This lesson examines the unique cyber threats facing treasury, from payment fraud to data breaches, and the essential controls needed to protect the organisation.

2.1 A Prime Target: The Cyber Threat Landscape
Treasury functions are prime targets for cybercriminals because they control corporate cash and sensitive bank account information. The CTP exam explicitly requires professionals to “Monitor information security risk and cyber-related risk (including e-mail scams, phishing scams)” . The ACT syllabus also highlights the importance of compliance and control to protect the organisation’s reputation . Common threats include:

  • Business Email Compromise (BEC): Fraudsters impersonate executives or suppliers to trick treasury staff into making fraudulent payments.

  • Phishing Attacks: Attempts to steal login credentials through deceptive emails or websites.

  • Ransomware: Malware that encrypts systems and demands payment for decryption.

2.2 Essential Controls and Mitigation Strategies
A multi-layered security approach is required. Key controls include:

  • Payment Verification and Authorization: Implementing a strict “four-eyes” principle where payments require dual authorization. Some companies use call-back procedures to verbally verify payment instructions .

  • Segregation of Duties: A fundamental control ensuring that no single individual can initiate, approve, and settle a payment. This is a core tenet of treasury internal controls .

  • Multi-Factor Authentication (MFA): Requiring multiple forms of verification for system access, particularly for initiating payments.

  • Employee Training: Regular training to help staff identify and report phishing and other suspicious activities.

2.3 Detecting and Responding to Fraud
Treasury professionals are expected to “Detect and mitigate fraud (such as payments, bank transactions, internal, external)” . This involves not only prevention but also having strong monitoring and detection systems in place, such as:

  • Bank Reconciliation: Daily reconciliation of bank balances to quickly identify unauthorized transactions .

  • Anomaly Detection: Using systems to flag unusual payment patterns, amounts, or beneficiaries.

  • Incident Response Plan: Having a clear plan to act quickly and limit damages if a cyberattack or fraud does occur.