digital print abstract
Inbiz Trends
Insights to appreciate changes and trends.

Cybersecurity and Digital Fraud: How to Protect Corporate Payments

Awareness and corporate procedures for addressing increasingly sophisticated threats
20.07.2026

In a context where digital payments, corporate treasury and technology are evolving rapidly, cybersecurity is playing an increasingly central role in protecting businesses. Threats no longer concern only traditional cyberattacks, but also increasingly sophisticated forms of digital fraud, in which the human factor becomes the primary target.

The topic was addressed during the event “Payment & Treasury Horizons: between strategy and innovation, a face-to-face look at the future”, organised on 23 June 2026 by Intesa Sanpaolo’s IMI Corporate & Investment Banking Division at Palazzo Rospigliosi in Rome. The event provided an opportunity for CFOs, Treasurers and Finance Managers from leading corporate and public-sector organisations to discuss how to navigate an increasingly dynamic, digital and complex financial landscape.

In this scenario, security is an essential prerequisite for supporting innovation. This was the focus of the presentation by Matteo Feraboli, Executive Director Cybersecurity, Anti-Fraud e Business Continuity, Intesa Sanpaolo, who explored the evolution of digital fraud and the persuasive techniques behind it, highlighting the decisive role of prevention and awareness in protecting payments.

The video examines the evolution of cybersecurity and fraud management in a landscape made more complex by generative artificial intelligence, which enables attackers to create increasingly credible scenarios, and by geopolitical tensions, which have contributed to a rise in attacks against critical infrastructure, including financial infrastructure. This is why strengthening prevention through greater individual awareness and compliance with corporate procedures is so important: recognising unusual requests, verifying communication channels and pausing before taking action are becoming crucial behaviours for protecting corporate payment transactions.

Matteo Feraboli, Head of Cybersecurity, Antifraud & Business Continuity Management, Intesa Sanpaolo

VIDEO TRANSCRIPTION

The world of cybersecurity and fraud management is undergoing radical change. We are seeing conflicting forces that have been at play for years now. The first one that comes to mind is artificial intelligence, including generative AI, which is completely transforming attackers’ capabilities, whether in the realm of cybersecurity or fraud. Another factor that is causing major disruption—and has led to a significant increase in cyberattacks across all industries—stems from geopolitical tensions that are initially manifesting in the East—think of the Russia-Ukraine war—and subsequently throughout the Middle East as well. This has spurred groups to begin attacking critical infrastructure, including financial systems, around the world.

We’re seeing that the major shift right now is a transition from the world of financial fraud to the world of scams. This is one of the factors having a significant impact in the corporate sector. What’s the difference between these two worlds? Fraud refers to incidents in which a customer’s money is stolen in a financial context without the customer realizing it—often due to malware or something downloaded onto their cell phone. The world of scams is significantly more complicated to manage because it’s a scenario where the customer—persuaded by a scammer—actively transfers funds to the scammer themselves. This is a major cause for concern that we’re seeing affect even large companies through schemes such as, for example, CEO fraud, which is one of the issues we’re increasingly addressing to protect our corporate clients.

What is a CEO fraud? Essentially, it’s a scheme carried out by a scammer who attempts to convince our client to make payments to bank accounts that are clearly not attributable to either one of our client’s customers or to the client themselves, for various purposes—such as acquisitions that are clearly fictitious since this is a scam. Artificial intelligence also plays a role in these schemes because, to make these attacks credible, fraudsters now use techniques such as deep fakes—that is, synthetic identities that can impersonate, for example, a CEO or even a CFO, including via video conferences—making it very difficult to detect these schemes. They are so convincing that when we contact our clients to warn them of the risk, we rarely manage to convince them that a scam is underway, and sometimes these funds end up in places where it becomes very difficult to recover them.

So how can you avoid this type of scam? Simply by adhering to company procedures, strictly following what is required—for example, by treasury procedures—and ensuring that communications received through unusual channels, such as a WhatsApp message from an unknown phone number, are always reevaluated and verified through an alternative channel. For example, let’s remember that these are all tactics that play on the cognitive level—they try to convince you through elements like urgency, psychological pressure, and authority. Typically, these messages—these scams—come from fake CEOs, so it’s really simple to counter them by re-enforcing the standard procedures that every company has in place. Stop, think, pause. If something seems out of the ordinary, okay? I pause, reflect, and then act. And that’s the only way to protect yourself from this kind of scam.


All published or otherwise available material on the website — including trademarks, logos, domain names, images, videos, press releases, articles, and documents in general reproduced herein, as well as application software, codes, and format scripts used for the site's implementation — is the property of Intesa Sanpaolo, companies of the Intesa Sanpaolo Group, or companies with which Intesa Sanpaolo has entered into commercial agreements and is protected under copyright and trademark regulations. All rights are reserved. Therefore, without prior formal consent from the owner, such material may not be copied, downloaded, reproduced, used on other websites, modified, transferred, distributed, or communicated to third parties, except for personal use only, with any commercial use being strictly prohibited.

Related articles
VIEW ALL