much responsibility on one person at one moment.

Contemporary scams may use information taken from professional profiles, company websites, social media, previous data breaches and genuine correspondence. A fraudulent request can arrive within an existing email conversation. A caller can know the names of colleagues and suppliers. A synthetic voice or manipulated video can make an impersonation more convincing.

Even a well-trained person can be vulnerable when the message is credible, the timing is unfortunate and the apparent consequences of delay are serious.

The question should not be, “Why did the employee fail to spot it?”

It should be, “Why was one employee able to authorise a consequential action without independent verification?”

That change of question moves the organisation from blame to design. It recognises that education matters, but strong procedures should still protect the business when someone is tired, distracted, intimidated or deceived.

Treat Scam Risk as an Organisational Risk

Fraud is sometimes left to the information technology or finance team. Yet a scam can enter through almost any relationship an organisation maintains.

Recruitment teams may receive false applications or requests to change payment details. Finance teams may be sent fraudulent invoices. Senior leaders may be impersonated. Customer-service staff may be persuaded to disclose information. Suppliers may have their email accounts compromised. Employees may be approached through personal messaging platforms and social media.

The consequences extend beyond an immediate financial loss. An incident can expose personal data, interrupt services, damage relationships, create legal responsibilities and weaken trust among employees, clients and communities.

Scam risk therefore belongs within wider governance. Leaders should know who owns it, which teams are involved, how incidents are escalated and what decisions need senior oversight.

This does not mean turning every employee into a fraud investigator. It means giving people clear responsibilities and ensuring that the parts of the organisation work together before an incident occurs.

Map the Decisions That Matter

An organisation cannot prepare for every story a scammer might invent. It can identify the decisions that would cause serious harm if manipulated.

These may include:

transferring money or issuing refunds;

changing bank or payroll details;

disclosing personal, commercial or confidential information;

granting access to accounts, systems or buildings;

changing supplier or customer records;

purchasing gift cards, cryptocurrency or other transferable assets;

responding to an apparent legal, regulatory or executive instruction;

publishing information or communicating on behalf of the organisation.

Each decision should have an appropriate verification process. The level of control should reflect the potential consequence, not simply the apparent confidence of the person making the request.

This is more useful than trying to list every possible scam. Criminal stories will change. The organisation’s high-risk actions are more stable.

Build Verification Into the Work

Good verification should not depend on an employee improvising while under pressure.

For significant payments, account changes or disclosures, the organisation can require confirmation through a separate trusted channel. If an instruction arrives by email, it might be checked using a known telephone number from an internal directory. If a supplier changes its bank details, a member of staff can contact an established representative using information already held on file.

Other useful controls include dual approval, transaction limits, waiting periods for unusual changes and additional review when a request departs from normal practice.

The precise process will differ by organisation. A small cultural organisation should not be expected to reproduce the systems of a multinational bank. But every organisation can ask:

Which actions should never depend on a single message?

Which details must be independently confirmed?

Who can approve an exception?

What happens when the apparent requester is a senior leader?

The final question is critical. Scammers use authority because they expect status to override procedure. A control that disappears when the chief executive appears to be asking is not a dependable control.

Leaders must make verification normal by accepting it themselves.

Remove the Penalty for Pausing

Procedures can exist on paper and still fail in practice.

An employee may know that a request should be checked but fear being criticised for delaying it. A junior colleague may feel unable to question a director. A contractor may worry that raising a concern will make them appear unreliable. Someone who has already clicked a link may remain silent because they expect blame.

These are cultural conditions, not technical faults, but they directly affect security.

People need explicit permission to pause an unusual request. They should know that careful checking will be supported even when the request turns out to be genuine. Reporting a mistake quickly should be treated as an act of protection, not a confession of incompetence.

The first minutes after an incident may determine how much harm occurs. If shame delays reporting, an attacker has more time to access accounts, contact other employees or move money.

A resilient organisation makes the safe action socially possible.

That begins with leadership language. “Why did you fall for it?” closes down information. “Tell us exactly what happened so we can contain it” opens the route to action.

Make Reporting Simple and Visible

Employees should not have to search through a policy document to learn how to report a suspected scam.

The reporting route should be easy to find, available to people working remotely and usable from outside a potentially compromised system. Staff should understand which situations require an urgent response and what information to preserve.

A useful reporting process answers five questions:

1. Who should be contacted?

2. How should they be contacted?

3. What information is needed?

4. What should the employee avoid doing next?

5. What response can they expect?

The organisation must also ensure that somebody receives and acts on the report. A dedicated inbox without clear ownership can create the appearance of a system without the protection of one.

Suppliers, freelancers and other partners may need a reporting route too. They often have legitimate access to information and systems but may not be included in internal communication. That gap can be exploited.

Prepare for the Incident Before It Happens

Prevention reduces risk; it does not eliminate it.

An organisation should know what it will do if money is transferred, credentials are disclosed, an account is compromised or a senior person is impersonated. Responsibilities should be agreed in advance rather than debated during the crisis.

An incident plan may need to cover:

securing affected accounts and devices;

contacting the bank or payment provider;

preserving messages, call details and transaction records;

assessing whether personal or confidential information was exposed;

meeting any legal, regulatory or contractual reporting duties;

warning employees, customers or partners who may also be targeted;

communicating accurately without speculation;

supporting the people directly involved;

reviewing how the attack progressed and improving the system.

Contact details should be current, and essential instructions should be accessible if normal systems are unavailable. A plan that exists only inside a compromised account may be impossible to use when it is needed.

The organisation should also decide who has authority to act. Delayed containment can be costly when everyone is waiting for a person who cannot be reached.

Train for Decisions, Not Definitions

Employees do not need endless lists of fraud terminology. They need practice making realistic decisions.

Training is more useful when it reflects the situations people actually encounter. A finance team may need to practise responding to changed supplier details. A receptionist may need to handle a caller requesting internal information. A community organisation may need to consider impersonation through messaging groups. A senior leader may need to understand how their urgency and communication habits can be imitated.

Exercises should include ambiguity. Real scams do not always announce themselves through obvious errors. A convincing scenario may contain genuine names, familiar language and an apparently reasonable explanation.

The purpose should not be to catch people out. It should be to reveal where the process becomes unclear.

After an exercise, the organisation can ask:

Did people recognise that verification was required?

Did they know how to perform it?

Could they challenge the apparent authority behind the request?

Was the reporting route fast and clear?

Did the response team act effectively?

These questions produce more useful learning than publishing a list of employees who clicked.

Recognise Culture, Language and Access

Security communication is not effective merely because it has been sent.

An organisation may include people with different first languages, levels of digital confidence, working arrangements and experiences of authority. Some employees may use assistive technology. Some contractors may have limited access to internal systems. Volunteers and temporary staff may be exposed to risk without receiving the same preparation as permanent employees.

Scammers can exploit these differences. They may use culturally familiar language, imitate community relationships or take advantage of uncertainty about how an organisation normally communicates.

Resilience requires accessible guidance, relevant examples and more than one way to report a concern. It also requires care in how groups are described. Culture should not be presented as a weakness, and limited technical confidence should not be confused with limited judgement.

The aim is to make protective systems usable by the full range of people who participate in the organisation.

Extend Resilience Beyond the Organisational Boundary

Many scams move through relationships between organisations.

A supplier’s compromised account can be used to send a genuine-looking invoice. A fraudulent message can imitate a funding body, delivery company, professional adviser or client. Criminals may study public announcements to identify new partnerships, senior appointments or major projects.

Organisations should agree with important partners how high-risk changes will be verified. Contact records should be maintained independently of incoming messages. Unexpected payment instructions should be treated carefully even when they appear within a legitimate conversation.

Customer-facing organisations should also consider how their own identity might be misused. Clear public guidance can explain how the organisation normally requests payment or information, where suspicious contact can be reported and which channels are genuine.

Trust is shared infrastructure. One organisation’s weak process can expose several others.

Measure What Strengthens Resilience

The easiest security figures to collect are not always the most meaningful.

An organisation may celebrate a reduction in clicks during simulated phishing exercises while employees remain unsure how to verify a payment request. It may record the number of people who completed training without knowing whether reporting has become faster.

More useful indicators may include:

the time between suspicion and reporting;

the time required to contain an incident;

the proportion of high-risk changes independently verified;

employee confidence in challenging unusual requests;

whether suppliers and contractors understand the reporting process;

recurring weaknesses identified through incidents and exercises;

whether agreed improvements are actually implemented.

The purpose of measurement is not to prove that the organisation is safe. It is to show where protection is working and where attention is still required.

Resilience Is a Leadership Practice

Scam resilience is built through repeated organisational behaviour.

It is present when a finance employee can challenge an urgent payment without fear. It is present when a leader follows the same verification rules as everyone else. It is present when a mistake is reported immediately, the response is calm and the organisation learns without humiliating the person involved.

Technology will continue to change the appearance and scale of deception. Criminals will adapt their scripts, channels and methods. An organisation cannot predict every approach.

It can build durable habits: consequential decisions are checked, unusual requests can be questioned, incidents are reported quickly and learning results in practical change.

Awareness asks people to recognise danger.

Resilience ensures they are not facing it alone.

About This Collection

Scam, Trust and the Business of Deception examines the psychological, technological, cultural and commercial systems behind contemporary fraud.

The series accompanies the Cultural Intelligence Studio video collection Manipulated Trust and podcast collection Inside the Scam: Trust, Manipulation and the New Economy of Fraud.