HD Field Guide 05

Executive impersonation response

A repeatable response when a senior leader appears to request payment, access, secrecy or urgent disclosure.

Control area
Incident readiness
Audience
Executives, finance & assistants
Reading time
6 min
Reviewed
16 July 2026

Executive impersonation succeeds when authority and urgency bypass normal checks. The strongest defence is a process that senior leaders visibly support and never ask staff to ignore.

Make verification culturally safe

Staff should know they will be supported for pausing an unusual request—even when it appears to come from the CEO or a board member. Leaders should state that verification is expected, not disrespectful.

Create clear thresholds for second approval, supplier bank-detail changes and release of sensitive documents.

Contain related access risk

Review whether the attacker used a compromised mailbox, stolen session or public information. Reset affected credentials, revoke sessions and inspect mailbox rules when compromise is suspected.

Warn relevant staff using a safe internal channel, without spreading malicious attachments or links.

Learn without blaming

Document the request, decision points and control gaps. Improvements may include stronger payment processes, protected directories, awareness exercises or clearer escalation contacts.

Avoid relying only on staff intuition. Good processes make the correct action easy under pressure.

Completion check

Before you close the guide

  • Transaction or access change paused
  • Independent verification completed
  • Finance, IT or security escalation activated
  • Sessions, mailbox rules and evidence reviewed if needed

Trusted references

Continue with primary guidance

Defensive guidance boundary

This guide provides general educational information. Adapt it to your organisation’s policies, contracts, legal obligations and incident process. For an active incident, use trusted professional and official support channels.