What the Revolut fraud incident reveals about ownership and authority

Revolut fraud incident

In twenty years across CIO and CEO roles, I’ve watched cyber risk become an everyday concern for the whole business. In my role, like many of my peers, I have had to consider the fine balance between security and authority. But even the most carefully considered balance does not always work.

The recent story involving digital bank Revolut, where sensitive personal data belonging to hundreds of customers was disclosed following fraudulent information requests, is a clear example of why processes alone are not enough. The breach was later followed by a wave of phishing attacks targeting Revolut customers, showing how one incident can create further opportunities for criminals. Processes need to be supported by clear ownership and the authority to act quickly and responsibly.

Revolut’s systems did exactly what they were designed to do. A normal process moved the data through the business before anyone realised the request itself was false.

In this case, the fraudulent request came from a legitimate government email domain, and the checks in place did not catch it. The check that could have stopped this existed in Revolut’s process, but it ran too late to make a difference.

We are seeing increasingly sophisticated and legitimate-looking requests slip past traditional security controls. As those requests become harder for technology alone to identify, people are increasingly becoming the last line of defence.

Technology and people need a plan behind them, with clear points where a problem gets flagged and stopped before it spreads. That could be a second check on unusual requests, or a habit of verifying anything sensitive through a separate channel before acting on it.

Technology also needs ownership. That means named people who are trusted to challenge a request and ask difficult questions, even when the paperwork looks correct.

In the Royal Navy, we called this a manoeuvrist approach. It means trusting the person closest to the situation to act on what they see, without needing permission from further up the chain. Applied here, it means the person handling a data request can pause it and flag a concern, even if every box has been checked. It also means backing that decision afterwards, on the occasions it turns out to be nothing.

The person who raises a concern needs to know that being wrong once will not cost them their standing. Otherwise, the next concern goes unspoken.

Revolut will not be the last major organisation caught by a request that appears legitimate and passes the usual checks. Processes provide consistency, but no process can anticipate every situation. The people closest to an issue will often notice first, and true resilience depends on giving them the confidence and authority to intervene.

For technology leaders, the responsibility is therefore broader than simply building effective controls. It is also to create the culture, ownership and authority needed to respond when those controls are not enough.

If you received a request like that tomorrow and it looked entirely legitimate, who in your business has the authority to stop it?

Looking for something specific?