Skip to content
Eight steps to build a cyber resilient finance function

Eight steps to build a cyber resilient finance function

icaew-sitecore-cd-as.azurewebsites.net July 30, 2026

In the past 18 months, the finance team that Ruth Billen FCA manages has seen around a 50% rise in attempted phishing attacks – and her team is itself part of a cyber security business.

“It’s a regular feature of our monthly all-hands calls that I’m the company’s highest reporter of phishing attempts, because I get them all the time,” says Billen, CFO of Bridewell, one of the UK’s largest independent providers of cyber security solutions.

As the finance department is the team that holds all the money, it is the obvious place for cyber criminals to start to try to extract cash from a business. Billen receives multiple phishing emails per week; these are usually high-activity campaigns, often for low amounts of money. “We’ve seen organisations get targeted for significantly larger sums – again, through their finance teams,” Billen says.

Billen warns that such attacks are becoming ever more sophisticated. Finance staff are frequently spoofed via WhatsApp. Many phishing emails are now designed to resemble entire email chains – a ruse to trick staff into being less sceptical. Attackers are making phishing messages feel more professional by using artificial intelligence to root out classic spelling and grammar errors that once served as handy red flags.

In parallel, finance functions can also let their guard down through sloppy technology management. Paul Rolison ACA, Director of Cyber Strategies Ltd, recalls a company that had a spare terminal in its accounts department that was always on, but no one knew exactly what it did. The supplier that was meant to be in charge of firewall management also hadn’t installed any updates for six years.

“Lo and behold, attackers saw the gaping hole offered by that idling terminal and marched straight through,” says Rolison. “The only thing that saved the department’s systems was quick thinking. A member of staff walked past the terminal, noticed something odd on its screen and yanked out its network cable – just before the attackers were able to extract sensitive data.”

That sort of lucky spot by a passing colleague is unlikely to happen in the majority of businesses that are fully remote, Billen notes – that includes her own business. “As remote companies’ security depends on how employees manage their IT setups, their finance functions are naturally more susceptible to attacks.”

With those points in mind, here are Rolison and Billen’s tips on how to hardwire cyber resilience into your finance function.

As part of ICAEW's campaign on backing business-led growth , we have outlined three key recommendations for government on cyber security:

Extracted Entities

Attack Types (1)

MITRE ATT&CK (1)

Platforms (1)