No Result
View All Result
SUBSCRIBE | NO FEES, NO PAYWALLS
MANAGE MY SUBSCRIPTION
NEWSLETTER
Corporate Compliance Insights
  • About
    • About CCI
    • Writing for CCI
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • Artificial Intelligence (AI)
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Downloads
    • Download Whitepapers & Reports
    • Download eBooks
  • Research
  • Books
    • CCI Press
    • New: Bribery Beyond Borders: The Story of the Foreign Corrupt Practices Act by Severin Wirz
    • CCI Press & Compliance Bookshelf
    • The Seven Elements Book Club
  • Podcasts
  • Webinars
  • Videos
  • Subscribe
Jump to a Section
  • At the Office
    • Ethics
    • HR Compliance
    • Leadership & Career
    • Well-Being at Work
  • Compliance & Risk
    • Compliance
    • FCPA
    • Fraud
    • Risk
  • Finserv & Audit
    • Financial Services
    • Internal Audit
  • Governance
    • ESG
    • Getting Governance Right
  • Infosec
    • Cybersecurity
    • Data Privacy
  • Opinion
    • Adam Balfour
    • Jim DeLoach
    • Mary Shirley
    • Yan Tougas
No Result
View All Result
Corporate Compliance Insights
Home Cybersecurity

Whaling: When Business Leaders Become Cyber Weapons

Scammers, often using AI, are targeting your company’s big fish

by Aileen Allkins
May 24, 2023
in Cybersecurity
moby dick illustration

The threat of cyber crime is nothing new for the average business. But new tools like AI mean fraudsters have access to even more sophisticated tools, enabling them to hyper-focus their attempts on high-value targets, including top executives and C-suite members. Aileen Allkins of elev8 Digital Skilling shares tips for making sure staff at all levels have the tools they need to spot a fraud attempt.

Cyber attacks against financial services organizations have surged since the start of 2022, rising by 81%, according to a recent analysis. If cyber crime wasn’t previously high on the agenda for senior executives, it certainly is now, and business leaders across all sectors must be aware of the threats they face and how to mitigate them.

One such threat that has emerged in recent times is whaling, a specific form of phishing that targets organizations’ most influential employees. By selecting victims at the very top of the org chart, hackers are able to reap dividends well into the millions with just one email.

Characterized by ultra-realistic mimicry and real-life details, whaling emails target high-level executives with convincing requests for the transfer of funds or sensitive data. Notably, whaling and other scam emails are increasingly making use of AI to fabricate a highly convincing tone of voice, and spam email addresses are often just one character away from that of the colleague they are mimicking. 

While whaling attempts may be highly convincing, their effectiveness depends on being able to exploit weak spots in the victim’s digital literacy. According to Verizon, 82% of all cyber breaches involve human error, and hackers frequently rely on this to manipulate their target into making a mistake.

Although the actions of employees are central to so many attacks, research has shown that organizations themselves may be falling behind in providing adequate training into modern attack scenarios. The UK’s Department for Science, Innovation & Technology recently reported that only 18% of businesses had provided cybersecurity training to all staff in the past year. While businesses are generally aware of the need for high-level cybersecurity measures, including appropriate education, too often, these needs are beyond the capabilities of a taxed IT department.

tech fluency_n
Cybersecurity

Not Your Grandpa’s C-Suite: Improving Tech Fluency at the Top of the Organization

by Jim DeLoach
January 18, 2023

In our hyper-connected world, just about every company is a tech company. As commerce and technology become increasingly intertwined, it’s even more important for senior executives and board members to ensure they have basic technological understanding, and Protiviti’s Jim DeLoach has the important questions for them to answer.

Read moreDetails

Cybersecurity at every level

Every employee that works with technology is a possible target for a cyber attack, making cybersecurity a vital skill for almost all roles in a business. Rather than a standalone function limited to a tech department, cybersecurity should be viewed as a foundational pillar of an organization-wide digital ecosystem that every member of the workforce should be equipped to play their role in protecting.

Regular training to bring staff up to date with cybersecurity protocol, current threats relevant to their role and best practices not only feeds into an organization’s cyber skillset but helps maintain a culture of cybersecurity awareness. Employees who are upskilled in simple yet powerful cyber defense practices will cease to be an easy access point for hackers.

Privacy

The effectiveness of a whaling attempt is often dictated by the fraudster’s ability to mimic a particular employee, crafting a message using language in line with that of the supposed sender, weaving in details that the target will recognize as genuine.

Cyber criminals fuel these communications by collecting information from publicly accessible sources, such as social media platforms, discarded documents and sometimes from previously hacked materials. Through training, staff can be guided to develop an instinct of what seemingly innocuous information may pose a risk if incorrectly handled or shared. Regular education on the use of privacy settings, encryption, antivirus software and firewalls can provide a powerful guard against hackers.

Protocol

While bolstering employees’ awareness of threats and removing attackers’ sources to manipulable material may diminish the likelihood of a successful cyber attack, protocols such as two-step verification must also be in place, and they must become regular practice.  

The authority of the targeted individual is a central tool in whalers’ strategy, and so safeguards like two-step approval for the transfers of funds or data should be required for even the most senior executives. Whether a secondary request is automated or performed manually, employers should ensure that staff are fully aware of what proper and truly cyber-secure verification processes look like.

Essential capabilities

A workforce that is trained to identify information that can pose a risk, made aware of the particular threats their position may be subject to and equipped with an understanding of how they can properly protect their data is an essential element of a robust cybersecurity strategy.

Cybersecurity is necessary and achievable, but it requires committed investment into training and ongoing efforts from every individual in a business. Businesses with a cybersecurity strategy limited to software and IT professionals overlook the most powerful agent in a digital workplace — the people who work within it — to their peril.  

Tags: Cyber RiskTraining
Previous Post

Regulatory and Economic Times Are Changing. Have You Re-evaluated Your Compliance Management System?

Next Post

Tracing Key Legal Developments in the UK’s AML Regime

Aileen Allkins

Aileen Allkins

Aileen Allkins is chief revenue officer of elev8 Digital Skilling.

Related Posts

gap concept resized

The Compliance Confidence Gap

by Kristina Ryan
August 25, 2026

Compliance leaders are confident employees are equipped to handle compliance situations when they arise. But confidence and evidence are not...

abstract obscured data colorful

Most Audit Leaders Are Using AI; Few Have a Strategy for It

by Staff and Wire Reports
August 20, 2026

Plus: 1 in 10 UK wealth managers don’t ask for a key piece of information; ransomware payments fall while attacks...

news roundup data grungy

As Costs Rise & ROI Remains Elusive, Majority of Execs Say AI Agents Are Worth the Risks

by Staff and Wire Reports
July 23, 2026

30% of UK managers get specially trained on sexual harassment; Gartner IDs 5 big changes for legal functions

restaurant meal check

Does Your Organization Have a Compliant Gift Policy Under Federal, State & Local Law?

by Pei Pei Cheng de Castro and Jennifer Hopkins
July 20, 2026

Meals, travel, charitable donations made on an official’s behalf are among categories many gift policies overlook

Next Post
parliament

Tracing Key Legal Developments in the UK’s AML Regime

GGR sq
No Result
View All Result

Privacy Policy | AI Policy

Founded in 2010, CCI is the web’s premier global independent news source for compliance, ethics, risk and information security. 

Got a news tip? Get in touch. Want a weekly round-up in your inbox? Sign up for free. No subscription fees, no paywalls. 

Follow Us

Browse Topics:

  • CCI Press
  • Compliance
  • Compliance Podcasts
  • Cybersecurity
  • Data Privacy
  • eBooks Published by CCI
  • Ethics
  • FCPA
  • Featured
  • Financial Services
  • Fraud
  • Governance
  • GRC Vendor News
  • HR Compliance
  • Internal Audit
  • Leadership and Career
  • On Demand Webinars
  • Opinion
  • Research
  • Resource Library
  • Risk
  • Uncategorized
  • Videos
  • Webinars
  • Well-Being
  • Whitepapers

© 2026 Corporate Compliance Insights

No Result
View All Result
  • About
    • About CCI
    • Writing for CCI
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • Artificial Intelligence (AI)
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Downloads
    • Download Whitepapers & Reports
    • Download eBooks
  • Research
  • Books
    • CCI Press
    • New: Bribery Beyond Borders: The Story of the Foreign Corrupt Practices Act by Severin Wirz
    • CCI Press & Compliance Bookshelf
    • The Seven Elements Book Club
  • Podcasts
  • Webinars
  • Videos
  • Subscribe

© 2026 Corporate Compliance Insights