A story we hear too often
The Thursday an agency’s bank pitch almost left with the invoices
the founder of a 35-person marketing agency
Priya built the agency from a spare bedroom in Wicker Park into 35 people and a client list she still knows by heart. Thursday is pitch day. The team has spent three weeks on a rebrand for a regional bank, and the deck, the pricing and the research sit in a shared drive next to every other client’s.
At 4:10 a client calls to ask why she received an invoice from the agency with a new bank account, and why it came from a domain one letter off. Priya pulls up the mailbox. A rule has been forwarding every message with ‘invoice’ or ‘contract’ in the subject to an outside address for three weeks. The bank pitch went too.
In the version that goes badly, two clients pay the wrong account, the bank’s confidential research is in a competitor’s hands, the security clause in the master services agreement becomes a breach-of-contract letter, and a departing account director takes the client list on the way out because nobody turned off her access.
In Priya’s version, the forwarding rule tripped an alert the day it was created. The engineer removed it, reset the account and found the look-alike domain the same afternoon. The invoice never reached a client. The pitch goes ahead Thursday. Priya wins it.
A rule has been forwarding every message with ‘invoice’ or ‘contract’ in the subject to an outside address for three weeks.
What changes the ending
- Mailbox MFA and alerts on forwarding rules, the quiet tool of every invoice fraud (CIS Controls 5 and 9, Account Management and Email Protections)
- Client files scoped by engagement, with access ending the day someone leaves (CIS Controls 6 and 3, Access Control and Data Protection)
- A named person watching the logs with authority to reset an account at 4:10 on a Thursday (CIS Control 13, Network Monitoring and Defense)