Decoding the world of cybersecurity

Finance: the security blind spot in plain sight

Jill Knesek, Chief Information Security Officer at BlackLine, argues that finance systems and emerging AI agents need the governance and control expected of critical infrastructure.

Finance: the security blind spot in plain sight

Contributed article

Jill Knesek

Chief Information Security Officer, BlackLine

Attackers rarely go where security teams are looking and, on many occasions, they typically go where they aren’t. Across most enterprises today, one of the largest unwatched spaces sits squarely inside the finance function: the systems that move money, hold the most sensitive data in the business, and are still treated as ordinary software rather than critical infrastructure.

It’s a mismatch that should worry every leadership team and board. Finance has quietly become one of the most attractive targets in the organisation, yet it remains one of the least defended. And as AI accelerates and finance functions hand more decisions to autonomous systems without an independent system of governance and control, this blind spot is about to get considerably larger.

The crown jewels we forgot to guard

Ask most security teams to map their crown jewels, and they’ll point to customer databases, source code, or the identity platform, while finance systems – whether it be the ERP, close and reconciliation tools or banking integrations – tend to be quietly filed under “business applications.”

Yet these are the platforms that hold some of the most sensitive data and highest-value access in the entire organisation, authorising payments, touching bank accounts, and holding the very numbers a company reports to markets and regulators. Treating them as ordinary line-of-business software rather than critical infrastructure is one of the most consequential mistakes an enterprise can make.

The gap between two teams

This gap exists largely because finance and security have historically operated as separate worlds, with finance teams seeing cyber as “IT’s job” and security teams seeing finance as a back-office function that runs on spreadsheets and trusted processes. Attackers understand that disconnect rather better than we do, and they exploit it with real precision. This is why business email compromise, credential theft and invoice fraud all thrive in the space between two teams, who all too often are each assuming the other has it covered. Global financial fraud losses now top $500bn a year, and a striking share of those incidents don’t begin with a sophisticated technical exploit at all, they begin instead with a well-crafted email to someone in finance who has the authority to move money and with no obvious reason to suspect the request is fake.

A new identity class arrives

Now the ground is shifting again, because as finance functions adopt AI agents to execute tasks autonomously, whether that’s preparing reconciliations, matching transactions or chasing collections, those agents become a genuinely new identity class that hold real system access and can act at machine speed, around the clock, without a human in the loop for every step.

The problem is that in most organisations they are onboarded with almost none of the governance we’d insist upon for a human employee, and while we wouldn’t dream of handing a new hire the keys to the ledger without an access review, monitoring, and an audit trail, that is more or less exactly what happens the moment an agent is switched on and pointed at a financial workflow.

The risks this introduces are subtle and serious in equal measure. A manipulated input, a compromised set of credentials, or a maliciously crafted instruction can now flow into an automated financial process and be executed faithfully – for the simple reason that the system is doing exactly what it was told, by something it believes it can trust.

When machine identities already outnumber humans many times over, the question of who, or what, is acting on our behalf, and whether we can actually prove it, will quickly become one of the defining security challenges of the next few years.

Govern it like critical infrastructure

None of this is a reason to slow down, because automation and AI are transforming finance for the better and the answer was never going to be bolting on yet more manual oversight. The answer is to build finance systems on the same principles we apply to any critical infrastructure, so that every action is traceable, every identity -human or agent – is governed, and every automated decision is explainable and open to review.

Agentic finance needs to be about giving AI real work to do while keeping it inside clear policies, segregation of duties, and a complete audit trail. This approach will ensure that productivity never comes at the expense of control. In other words, AI in finance that is powered by intelligence but governed by finance.

Turn the lights on

For CISOs, the immediate task is less about new technology than about closing an old gap. Leaders need to bring finance and security to the same table and extend identity and access governance to cover both the systems that move money and the agents now operating inside them. It is also now time to treat finance as critical infrastructure, in short, because your attackers already do – the blind spot has been hiding in plain sight, and it’s long past the time we turned the lights on.

×