CYB-29 · Cyber security
Business Email Compromise is the number-one financial fraud vector against SA insurance brokers. Attackers compromise email, then impersonate the broker to redirect premium payments or claims settlements. The most effective preventive control is a verbal verification protocol: any change to banking details must be confirmed via a known phone number — never via email alone.
Trigger
No verbal verification protocol for changed banking details; no dual-authorisation requirement for outgoing payments above a defined threshold; staff unaware of BEC risk pattern
Applicability gate
This is a readiness rule mapped to JS2 themes. Its presence in the library does not establish that JS2 applies directly to the firm.
Citation
This control maps to the public instruments below. The mapping does not establish entity applicability.
Remediation
Implement a written policy: all changes to banking details must be verified via a known, pre-existing phone number. No banking detail changes actioned via email alone. Dual authorisation required for all outgoing payments >R10,000. Include BEC scenario in annual tabletop exercise.
Evidence required