Secure development lifecycle (SSDLC): what it is and how to put it in place
What the secure development lifecycle is, what happens in each phase, what SAST, DAST and SCA add, and where to start if you have nothing in place today.
Pretending to be someone else in order to get something is an old fraud with new tools. It happens to the person whose identity documents end up being used by somebody else, and it happens to the company that pays an invoice to a supplier that was not its supplier. Both are searched for with the same words and neither is resolved the same way, so this guide separates what to do in each case: what it is exactly, how impersonation differs from full identity theft, how it reaches a company today, and what to do once it has already happened.
Identity theft and impersonation mean passing yourself off as another person or as an organisation in order to obtain a benefit or cause harm. No document needs to be stolen: it is enough to assemble sufficient data for whoever is on the other side to believe they are talking to you.
That data is almost never stolen in one go. It is assembled: a work email address that is published, an org chart that can be inferred from LinkedIn, a phone number that appears in a signature, a password that leaked somewhere else years ago. That is social engineering, and its raw material is information that is nearly always public, or already out there without anyone having noticed.
There are two different victims and it is worth not mixing them up:
The rest of this guide covers both, but it dwells on the second, which is the one almost nobody explains and the one that moves the most money per incident.
It is the most repeated question and almost nobody answers it, so it goes first.
In everyday use the two terms are used interchangeably, and in most conversations they are. Where a distinction is drawn, it is drawn like this:
The practical difference, and the one you notice when you report it, is exactly that: an isolated email and somebody living under your name are not investigated the same way and do not leave the same trail.
What this page will not do is tell you how your case is classified in law. That depends on what was done, with which document and with what intent, and it changes from one jurisdiction to another. A lawyer with the facts in front of them decides it. What matters here is the other half: how it is done technically, how it is detected and how it is made difficult.
This is the form of impersonation that moves the most money in a company and the one that looks least like what people imagine. There is no virus and no red screen: there is a correct email, written in your language, arriving at a plausible moment.
CEO fraud is the well-known version: somebody writes as the chief executive to whoever can authorise a payment, usually with urgency, confidentiality and a deal that justifies skipping the usual circuit.
Business email compromise is the whole family, and its variants are worse because they are more believable:
The way in is usually spear phishing: not a mass email, but one written for one specific person. Its cousins on other channels are smishing by SMS and vishing by phone, which is the old telephone scam with better scripts.
The control that cuts this off is not technical, it is procedural: no change of bank details is accepted through the same channel it arrived on. It is verified by phone, on a number you already had, not the one in the email signature.
Here the victim who pays is not the company, it is its customers, and the brand is charged for it anyway.
The usual forms are a domain that looks like yours with one letter changed or a different extension, a fake social profile that answers your customers, or emails that go out in your name from servers that are not yours.
That last one has a concrete, measurable defence that many companies still do not have properly in place: the records that authorise who may send email on behalf of your domain, with DMARC on top telling the world what to do with anything that does not line up. Publishing it without ever reaching a reject policy is leaving the door ajar, and that is the state most are in.
The other thing you need is to look: domains registered that resemble yours, profiles opened in your name, and mentions of your brand where access is being sold. That is dark web monitoring, and it is how you find out before an angry customer tells you.
Cloning a recognisable voice from public material is a consumer task today, not a laboratory one. And that breaks the informal control half of every company leans on: calling to confirm.
A voice deepfake is used where it has the most effect: a short call, background noise, urgency, and a request that was already half expected. And on video calls, at exactly the quality where the flaws look like the connection.
The practical conclusion is not to distrust everybody, which is not workable. It is this: recognising a voice or a face has stopped being a verification. What verifies is a different channel and a piece of information the attacker cannot have, not that somebody sounds like who they say they are. It is worth saying out loud inside the company, because the people who approve payments still believe that recognising the boss is enough.
A good share of impersonation does not start with a deception, it starts with a password that is already circulating.
And out of that comes the most useful signal there is to watch: a credential from your domain appearing for sale. When that happens there is nothing left to detect afterwards, because the attacker walks in through the front door.
In order, and the first two before anything else:
For a company there is one more step that gets forgotten: warn whoever might receive the next email. If your finance director is the one being impersonated, the people who are going to get the request are your suppliers and your customers.
All of the above can be written into a policy and still not work. The difference between believing your team would spot CEO fraud and knowing it is having tried.
If you would rather see the general order of priorities first, the guide to cybersecurity for companies puts it in sequence, and a specific case can be put to us through contact.
If any of this looks like a problem you are carrying, half an hour on a call scoping it with a senior pentester is worth more than reading another article.
Talk to a senior pentesterPick a time that suits you. You tell us what you need and where you are, and we explain how we work and how we can help.