TL;DR: CEO fraud has driven more than $26 billion in losses over the last few years, including $1.8 billion in 2020, and KnowBe4’s manual focuses on how criminals exploit executive trust, weak risk assessment, and restitution gaps. The real lesson is that identity verification, payment approval, and escalation controls must be treated as a single fraud surface, not separate processes.
NHIMG editorial — based on content published by KnowBe4: CEO Fraud Prevention Manual
By the numbers:
- CEO fraud has been responsible for more than $26 billion in losses over the last few years.
- $1.8 billion in losses were recorded in 2020 alone.
- When AWS credentials are exposed publicly, attackers attempt access within an average of 17 minutes.
Questions worth separating out
Q: What breaks when CEO fraud controls are not in place?
A: Without strong verification at the point of action, executives' names or voices can be used to bypass normal approval paths.
Q: Why does CEO fraud remain effective even in mature organisations?
A: Because mature organisations often protect systems better than decisions.
Q: How do security teams know if CEO fraud controls are actually working?
A: Look for evidence that unusual requests trigger independent verification, that high-risk approvals are logged end to end, and that staff can reject suspicious instructions without penalty.
Practitioner guidance
- Introduce step-up verification for high-risk requests Require a second, independent verification step for payment changes, beneficiary updates, bank detail changes, and urgent exceptions.
- Separate executive identity from action authority Do not let a message from a senior leader directly authorise a transfer or account change.
- Harden delegate and assistant workflows Treat executive assistants, finance processors, and procurement staff as high-value fraud targets.
What's in the full article
KnowBe4's full guide covers the operational detail this post intentionally leaves for the source:
- The fraud lifecycle and the criminal strategies used to pressure employees into bypassing normal checks
- A prevention checklist for executive impersonation, payment approval, and restitution workflows
- Response and restitution options for organisations that have already suffered CEO fraud
- Practical prevention guidance for executives, finance teams, and support staff dealing with fraudulent requests
👉 Read KnowBe4's CEO fraud prevention manual →
CEO fraud prevention manual: what should executives and IAM teams do?
Explore further
CEO fraud is an identity governance failure, not just a finance problem. The attack succeeds when organisations trust message content more than verified identity, especially in time-sensitive payment and approval workflows. That makes the control question one of assurance, not awareness. Identity verification and delegated approval governance must be designed together, because the fraud path runs through both.
A question worth separating out:
Q: Who is accountable when executive impersonation leads to a fraudulent transfer?
A: Accountability usually spans finance, operations, and security because the failure crosses identity verification, workflow design, and transaction approval. The organisation should define who owns the control, who approves exceptions, and who preserves evidence for recovery and investigation.
👉 Read our full editorial: CEO fraud prevention: the governance gaps executives still miss