# What Happens If the CFO's Computer Is Compromised? The First 60 Minutes of a Holding Company Cyberattack

**URL:** https://securesys.com.tr/en/blog/cfo-laptop-compromised-first-60-minutes-of-an-attack

Does targeting a holding company's finance operations require hacking hundreds of servers?

Not always.

Sometimes all an attacker needs is access to the right person's account.

Compromising the account of a CFO, finance director, accounting manager or any employee authorised in payment processes can let an attacker see the organisation's internal financial relationships, suppliers, payment habits and executive communications.

Let us now look at the first 60 minutes of a cyberattack a holding company could experience, through an entirely illustrative scenario.

### 09:02 — It All Starts with an Ordinary Email

The finance director begins the day by checking the inbox.

A short message that appears to come from a supplier they have worked with before catches their attention:

"The July reconciliation file has been updated. You can access the current document via the link below."

The language of the message is correct.

The company name is right.

The subject line is familiar.

The attacker may even have referenced a genuinely ongoing project, thanks to information obtained earlier.

The finance director clicks the link.

A page closely resembling the Microsoft 365 sign-in screen appears.

And the first stage of the attack is complete.

### 09:08 — The Target Is No Longer Just the Password

In modern attacks a username and password are not always enough.

Because many organisations now use MFA.

For that reason, in some scenarios attackers target users' active sessions or session tokens.

If successful, a far more valuable door can open for the attacker:

the user's existing corporate session.

From this point on, the aim of the attack begins to expand from the finance director's computer towards the company's digital identity infrastructure.

### 09:17 — The Microsoft 365 Door Opens

If the attacker gains access to the corporate account, Outlook is not all they find.

Depending on privileges and the organisation's configuration,

Outlook, Teams, OneDrive, SharePoint and other corporate resources can all become a potential source of information for the attacker.

But something interesting happens.

The attacker deletes no files.

Shuts down no systems.

Leaves no ransom note.

Sends no threatening message to anyone.

Because the aim is not yet to stop the company.

The aim is to understand the company.

### 09:24 — Quiet Reconnaissance Begins

The attacker may start searching the finance director's mailbox for particular words:

Payment.

Invoice.

IBAN.

Transfer.

Bank.

Contract.

Approval.

The correspondence containing these words can give the attacker important clues about how the organisation works financially.

Who issues payment instructions?

Who performs the second approval?

Which executives communicate with each other regularly?

Which companies receive payments continuously?

What payment sizes are considered normal?

The attacker is no longer analysing the technical infrastructure but the company's behavioural model.

### 09:31 — SharePoint and Corporate Documents

Company documents may be next.

Depending on the user's access rights, platforms such as SharePoint may hold

budget files, management reports, contracts, supplier lists, project documents or information about group companies.

For a holding company the risk here is even greater.

Because a single account sometimes carries information about more than one company.

The correspondence the same user conducts with different group companies, subsidiaries and suppliers can give the attacker the opportunity to map a significant part of the organisation.

### 09:42 — The Attacker Now Knows the Finance Process

By the end of the first 40 minutes the attacker may hold an important advantage:

context.

This is extremely valuable in financial fraud.

Because a poorly prepared phishing message is relatively easy to spot.

But if the attacker knows

the real project,

the real executive,

the real supplier,

the real payment timing

and the style of correspondence inside the organisation, a far more convincing attack can emerge.

The message the attacker will prepare no longer needs to look "suspicious".

On the contrary, it needs to look as normal as possible.

### 09:51 — The Only Thing That Changes Is the IBAN

The attacker selects a genuine payment process already under way.

The project is real.

The supplier is real.

The invoice may be real.

The payment amount is ordinary for the company.

The tone of the correspondence matches corporate communication.

But one critical detail is changed:

the bank account.

The message sent to accounting is quite simple:

"There has been an update to our payment account. Could you make today's transfer to the account below?"

This is where the financial dimension of the attack begins.

### 09:57 — The Difficult Decision in Front of Accounting

The message arriving on the accounting employee's screen may look nothing like classic phishing examples.

The sender may be familiar.

The project may be correct.

The amount is plausible.

The correspondence has a history.

The request appears to be a natural part of the company's daily operations.

So in modern cyberattacks it may not be enough to ask only:

"Is this email genuine?"

The real question is:

"Is the person requesting this transaction really who we think they are?"

### 10:02 — A Full 60 Minutes Have Passed

An hour ago the company was operating normally.

The firewall was active.

EDR was running.

Antivirus was up to date.

MFA was in use.

SIEM was collecting logs.

Thousands of events were flowing across the SOC screens.

Yet despite all of this, one critical question may still be unanswered:

### Does the company know it has been attacked?

One of the most important problems in cybersecurity today emerges precisely here.

Owning a security product and being able to detect an attack in time are not the same thing.

### Now Let Us Rewind to 09:02

This attack chain could in fact have been broken at many points.

Advanced email security could have blocked the first message.

Identity security and correctly configured MFA controls could have reduced the risk of account takeover.

Conditional Access policies could have restricted unusual access.

EDR/XDR solutions could have made suspicious behaviour visible.

SIEM and SOC correlation could have detected unusual sessions and activity.

PAM solutions could have limited uncontrolled use of critical privileges.

And dual verification plus independent payment confirmation in the finance department could have prevented the money being transferred even if the attacker had bypassed the technical controls.

For finance and holding structures, cybersecurity is therefore no longer a technology problem consisting of a firewall, antivirus or a handful of security products.

Identity + user + device + data + privilege + financial process + continuous monitoring must be assessed together.

### The Real Question for Holding Companies

Attackers do not always need to bring systems down.

Sometimes the most successful attack is the one nobody notices.

Systems keep running.

Employees do their jobs.

Emails arrive.

The ERP works.

Banking systems are open.

Yet the attacker is inside, learning how the organisation works.

It is therefore not enough for boards and senior executives to ask their security teams only:

"Do we have security products?"

There may be a far more important question:

"If an attack like this one, beginning at 09:02, happened in our holding company, at what time would our security team notice?"

Because in cybersecurity the critical difference is sometimes not whether the attack happens;

it is the time between the attacker and the defence team.

#### SecureSys Knowledge Centre

At SecureSys we assess not only whether organisations own security products, but how quickly they can notice and stop an attack. Through identity security, email security, EDR/XDR, SIEM/SOAR, 24/7 SOC monitoring, social engineering tests and penetration testing, we help organisations break the attack chain early.

Because in cybersecurity what usually matters is not whether the attack happens, but how long it takes to be noticed.
