Course track
Finance & Payments
For finance, accounts payable, and payment teams: business email compromise, wire fraud, payment-portal fraud, vendor impersonation, insider misuse, and building a security-first finance culture.
Who takes this: Finance, accounts payable, treasury, and payment-approval staff
PCIFTCISONISTCBNNDPASOC2
| Module | Length | What staff learn | Maps to |
|---|---|---|---|
| Business Email Compromise & Invoice Fraud Priority | 7 min | Recognize a spoofed vendor-invoice or payroll-change email and apply the verification step before paying. | PCI, FTC, ISO, NIST |
| Wire Fraud & Payment Fraud Awareness Priority | 6 min | Apply dual control and verbal verification before any wire or urgent payment. | PCI, FTC, CBN, ISO |
| Protecting Financial Information Online (Finance Teams) | 4 min | Handle card and account data to PCI standard and recognize fake payment-portal links. | PCI, FTC |
| Nigeria: POS & Bank-Alert Fraud for Finance Teams | 4 min | Verify reversal or refund requests through the bank's official channel only. | CBN |
| US: FTC Safeguards Rule Essentials | 5 min | Explain the finance team's role in the written information security program. | FTC |
| Verifying Payment Changes: The Callback Rule | 3 min | Apply a documented callback procedure for any change to bank details. | PCI, FTC, CBN |
| Vendor Impersonation and Third-Party Payment Scams | 5 min | Spot the warning signs when a vendor or supplier contact is actually an impostor trying to redirect payments. | ISO, NDPA, PCI |
| Insider Threats and Financial Data Misuse | 5 min | Recognize behaviors that signal insider financial misuse and know the right steps to report concerns without creating a hostile workplace. | SOC2, ISO, NDPA |
| Safe Handling of Payment Card Data | 5 min | Apply the basic rules for handling payment card data safely so your team reduces exposure and supports PCI DSS obligations. | PCI, ISO, SOC2 |
| Building a Security-First Finance Culture | 5 min | Describe practical steps to embed security habits into everyday finance team routines so awareness becomes a shared team value, not a one-time training. | ISO, SOC2, NIST |
Compliance codes show which frameworks each module supports; they describe what the training content covers, not a guarantee of legal compliance. Confirm specific clause wording with your own compliance advisor before citing it to a regulator or auditor.