Skip to main content

Isle of Man Threat Commentary: The Importance of Cyber Threat Awareness and Training

May - June 2026

 

 

Staff Are Your First and Last Line of Defence

A single unexpected email, invoice, phone call, or message can be enough to put an organisation at risk. Many cyber incidents do not begin with a technical failure, but with a routine business action being manipulated by a criminal. This could be a member of staff approving a payment, responding to a supplier, clicking a link, entering login details, or assuming that a request is genuine because it appears to come from a trusted contact.

For businesses, staff awareness is therefore essential. Employees are often the first to encounter suspicious activity, but they may also be the final opportunity to stop an incident before money, data, or access is lost. This does not mean staff should be expected to identify every threat on their own. Instead, they should be supported with regular training, clear reporting routes, strong verification procedures, and a workplace culture where concerns can be raised quickly and without blame.

Cyber security awareness is most effective when it reflects how people actually work. Staff should understand the types of threats they are likely to face in their role, what warning signs to look for, and what steps to take if something doesn’t feel right. When combined with appropriate technical controls and business processes, well-informed staff can play a vital role in preventing cyber incidents from escalating.

 

Recent Local Incidents

The CSC received several local reports between May and June that demonstrate why staff awareness, verification and escalation processes are so important.

One report involved a local organisation receiving two fraudulent supplier invoices over consecutive weeks. Internal concerns were raised at the input stage on both occasions, but key verification steps, such as callback checks and supplier validation, were not completed. One fraudulent invoice for over £10,000 was paid, while a second invoice was stopped before payment. The report highlighted failures in financial controls, verification, and escalation protocols.

Another report involved the compromise of a business email account. Attackers used the genuine account to continue an existing conversation with a client and instruct them to send payment to a different bank account. Email rules had also been created to hide the attacker’s activity from the account holder. The client sent over £22,000 to the fraudulent account.

These incidents demonstrate how convincing modern scams can be and highlight the need for staff training to be supported by clear processes. If anything seems unusual, staff should know how to pause, verify, and escalate before any action is taken.

 

Why Staff Awareness Matters

Staff are often closest to the processes criminals want to exploit. They handle invoices, speak with customers, process payments, manage accounts, respond to emails, and use business systems every day. This makes them a frequent target, but also a critical part of an organisation’s defence.

Awareness training should help staff understand:

  • What common scams look like
  • How criminals use urgency, pressure and trust
  • Why payment changes must be verified independently
  • How to recognise suspicious links, attachments and login pages
  • What to do if they click something or enter details
  • When and how to report concerns
  • Who to escalate to if something feels unusual

Training should be practical and role-specific. For example, finance staff may need more detailed training on invoice fraud and payment verification, while front-line staff may need to focus on suspicious calls, customer impersonations, phishing emails, and data handling.

A strong reporting culture is just as important as training. Staff should be encouraged to report concerns early, even if they are unsure or think they may have made a mistake. Early reporting may allow your organisation to reset credentials, stop payments, contact banks, warn customers, or contain a compromise before further harm occurs.

 

Red Flags and Impact

Businesses should ensure staff can recognise common warning signs, including:

  • Requests to change bank details or payment instructions
  • Urgent or confidential payment requests
  • Pressure to bypass normal processes
  • Messages discouraging staff from checking with others
  • Slight changes in email addresses, domains, or contact details
  • Unexpected attachments, links, or login prompts
  • Invoices that appear out of sequence or duplicate previous requests
  • Messages from known contacts that seem unusual in timing, tone, or content
  • Requests that rely on secrecy, authority or urgency

The impact of these incidents can extend beyond the initial financial loss. Businesses may face operational disruption, reputational harm, loss of customer confidence, strained supplier relationships, and potential legal or regulatory consequences.

In payment fraud cases, funds can be moved quickly, making recovery difficult. Preventing the incident, or escalating concerns before a payment is made, is usually far more effective than trying to recover money afterwards.

 

Key Considerations

To reduce the risk of staff-targeted cyber attacks, businesses should consider the following actions:

Provide regular, practical staff training: Training should be relevant to the organisation and include realistic examples, such as phishing, invoice fraud, account compromise, smishing, vishing, and supplier impersonation.

Create clear reporting routes: Staff should know exactly who to contact if they receive a suspicious message, click a link, enter credentials, or notice unusual account activity.

Verify payment changes independently: Any request to update bank details or make an urgent payment should be verified using a trusted contact method, such as a known phone number already held on file. Staff should not rely on contact details provided within the suspicious email.

Encourage a no-blame reporting culture: Employees are more likely to report concerns early if they know they will be supported.

Strengthen financial controls: Use dual approval for payments above agreed thresholds. Where possible, separate responsibilities for requesting, approving, and processing payments.

Formalise supplier processes: Maintain trusted supplier records and require formal checks before accepting new or amended bank details.

Secure business email accounts: Enable multi-factor authentication, monitor for suspicious login activity, and review mailbox forwarding or deletion rules that may indicate compromise.

Use technical controls to support staff: Email filtering, anti-spoofing controls, endpoint protection, and account monitoring can reduce the number of threats that reach staff.

Test and refresh procedures: Staff awareness should not be a one-off annual exercise. Businesses should regularly review lessons learned from incidents, update processes, and ensure staff understand current threats.