Join our Newsletter — 33% off our NHI Course
Home› FAQ› Cyber Security› What should employees do when an executive email…
Cyber Security

What should employees do when an executive email asks for money or confidential information?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 26, 2026 Domain: Cyber Security

Employees should pause, verify the request through a separate channel, and never rely on the email alone. If possible, confirm in person or by phone or instant message using a known contact path. If the message is suspicious, report it immediately and do not send payment details, passwords, personal data, or gift cards without direct confirmation.

What should employees do when an executive email asks for money or confidential information?

An executive-style request for money or sensitive data should be treated as a verification problem, not a compliance problem. The safest response is to stop, use a second communication path you already trust, and confirm the request before acting. That discipline matters because email display names, signatures, and tone are easy to imitate, even when the message looks routine.

Why executive-request scams succeed

These messages usually work by borrowing authority and urgency. The sender may ask for gift cards, wire transfers, payroll changes, invoice updates, login details, or internal documents, then pressure the employee to act quickly and quietly. The attack is effective when the recipient assumes the request is legitimate because it appears to come from a senior leader.

A separate-channel check breaks that assumption. The key control is not sophistication, it is independence: verify through a known phone number, a trusted messaging channel, or an in-person confirmation path that was established before the request arrived. If the request is real, the executive can confirm it quickly. If it is fraudulent, the verification step usually exposes the inconsistency.

What to verify before you send anything

Employees should verify the requestor, the payment destination, the business purpose, and the sensitivity of the information requested. A changed bank account, an unusual payment method, a request to bypass normal approvals, or a demand for credentials or personal data should all raise the bar for confirmation. If the request cannot survive a normal approval path, treat that as a warning sign.

Confirmation should be based on a contact path the employee already knows is valid, not on details provided in the suspicious email. If the message contains links, attachments, or forwarding instructions, resist the urge to use those embedded paths to verify it. The safest test is whether the request still makes sense after it is detached from the original message.

How to respond when the message looks suspicious

Do not send money, passwords, personal data, gift cards, or confidential files until the request is independently confirmed. Preserve the message, report it through your organisation's reporting route, and follow local incident handling instructions if the request attempted to redirect funds or capture information. Fast reporting helps security and finance teams warn others and limit follow-on abuse.

Employees should also avoid informal exceptions such as "this is probably okay because it came from the CEO" or "I will deal with approvals later." Fraud often depends on bypassing the normal process just once. The correct response is to slow the transaction down until the request has passed the same verification standard you would use for any high-risk change.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

CIS Controls v8 and NIST SP 800-53 Rev 5 set the technical controls, while ISO/IEC 27001:2022 and SOC 2 (AICPA) define the regulatory obligations.

FrameworkControl / ReferenceRelevance
CIS Controls v8CIS-14 — Security Awareness and Skills TrainingEmployees need phishing and social engineering training for executive impersonation attempts.
CIS-8 — Audit Log ManagementReporting suspicious executive emails depends on preserved evidence and reviewable logs.
Recommendation — Train staff to verify executive requests through a trusted second channel before sending money or data. Retain suspicious-message evidence so security teams can investigate and block repeat attempts.
NIST SP 800-53 Rev 5AT-2 — Awareness TrainingAwareness training supports recognition and response to executive-style social engineering.
IR-4 — Incident HandlingSuspicious requests should be escalated through incident handling when fraud is suspected.
Recommendation — Teach employees to stop and independently confirm unusual executive requests before acting. Route suspected impersonation attempts to incident handling and preserve the original message.
ISO/IEC 27001:2022A.6.3 — Information security awareness, education and trainingStaff awareness is essential for resisting executive impersonation and payment fraud.
A.5.24 — Information security incident management planning and preparationSuspicious executive requests should be handled through prepared reporting and response steps.
Recommendation — Provide awareness training that requires out-of-band verification for urgent executive requests. Prepare staff to report suspected impersonation immediately through the incident process.
SOC 2 (AICPA)CC2.2 — Communication and InformationClear internal communication paths reduce the chance that staff act on fraudulent requests.
Recommendation — Document trusted contact paths so employees can confirm executive requests independently.

Practitioner Guidance

What to prioritise: Train staff to treat money movement and confidential-data requests as two of the highest-risk email scenarios, because both can create immediate loss if they are acted on from inbox alone. The practical standard is simple: no payment, credential, or sensitive-data release without a second-channel confirmation that was not supplied by the message itself.

What to verify: Make sure employees know the approved contact path for each senior leader, finance approver, and delegate, and that those paths are documented before an incident occurs. The most common failure is not lack of caution, it is not knowing which number, chat handle, or in-person escalation path is actually trusted.

Practitioner takeaway: The control is behavioral and procedural, not technical, so the organisation wins when employees slow down enough to verify authority outside the inbox before any value or sensitive information moves.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 26, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org