atlasbrief

Chapter 13 - The Board Meeting

Carter Sentinel’s board met without me for the first hour.

That irritated me.

It was correct.

Independent investigation presented findings.

Unauthorized vendor payments:

$144,700 completed.

$49,800 attempted.

Recovered/frozen:

$31,600 from latest transfer and remaining account.

Insurance expected to cover part after deductible, subject to controls review.

Employee discipline:

Two accounts payable employees received corrective action, not firing, because the fraud exploited weak controls but no evidence of collusion.

Former supervisor Karen Lowe was cleared of intentional involvement. Her credentials had been reused through an old token that should have been disabled after departure.

That was our failure.

Not hers.

Maya recommended:

Mandatory out of band confirmation for executive vendor approvals.

Lower transaction review thresholds.

Vendor revalidation.

Stronger domain spoof detection.

I approved.

Board chair George said:

“You built a cybersecurity company and got hit by email fraud.”

“Yes.”

“Embarrassing.”

“Yes.”

“Good.”

“What?”

“If you were defensive, I’d worry.”

Then legal findings.

Natalie had no legal access to my shares.

Richard’s POA never effective.

No board action taken.

No customer data accessed.

No source code compromised.

The failed shareholder portal login revealed no records beyond public facing authentication screen.

Good.

The business survived.

The Chicago contract customer was informed under our transparency obligations.

They did not cancel.

They did demand enhanced controls and third party audit.

Fair.

My company would not collapse to make the story dramatic.

It would become better because we admitted weakness.

Then the board discussed me.

Conflict.

Family boundaries.

George said:

“Andrew, you need a formal policy. No relatives as vendors without committee approval.”

“Agreed.”

“No family consulting.”

“Agreed.”

“And your father never enters our office again without visitor badge.”

I almost laughed.

“Agreed.”

After meeting, Maya stopped me.

“You okay?”

“No.”

“Good.”

“Everyone says that.”

“Because people who say ‘I’m fine’ after this are dangerous.”

I smiled.

She continued.

“There’s one thing not in board report yet.”

“What?”

“Natalie contacted someone inside company before the first invoice.”

“Who?”

“Your executive assistant at the time. Melissa Grant.”

I remembered.

Melissa left eight months earlier for another job.

“What did she do?”

“She gave Natalie a copy of your travel calendar and old approval template.”

My stomach tightened.

“Collusion?”

“Melissa says she thought she was helping with surprise anniversary planning.”

Of course.

Natalie was an event planner.

“What else?”

“She forwarded a blank PDF of your standard executive approval memo.”

That became template for forgery.

Melissa had no intent to defraud.

Careless.

Not criminal necessarily.

Again:

Natalie turned ordinary trust into access.

Maya said:

“She’s very good at making requests sound normal.”

“Yes.”

“How long?”

“Her whole life.”

That was the real security lesson.

May you like

The most dangerous social engineering does not feel like hacking.

It feels like family.

Related Stories

Other posts