ESRM Program · Financial Cluster

Fraud Risk Mitigation

Put real checks between a convincing request and your company’s money.

$2,500 fixed-fee assessment 3–4 weeks Credited toward the vCSO program

Measured against the COSO/ACFE Fraud Risk Management Guide and your own incident history. Led by Don Oxman, CPP, CISSP, CISM. Licensed by Texas DPS. In business since 2013.

Most fraud arrives as a normal-looking request.

Fraud risk mitigation is one of thirteen domains in our Enterprise Security Risk Management (ESRM) program, and part of the Financial cluster with Loss Prevention. It covers fraud from outside and inside the company, like an email that seems to come from your CFO, or a longtime bookkeeper at an Arlington contractor paying a vendor that does not exist.

In most small and midsize companies, fraud prevention rests on the controller or office manager, and on trust. The same person often sets up vendors, approves invoices, and releases payments. Bank-detail changes get made from an email. Nobody has written down what to do when a wire goes to the wrong account, so the first hours go to figuring out who to call. We help you put verification steps and controls in place, and a plan for when one fails.

How companies actually lose money to fraud

Email impersonation

A message that looks like it came from the owner or a known vendor asks for an urgent wire. Finance staff want to be helpful, and that is what gets exploited.

Vendor bank changes

A vendor’s new bank details arrive by email or phone and get updated without a call-back, so the next real payment goes to a criminal’s account.

Check fraud

Checks are stolen from the mail, altered, or counterfeited. The longer it takes to reconcile the account, the harder the money is to recover.

Payroll & expenses

Ghost employees, direct-deposit changes requested by impostors, and padded or duplicate expense reports that nobody compares against receipts.

Deepfake requests

Voices and video can now be faked well enough to pass for an executive on a call, so a familiar voice on the phone no longer proves who is asking.

Internal schemes

An employee who controls vendor setup, approvals, and reconciliations can run fake invoices or kickbacks for years before anyone notices.

Five questions for leadership

  • If a vendor emailed new bank details today, what would your AP team do before paying?
  • Can any one person set up a vendor, approve its invoice, and release the payment?
  • Is there a call-back rule for urgent payment requests, even when they come from the owner?
  • Does someone outside accounting review the bank reconciliations each month?
  • If a wire went to the wrong account this afternoon, who would call the bank, and how fast?

If you answered “no” or “not sure” to any of these, that is where we would start. Most of these gaps cost little to fix before an incident and a great deal to fix after one.

How an Engagement Works

Every ESRM domain starts with the same fixed-fee assessment. If you decide to continue, we credit the fee toward the program, and fraud risk becomes part of your vCSO engagement alongside whichever other domains you need.

Step 1 · Start here

Fraud Risk Assessment

Fixed fee · typically 3–4 weeks
$2,500
  • Interviews with the owner or CFO, the controller, accounts payable, payroll, and HR.
  • Structured review: a 15-question risk profile, a 25-point practices checklist, and a maturity score from 1 (Initial) to 5 (Optimized).
  • Payment flow map: how vendors, payroll, wires, and expenses are set up, approved, and paid.
  • Gap analysis against the COSO/ACFE Fraud Risk Management Guide and your own incident history.
  • Written report and prioritized roadmap, walked through with your leadership team. The report is yours whether or not you continue.

The fee is credited in full toward the program if you start within 90 days.

Step 2

The vCSO / ESRM Program

Fraud risk run inside your full ESRM program
$2,500–$7,500 /month
  • Assess (Q1): we start from your assessment findings.
  • Build (Q2): a fraud risk policy, payment verification and call-back procedures, segregation of duties where staffing allows, and a fraud response plan.
  • Training for finance, AP, payroll, and executive assistants on impersonation, bank-change requests, and deepfake calls.
  • Tabletop exercise on a misdirected wire, covering who calls the bank, your insurer, counsel, and law enforcement.
  • Operate (Q3+): we stay on as the named owner, with quarterly control reviews, refresher training, and reporting to leadership or your board.

Month to month. Cancel with 30 days’ notice. About the vCSO program →

Add-on · Any client

Payment Fraud Services

Billed per engagement, quoted in advance.

  • Payment review: how vendor, payroll, and wire changes get approved.
  • Awareness session for finance, AP, and payroll staff on current schemes.
  • Post-incident review of what happened and which controls failed.
  • Coordination with your counsel, CPA, or a licensed investigator.

Why Total 360

Fraud and cyber, one advisor

Most fraud attempts now arrive by email, text, or phone. We review the payment process and the email security behind it together, so nothing falls between finance and IT.

Clear about our role

We design and test the controls. When a case needs forensic accounting or a licensed investigator, we help you bring in the right one and work alongside your counsel.

Experienced leadership

Led by Don Oxman: M.S. in Security Management, CPP, CISSP, CISM. U.S. Army and AT&T background. In business since 2013 and licensed by Texas DPS.

Common questions

What does a fraud risk assessment cost?

$2,500, as a fixed fee. It usually takes three to four weeks from kickoff to the readout. If you start the vCSO program within 90 days, the full fee is credited toward it.

What do we get at the end of the assessment?

A written report with your maturity score from 1 (Initial) to 5 (Optimized), the gaps we found against the COSO/ACFE Fraud Risk Management Guide and your own incident history, and a prioritized roadmap. We walk your leadership team through it, and the report is yours whether or not you continue.

Do we have to sign up for the full program?

No. The assessment stands on its own. If you continue, fraud risk runs inside the vCSO program at $2,500 to $7,500 a month depending on scope. It is month to month, and you can cancel with 30 days’ notice.

Can we buy payment fraud services without the program?

Yes. They are available to any client. Billed per engagement, quoted in advance.

Will you replace the people and providers we already use?

No. We work alongside your IT provider, attorney, insurer, and other advisors. We set the standard, help them meet it, and check that the work gets done.

Also in the Financial cluster Loss Prevention All 13 ESRM domains

Start with a 30-minute Risk Discussion

No deck and no sales pitch. Walk us through how a payment gets approved and released at your company. We’ll give you an honest read on where it could be exploited and send a scoped proposal within five business days.

Schedule a Risk Discussion Or call 817-677-0515 · info@total360security.com