Skip to content

The situation, read aloud to everyone

You handle payments for a small organisation. An email has arrived from your director, who is abroad this week. A supplier you pay every month has new bank details, and the invoice is due today. The email reads exactly like the director: same greeting, same habit of signing off with a first initial, and it refers to last month's invoice by its real number.

Fictional educational scenario. No real organisation, person or bank account is described.

Running the three rounds

Round 1 · The first move

10 minutes

  • Read the situation aloud. Do not explain the playbook and do not use the word verification
  • The finance officer states a first move out loud and carries it out with whoever is involved
  • Let it play. Do not correct anything, and do not let the rest of the room comment yet

Round 2 · The deadline has not moved

15 minutes

  • Announce: it is late afternoon, the director is not reachable, the invoice is due today
  • This is the round that teaches. Protect the silence while the finance officer thinks
  • Do NOT hint at the answer. If a group is stuck, ask only: what is the smallest thing you could do that keeps today working?
  • End the round by telling the room the director never sent the email, and that nothing in it was detectable

Round 3 · Write the rule, then break it

15 minutes

  • Each finance officer writes ONE process rule on the rule sheet
  • Swap sheets between groups. Each group now plays attacker and tries to find a way through the rule they received
  • Collect the rules that survived. Those are the ones worth taking to whoever owns the payment process

What settles it, for you only

Do not read this out before the end of round 2. The drill stops working the moment the room is told the answer.

  • Paying the invoice to the details ALREADY ON FILE and leaving the change unprocessed settles it. The deadline is met, the real supplier is paid, and the attacker gets nothing
  • The insight is that this is two requests, not one. Pay the invoice; refuse the change. The change can wait for tomorrow, because nothing bad happens if it does
  • Escalating to a second authorised person is also a real answer, and is often what a written process will require
  • A small test payment is the trap that feels clever. It proves only that the attacker's account accepts money, and you have now sent some
  • Waiting and missing the deadline is safe but needlessly costly. The supplier is real and the invoice is real

Closing the session

  • The message was not detectable, and that was deliberate. Say this plainly to anyone who feels they failed.
  • Two requests, not one: you can pay and still refuse the change.
  • A rule beats vigilance, because vigilance is a person having a good day.
  • Point the group at the on-screen drill so they can see the branch they did not take.

shënim: ky material u krijua në kuadër të projektit 'U.S. Cybersecurity Leadership in AI for Albania', financuar nga departamenti i shtetit i shteteve të bashkuara. mendimet, gjetjet dhe përfundimet e paraqitura këtu janë të autorit(ëve) dhe nuk pasqyrojnë domosdoshmërisht ato të departamentit të shtetit të shteteve të bashkuara.

Disclaimer: This material was created on behalf of the 'U.S. Cybersecurity Leadership in AI for Albania' project, funded by the United States Department of State. The opinions, findings, and conclusions stated herein are those of the author(s) and do not necessarily reflect those of the United States Department of State.

Disclaimer

Found something unclear, outdated or improvable? Suggest an improvement