LUKA SANDVOSSBLOG
← ALL POSTS

Security awareness

Can your team verify an urgent payment request?

A practical security awareness exercise for suspicious invoices, including a handover note for supplier checks and payment approvals.

Luka Sandvoss · · 4 min read

Auf Deutsch lesen →
A person holding invoice paperwork beside a laptop displaying invoicing software.

A finance assistant spots something odd in a supplier email. The invoice looks familiar, but the bank details have changed. They pause the payment and look for a trusted phone number. Nobody has documented where that number is kept.

This fictional example would make a useful security exercise because the difficulty continues after the suspicious message has been recognised. A team needs a verification route it can actually use.

A convincing message can still need checking

Germany's 2026 Cybersecurity Monitor focuses on online fraud and AI. Its public summary says 40 percent of respondents engage with cybersecurity only when a problem occurs. The underlying survey reached 3,060 people aged 16 or older in Germany in January 2026. These are population survey responses, not employee performance results. ProPK and BSI: CyMon 2026.

The BSI's guidance on deepfakes describes the manipulation of faces and voices. That matters for verification: hearing a familiar-sounding person doesn't settle whether an unusual request is authorised. BSI: Deep Fakes, Threats and Countermeasures.

The GMX and WEB.DE spam report of 11 August 2026 describes invoice fraud tailored to individual recipients. Arne Allisat, who leads email security for the providers, calls for ongoing security work even as their measured spam volume falls. This is a provider's assessment, not a survey of your workforce. It is a reason to include a polished, plausible message in security awareness training.

Follow the request all the way through

Prepare a fictional supplier message and invoice. Tell participants that they are practising, use no real credentials and don't ask anyone to make a payment. Give them the same tools and contact information they would have at work.

Ask them to resolve the changed bank details using an established supplier contact. Watch where they look for the number and whether they know who may pause the transaction. A number supplied in the questionable email doesn't count as an independent route.

For a foundation, the request could appear to come from a grant recipient. In a community organisation, a supposed IT support request might be more familiar. Choose a situation people recognise, then let them work through it at a pace that exposes missing information.

Fix the process the exercise uncovers

If the group cannot find an approved contact, the training has identified a documentation problem. If staff hesitate to delay a payment, management needs to clarify their authority. Repeating the warning about fraud won't resolve either issue.

I would leave the session with an agreed contact route, a named backup and a short description of when to stop. Staff also need somewhere to report a possible mistake promptly. A person who has already clicked should be able to ask for help without first composing an explanation that protects their reputation.

Useful observations include the time taken to locate a trusted contact, whether the request reached the right person and which steps required help. Record unclear responsibilities alongside individual actions.

Before closing the session, give the backup colleague this handover note to complete:

Supplier verification route: where the established contact is recorded, who checks a proposed change, and who covers their absence.

Payment hold: the role authorised to pause the transaction and the person who must confirm release.

Record of the check: where to save the outcome so the next colleague can see it.

Ask the backup to locate the contact without help from the usual account owner. An empty field or a private inbox is a process gap worth fixing now.

Repeat the exercise later with a different pretext. Reusing the checking process would be encouraging, although a small training exercise cannot establish a reduction in fraud losses.

Medienkundig offers a security awareness pilot for organisations, with scenario exercises and feedback on participants' decisions. The training focus and schedule are agreed with the team. The offer page is in German. Bring your escalation and payment-approval process to that conversation; it determines what staff need to practise after recognising a suspicious request.

Research checked on 10 September 2026. Cover: photograph by SumUp / Unsplash. Illustrative photograph, not a Medienkundig project or training session.