The top 5 attack paths in our market
1. Invoice/IBAN diversion (BEC): A supplier's "changed bank account" email from a lookalike domain. One mid-size textile exporter paid Rs 8.5M to a "new IBAN" — gone within 48h. Defense: voice-verify any banking-detail change on a KNOWN number + dual approval above a threshold.
2. Ransomware via pirated software: Your accountant's cracked Windows/Office is the entry point. Studios and clinics lose years of archives. Defense: remove pirated software; free alternatives (LibreOffice, GIMP) exist; 3-2-1 backups with ONE OFFLINE copy.
3. WhatsApp CEO fraud: The boss's "new number" urgently needs gift cards/transfers. Defense: company rule — no payment instruction accepted from WhatsApp alone, ever.
4. Employee credential theft: Phished email passwords expose your whole mailbox history (including invoices and customer data). Defense: MFA on all email + a password manager + quarterly phishing drills (use our AI roleplay!).
5. Payment-page skimming for e-com: Fake "track your order" pages and COD cash theft by riders. Defense: verified courier partners only; reconcile COD daily.
**Start with the free PISA Cyber Health Check (Toolkits → Organizations) — 15 minutes, scored against NIST CSF, with your top 3 fixes.
