This October, Australia's national cyber campaign runs as Cyber Security Action Month, and for the first time the Australian Signals Directorate (ASD) is running a year-long Cyber Action Year alongside it. In ASD's words, "awareness alone is not enough. It is time to turn awareness into year-round collective action." Finance teams have particular reason to take that message seriously. Organisations are being told to assume breach, yet many payment processes still assume trust: that the supplier record is accurate, the email is genuine and the person on the phone is who they say they are. That assumption is often where a cyber incident becomes a financial loss.
ASD is asking organisations to adopt an "assumed breach" mindset, planning on the basis that a compromise will happen rather than hoping it won't. For finance, the cost of getting that wrong is rising. In ASD's most recent Annual Cyber Threat Report, large businesses saw a 219% rise in self-reported cybercrime losses, to an average of A$202,700 per report.
Awareness is losing ground to AI-enabled attacks
Research from Eftsure shows why awareness needs to be matched with action. In the 2026 AU payment security survey of 1,015 Australians, more than half had experienced a financial fraud attempt in the past 12 months, and 90% believe AI-generated scams are harder to detect than traditional ones. People can know a threat exists and still miss it when it arrives.
AI can now do parts of the attacker's work. Cloning a voice takes around three seconds of audio, which can be enough to impersonate a CFO on a call to accounts payable. In June, an OpenAI agent researching public health spending accessed non-public files on a Medicare statistics portal after it was blocked; the agent wasn't acting maliciously, but it treated security controls as obstacles to work around. The same techniques can be turned on finance, from synthetic supplier identities built to pass onboarding checks to AI agents with access to payment workflows. When attackers can generate a convincing voice, invoice or email in seconds, relying on staff to catch every fake puts too much weight on instinct.
Building on the national checklist
The key actions promoted for Cyber Security Action Month cover software updates, backups, multi-factor authentication, passphrases and scam reporting. They're the foundation for protecting devices and accounts, and a starting point finance teams can build on. The next layer covers a risk that sits beyond any one organisation's systems: a request to change a supplier's bank details that arrives from that supplier's genuine but compromised inbox. Your own multi-factor authentication can't stop a breach in someone else's system. The email can pass your filters because it comes from a real address, and it can reference a real invoice because the attacker has read the thread.
Fraud tends to succeed in the handover between IT controls that secure systems and finance processes that move money. Each side can do its job well and the payment can still reach the wrong account, often because no one clearly owns the space in between. Eftsure's research found 73% of employees lack awareness of the tools available to help prevent payment scams, which leaves most staff relying on instinct at exactly that handover point.
Stop assuming trust at the point of payment
Applied to payments, an assumed breach mindset means no payment is trusted by default. Every channel a request arrives through is treated as potentially compromised, from the inbox and the supplier portal to the phone line and the supplier record in your own ERP. Each payment is then verified before money moves, against a source an attacker can't control from inside those channels.
In practice, bank details get confirmed against an independent, authoritative source rather than the contact details supplied in the request. Any change to a supplier's bank account triggers verification before the next payment runs. Approvals stop depending on a familiar voice or a senior name, which matters because only 25% of respondents said they would feel comfortable questioning a suspicious payment request from a senior executive.
Take a second to verify before money moves
This year's campaign asks Australians to take a second before acting online. For finance teams, that second belongs at the point of payment, and these controls can be put in place this month:
- Map every route through which supplier bank details can be changed, and close any route that bypasses verification.
- Verify every new supplier and every bank detail change through a source that is independent of the request.
- Remove phone calls, video calls and emails as the sole basis for approving urgent or out-of-cycle payments.
- Add finance to your cyber incident response plan, with a named owner for contacting the bank if funds go to the wrong account.
- Train AP teams on the verification steps they are expected to follow, using worked examples from your own payment process.
- Check how your cyber insurance policy treats payment fraud losses, including social engineering and payments your own staff authorised, before you need to claim.
Speed matters once a fraudulent payment gets through. According to the NSW Police Cybercrime Squad, the first hop for stolen funds is typically an Australian bank account, and incidents reported within 24 to 48 hours have a good chance of recovery. After 48 hours, the money has usually moved offshore.
"We're becoming very adept at applying the financial kill chain and stopping the cash," Detective Superintendent Matt Craft, Commander of the NSW Police Cybercrime Squad said. His advice is to call the bank first, then report through ReportCyber.
ASD has given organisations a year to turn awareness into action. For finance leaders, that starts with taking ownership of payment trust, so no payment is trusted until it has been verified.