
The UK is taking cyber resilience more seriously than ever. The government’s Cyber Resilience Pledge and forthcoming Cyber Security and Resilience Bill reflect a growing recognition that cyber risk is no longer just an IT issue. Organisations are being encouraged to strengthen their ability to withstand, respond to and recover from cyber threats.
Yet many organisations are still preparing for the wrong attack. When leaders think about cyber resilience, the conversation usually centres on ransomware, malware, network intrusions and system outages. The assumption is that cyber criminals are trying to break into systems. Increasingly, they are not.
According to UK Finance, authorised push payment (APP) fraud rose 19% to £576.4 million in 2025. Rather than hacking their way into organisations, criminals are increasingly persuading employees to willingly send money to the wrong account. At the same time, AI-powered voice cloning, deepfakes and impersonation attacks are making fraudulent requests harder to spot. The uncomfortable reality is that many organisations are investing heavily in protecting systems while leaving the processes that move money dangerously exposed.
Cyber resilience is no longer just about preventing unauthorised access to technology. It is about preventing criminals from exploiting trust. As business leaders review their resilience strategies, there are four questions worth asking.
1. Are We Trusting Information That Has Never Been Independently Verified?
One of the most common fraud tactics remains deceptively simple. A criminal impersonates a supplier, requests updated payment details and waits for the next invoice to be paid into an account they control. The attack works because many organisations still rely on signals that were once considered trustworthy. An email arrives from a familiar contact. A phone call appears to come from a known supplier. The request sounds reasonable.
The problem is that trust has become increasingly easy to manufacture. Email addresses can be spoofed. Phone numbers can be cloned. AI can replicate voices and writing styles with alarming accuracy. Yet many organisations continue to make payment decisions based on information that has never been independently verified.
There is no such thing as a perfectly accurate supplier database. Records become outdated, account details change and mistakes happen. Fraudsters exploit these weaknesses, but they are not the only risk. Poor-quality data can create operational and financial vulnerabilities long before a criminal becomes involved. The first question leaders should ask is simple: how much of our payment process relies on trust, and how much relies on verification?
Also Read: Two-Thirds of Business Leaders Believe Their Company Has Already Suffered an AI Data Breach
2. What Happens When AI Makes Trust Impossible?
For years, organisations have focused on awareness training. Employees have been taught to spot suspicious emails, challenge unusual requests and look for warning signs. Those measures remain important, but they are becoming less reliable.
AI is rapidly eroding many of the signals people have traditionally used to identify fraud. A convincing email no longer proves legitimacy. A familiar voice no longer guarantees authenticity. Even video evidence can no longer be accepted at face value. Many organisations still depend on employees recognising that something feels wrong. But resilience becomes fragile when it relies on human intuition rather than robust controls.
The question leaders should ask is not whether employees can identify every fraudulent request. It is whether critical processes remain secure even when a fraudulent request appears completely legitimate. Because in an era of AI-powered deception, trust alone is no longer a control.
3. Are Finance Teams Included in Cyber Resilience Planning?
Many cyber resilience programmes are led by IT, security and risk teams, with finance consulted later. Historically, that made sense. Cyber incidents were viewed primarily as technology problems.
Today’s threat landscape looks different. Many cyber-enabled attacks are designed to manipulate financial processes rather than compromise systems. Their objective is not necessarily to steal data. It is to steal money. If attackers are increasingly targeting payment workflows rather than networks, finance teams are no longer peripheral to cyber resilience. They are on the front line.
Finance teams manage supplier data, approve transactions and oversee payments. They control many of the processes criminals are actively trying to exploit. If they are absent from resilience planning, organisations risk overlooking one of their most important lines of defence.
4. Would We Spot a Problem Before the Money Disappears?
No organisation has perfect controls. The question is not whether mistakes, anomalies or fraud attempts will occur. The question is how quickly they will be identified.
Many organisations only discover problems after a supplier raises concerns, an audit uncovers discrepancies or a reconciliation exercise reveals that money has gone to the wrong place. The organisations that respond most effectively are often those that detect issues early.
Leaders should ask how quickly they could identify an unauthorised payment, an unexpected account change or a deviation from normal payment patterns. In cyber resilience, speed matters. The same is true for payment fraud.
Also Read: 5 Reasons You Need a Container Firewall
Resilience Must Extend Beyond IT
The Cyber Resilience Pledge and Cyber Security and Resilience Bill are encouraging organisations to think more broadly about preparedness. That is a welcome development. But resilience cannot stop at the firewall.
The organisations best positioned to withstand future threats will be those that recognise cyber resilience as a company-wide responsibility spanning finance, procurement, compliance, risk and security. The next major cyber incident facing your organisation may not involve malware, ransomware or a compromised network.
It may begin with a supplier record nobody questioned, a payment instruction nobody verified and a request that looked completely legitimate.