A finance director I spoke to a few weeks ago told me she'd started double checking every payment instruction twice, even ones from people she'd worked with for years.
Not because anything had gone wrong. Because she'd read something that made her uneasy, and it turns out she was right to be.
New research from the cyber security firm Zscaler, published through its ThreatLabz threat intelligence team, looked at a single ransomware campaign that hit 351 victims across 334 organisations over the course of a month.
And the pattern it found wasn't the one most employers would expect. Nearly two thirds of the people targeted held manager-level titles or above. The average victim was 46. Three quarters of them worked in accounting and finance, sales, operations, HR or marketing, not IT, and not the boardroom either.
Ransomware attempts were up 146% year on year in the same data. Public extortion cases were up 70%, and stolen data volume climbed 92% alongside it. But the number that matters most for anyone hiring at finance leadership level is the target profile itself, not the growth stats around it.
Zscaler's researchers, as reported by The Register's report on the research, described attackers mapping out reporting lines using information pulled from compromised systems combined with whatever's sitting in public view. From there they go straight after the people who approve payments, hold budget authority, and can pull sensitive records. No need to get anywhere near a chief executive's inbox.
That last part is the bit that should change how you think about your next finance hire.
For years, the working assumption in most businesses has been that cyber risk sits with IT. You hire a finance director for commercial judgement, technical accuracy, maybe a bit of gravitas in the boardroom when the numbers get tricky. Security gets filed under a different department, dealt with by someone else, somewhere else in the building entirely.
But this research suggests that assumption is well out of date. Has been for a while, probably. We just hadn't seen the numbers laid out this plainly before, at least not attached to a campaign this size.
Why are finance managers the ones getting targeted?
Because they hold the keys. A financial controller or finance director can move money, approve invoices, and pull records that a junior admin simply can't reach.
Attackers who've already got a foothold in a network don't need to bother with the CEO's inbox when a finance manager's login gets them just as far, often with a lot less scrutiny attached. It's a shortcut. A fairly logical one too, once you see it laid out like that.
I've placed a fair few finance directors and financial controllers over the years. I can count on one hand the number of interview processes that touched on any of this. Most conversations are still about month-end close, board reporting and team management, and fair enough, those things matter enormously and always will.
But a candidate's instinct for spotting something that doesn't quite add up, an oddly worded payment request, an unfamiliar sender pushing hard for urgency, is turning into a genuine hiring criterion. Not a nice-to-have tacked on at the end of a job spec anymore.
What should this actually change about how you hire a financial controller?
Ask how a candidate has handled a suspicious payment request in the past. Not whether they've sat through a training module about it once, ticked a box, moved on.
Ask what their old finance team's authorisation process actually looked like too, and whether they ever pushed back on it when someone senior was leaning hard on them to skip a step. The good candidates usually have a story, and it's rarely a comfortable one to tell in an interview. Which is exactly why it's worth asking in the first place.
If nothing else, it tells you far more about how someone handles pressure than a question about their Excel skills ever will.
None of this means every financial controller needs to double as a security analyst. That's not realistic, and it isn't really the point.
What it does mean is that judgement under pressure deserves a proper place in how you assess someone for this level of role, alongside the technical checks you'd already run. The willingness to slow down and question a request that feels wrong, even when someone senior is chasing it hard, is worth testing for directly rather than assuming it's already there.
Knowing what to look for in a financial controller has quietly changed shape over the past year or two, whether most hiring managers have clocked it yet or not. It's the same instinct, funnily enough, that makes a good finance leader good at spotting a dodgy invoice or an overstated forecast in the first place. Turns out it's also the thing standing between a business and a very expensive Tuesday.
A lot of the employers we work with are still hiring finance leadership roughly the way they did five years ago. Which made sense five years ago.
But the world that role sits inside has moved on, and the way businesses recruit for it needs to move with it. Otherwise they'll keep filtering good candidates on criteria that quietly stopped being the whole picture some time back.
It isn't only about screening out risk either. Finance leaders who ask sharp questions about process tend to be the same ones who spot the growth opportunity buried in a messy set of numbers. That instinct travels well.
If you're building out a finance function or replacing someone senior, our guide to choosing the right finance recruitment agency covers what a thorough hiring process should include beyond the CV screen.
And if this has made you want to benchmark what strong finance leadership looks like against your own team, our finance recruitment page is a reasonable place to start poking around. No pressure attached either way.
Worth a read too if you're curious what the fuss in The Register's original report was actually about. It's a decent piece on how these campaigns get built, and it steers well clear of the usual cyber security scaremongering that tends to follow stories like this one.
Either way. Next time someone tells you cyber risk is purely an IT problem, you've now got a fairly specific reason to disagree with them.



