Close Menu
  • Home
  • Managing resilience
    • AI resilience
    • Business continuity
    • Business resilience
    • Climate resilience
    • C-suite and the board
    • DORA – the EU Digital Operational Resilience Act
    • Operational resilience
    • Organizational resilience
    • Supply chain resilience
    • Technology
  • Risk
    • Enterprise risk management
    • Operational risk
    • Threatscape
  • Cyber resilience
    • Cyber resilience updates
    • DORA – the EU Digital Operational Resilience Act
    • Product updates
More items
  • All News
  • Research
  • Jobs in Resilience
  • Resilience Resources
  • About Resilience Forward
X (Twitter) LinkedIn
  • Home
  • Managing resilience
    • AI resilience
    • Business continuity
    • Business resilience
    • Climate resilience
    • C-suite and the board
    • DORA – the EU Digital Operational Resilience Act
    • Operational resilience
    • Organizational resilience
    • Supply chain resilience
    • Technology
  • Risk
    • Enterprise risk management
    • Operational risk
    • Threatscape
  • Cyber resilience
    • Cyber resilience updates
    • DORA – the EU Digital Operational Resilience Act
    • Product updates
Login
LinkedIn Bluesky
Resilience Forward
Subscribe Now
  • All News
  • Research
  • Jobs in Resilience
  • Resilience Resources
  • About Resilience Forward
Resilience Forward
You are at:Home»Risk»Threatscape»A hidden dependency: when trust becomes a vulnerability (Page 4)
Threatscape

A hidden dependency: when trust becomes a vulnerability

Mick Leach highlights a missing dependency in most resilience frameworks - the trust embedded in everyday business communication. Resilience frameworks must evolve to accommodate and close this gap and in this article he looks at where to start.
June 2, 20265 Mins Read
Mature businessman smiling talking on smartphone drinking coffee.

Resilience includes mapping dependencies, stress-testing supply chains, documenting critical processes, and scrutinising third-party relationships. Yet one dependency underpins almost every operational process that an organization runs and it almost never appears on a resilience map: the trust embedded in everyday business communications.

From casual emails between colleagues to supplier invoices, our workdays are defined by trusted connections. They are the operational fabric of every organization, and they are also increasingly the point at which resilience starts to break down.

When that trust is compromised by cybercriminals, it can come with a high cost. The FBI Internet Crime Complaint Center estimates the average cost of a business email compromise (BEC) incident is $123,000. But the consequences can extend far beyond that, damaging critical relationships and undermining the foundations the business is built on.

Understanding why such attacks succeed requires looking at how they are constructed. Threat groups have become increasingly effective at conducting their own malicious form of analysis before they strike.

Abnormal AI’s ‘2026 Attack Landscape Report‘, drawing on 159 million email attacks from the second half of 2025, found that accuracy rather than volume is now a defining factor.

Over one-third (39%) of all the BEC emails analysed for the report impersonated trusted internal contacts; including executives, business departments, and other colleagues. External contacts, such as vendors or partners, accounted for another 61%; with attackers deftly hijacking normal processes like payments and procurement.

These attackers research their targets, identify which vendor relationships carry implicit trust, study internal communication norms, and map the approval hierarchies that govern financial decisions. The attack is then engineered to fit seamlessly into that operational context.

Mirroring the legitimate business world, AI-powered tools have made this formerly resource-heavy task highly automated and accessible for even smaller threat groups.

It has become especially challenging when managing third-party risk. Abnormal AI’s research shows a growing trend of exploiting the early stages of the procurement process. Initial procurement enquiries are unlikely to raise any flags, setting up the imposters to steal payment further down the line. This trend is especially prevalent in EMEA, accounting for 41% of the vendor attacks in the region.

The limits of current resilience frameworks

Operational resilience frameworks accounting for third-party risk have matured considerably in recent years. Under DORA, financial entities must map their important business services and demonstrate continuity under stress.

However, most frameworks tend to focus on mapping technology dependencies and process vulnerabilities, but not on the communication layer, the trust assumptions, and the relationship patterns that run through every dependency they document.

This gap has always existed, but it has become increasingly critical as attackers have become faster and more adept at exploiting it. AI-powered impersonation now enables attackers to replicate not just a sender’s identity but their communication style and contextual detail. The informal human security layer of looking out for bad spelling or unusual tone is nowhere near enough anymore.

This is reflected by internal security strategies. Zero trust network architecture, which applies the principle of ‘assume nothing, verify everything’ to user movement and access requests, aims to restore trust on a systemic level.

But zero trust stops at the system boundary. It does not extend to the relational layer, those vendor relationships built over the years, and the internal approval that follows a familiar pattern.

Identity has become the new security perimeter – but managing identity at the infrastructure level is not the same as managing trust at the human level.

Building resilience into the human layer

Closing this gap is less a technical overhaul than an extension of existing resilience practice – applying dependency mapping, continuous monitoring, and adaptive response to the communication layer.

Getting to grips with this first requires organizations to establish behavioural baselines of what normal looks like. This needs to cover all internal employee relationships and extend outwards to vendors, partners, and any other third parties.

From here, it is possible to conduct reliable contextual examinations, assessing whether a request is consistent with the established pattern of that relationship, rather than just whether the sender appears legitimate. For example, you might have a vendor abruptly request changes to payment routing outside their usual cycle, with the email arriving at an odd time outside working hours. Anomalies like this need extra scrutiny, no matter how the email’s identity and contents read.

Finally, this needs to happen consistently at both speed and scale, and AI-native detection is the best way to achieve this. No team can manually assess the contextual signals embedded in thousands of messages every day. AI systems that analyse patterns, flag anomalies, and model intent across an organization’s full communication environment are essential for such a pervasive and fast-moving threat.

Protecting the dependency that holds everything else together

Resilience includes protecting what the business depends on. For most organizations, that still does not include the communication layer: the trusted connections that underpin every supplier relationship, approval process, and financial decision made each day.

Successful attacks begin with a message that nobody questioned. It is a weakness that belongs on the map alongside all the other dependencies that organizations have worked to protect. Resilience frameworks must evolve to accommodate and close this gap before attackers make the cost of inaction impossible to ignore.

The author

Mick Leach is Field CISO, Abnormal AI

Africa Asia Asia Pacific Australasia Europe Middle East North America UK
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email WhatsApp
Previous ArticleUK businesses strengthen cyber resilience but people and governance gaps remain
Next Article New benchmark report shows what separates reactive security programmes from resilient ones

Related Posts

An exploding digital padlock illustrates the requirement for post-quantum cryptography.

Research breakthrough brings reliable quantum computers and Q-day closer to reality

September 10, 2026
A danger sign on a digital background.

New blob URL phishing technique evades detection by using legitimate Microsoft services

September 10, 2026
AI risks

Unmanaged AI workflows expose EMEA organizations to rising compliance and data risks

September 9, 2026
City skyline at sunset with bright light trails and a translucent blue smart-city grid overlay and GPS pins indicating locations.

AI world models: future possibilities for organizational resilience?

September 7, 2026
DRJ and BCI logos

DRJ and BCI publish guidance for governing, managing, and using AI in resilience

September 7, 2026
Decision making with over whelming information.

AI can find the vulnerability. Accountability still sits with your crisis leadership

September 7, 2026
Advertisement
Resilience First
This week's most read articles
Under pressure: An egg cracking under pressure applied by squeezing clamps form the sides.

Managing scenario testing for operational resilience

May 16, 2024
COSO logo

New COSO ERM guidance aims to help organizations with practical implementation

May 12, 2026
Close-up of a green-brown iris peering through a jagged tear in dark paper or wall material.

The blind spots in business continuity

September 2, 2026
Latest resources
A woman with blonde hair and a ponytail looking at colourful sticky notes on a wall.

The stories behind the organization: how cultural narratives shape resilience

August 7, 2026
Load More

Subscribe to Updates

Get our Resilience Updates newsletter.

Most Popular Feature Articles
Three dark coloured light bulbs on a black background illustrate the concept of The Dark Triad in Crisis Management.

The Dark Triad in crisis management

Five stage crisis management framework

A five stage framework for a crisis management process

Blue interconnected gears and network nodes symbolizing automation and complex machinery.

Agent zero – the 2028 digital pandemic

Latest Reports
A futuristic red warning alert icon with glowing exclamation mark.

Cloud Security Alliance publishes Hugging Face Incident Initial Post-Mortem

A person hold a building door open for a person behind who is tailgating to get unauthorised access.

Security Culture: A Strategic Capability That Builds Resilience in a Volatile World

An identity icon with a map marker on it, indicating the concept of identity as a target for attackers. The icon is on a generic IT background predominantly in black and orange.

Identity-based approaches dominate initial access for ransomware attacks

A promo box for an article about resilience governance.
© 2026 Resilience Forward
  • About Resilience Forward
  • Newsletter
  • Newsfeed
  • Advertise
  • Call for Papers
  • Contact
  • Privacy Policy and Cookie Use
  • AI Use Policy

Type above and press Enter to search. Press Esc to cancel.

Manage Cookie Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behaviour or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
Manage Cookie Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behaviour or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
Ad Blocker Enabled!
Ad Blocker Enabled!
Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.

Sign In or Register

Welcome Back!

Login to your account below.

Lost password?