'Corporate governance failures often enable social engineering frauds.' Discuss in the context of recent cyber frauds targeting Indian companies.
In this answer
Social engineering fraud succeeds not by breaking encryption but by exploiting trust and hierarchy inside firms. SEBI's July 2026 caution to listed companies against the 'Boss Scam' — CEO/MD impersonation to trigger fund transfers [1] — shows that weak internal controls, not weak technology alone, is the enabling condition.
How governance gaps enable such frauds
- Absent verification protocols: staff act on instructions received over email, WhatsApp or Microsoft Teams without call-back confirmation to the concerned official, the very safeguard SEBI advises [1].
- Hierarchical deference: a junior finance officer rarely questions an apparent MD's "urgent, confidential" instruction — a culture failure, not a software failure.
- Weak internal financial controls: the Companies Act, 2013 requires boards and auditors to report on adequacy of internal financial controls [4]; single-authorisation payment channels defeat this in practice.
- Poor cyber-hygiene ownership: malware hijacking active WhatsApp Web session tokens works only where device and app usage is ungoverned; SEBI's CSCRF makes cyber governance a board-and-CISO responsibility for regulated entities [2].
But governance failure is only part of the story
- Technology escalation: deepfake voice cloning and AI-generated video calls make impersonation credible even to alert staff [1].
- Ecosystem gaps: proceeds move rapidly through mule accounts; I4C's Suspect Registry and MuleHunter.ai partnership address a laundering layer no single company controls [3].
- Detection asymmetry: firms face fraud attempts continuously while attackers need one success — hence I4C's trend-alert to SEBI [1][3].
Thus governance failure is the necessary enabler, while AI-enabled deception is the force multiplier. The way forward lies in mandatory dual-authorisation and out-of-band verification for high-value transfers, board-level cyber-risk reporting under CSCRF [2], periodic social-engineering drills for finance teams, and faster company-to-1930/I4C reporting to freeze mule accounts [3]. Embedding these into internal financial controls converts cyber security from an IT function into a genuine fiduciary duty of the board.
Sources
- 1SEBI Press Release, "Caution to Regulated entities and listed companies – Boss scam" (17 July 2026)CEO/MD impersonation modus operandi, channels used, deepfake variant, verification advice, I4C alert
- 2SEBI Circular, Cybersecurity and Cyber Resilience Framework (CSCRF) for SEBI Regulated Entities (Aug 2024)board/CISO-level cyber governance obligations
- 3PIB, "I4C and RBIH Sign MoU to Strengthen AI-Driven Detection of Mule Accounts and Cyber Financial Frauds"mule accounts, Suspect Registry, MuleHunter.ai, 1930 helpline
- 4Section 134, Companies Act, 2013 (India Code)board reporting on adequacy of internal financial controls