
Sign up to save your podcasts
Or


The FBI's Internet Crime Complaint Center logged more than one million complaints in 2025 for the first time in the program's 25-year history. Reported losses came in just under $21 billion, up roughly 25% year over year. Business email compromise alone accounted for over $3 billion — making it the most financially destructive threat category aimed specifically at organizations. And for the first time, the IC3 report carved out a dedicated section for AI-related crime.
This isn't a story about Fortune 500 targets. A large company has a fraud team, a security operations center, and dedicated identity verification vendors. Your 150-person company has a controller, an office manager who also handles HR, and an outside IT provider you call when something breaks. The attackers are the same. The tools are the same. The asymmetry is the point.
In this episode, Chad walks through three operational controls built for the middle market: verifying any payment or account-change request outside the channel it arrived on, replacing one-time authentication codes with passkeys and FIDO2 authentication, and shifting your team's training from spotting a fake to following a procedure — regardless of how convincing the request looks. The third control is the one most organizations skip, and it's the one that matters most now that AI has made every signal your team was trained to trust trivially easy to fake.
You'll leave with three concrete actions you can assign tomorrow afternoon: a one-page callback rule, one question for your IT provider, and a call to your bank's fraud desk before you ever need it.
AI for the C Suite™ podcast keeps C-Suite leaders informed and engaged in the world of AI for business. If you're a CEO, President, Owner, or C-suite leader looking to understand how AI will impact your organization, you've found the right podcast.
https://aiforthecsuite.com/#chadharvey #aiforthecsuite #aic
By Chad HarveyThe FBI's Internet Crime Complaint Center logged more than one million complaints in 2025 for the first time in the program's 25-year history. Reported losses came in just under $21 billion, up roughly 25% year over year. Business email compromise alone accounted for over $3 billion — making it the most financially destructive threat category aimed specifically at organizations. And for the first time, the IC3 report carved out a dedicated section for AI-related crime.
This isn't a story about Fortune 500 targets. A large company has a fraud team, a security operations center, and dedicated identity verification vendors. Your 150-person company has a controller, an office manager who also handles HR, and an outside IT provider you call when something breaks. The attackers are the same. The tools are the same. The asymmetry is the point.
In this episode, Chad walks through three operational controls built for the middle market: verifying any payment or account-change request outside the channel it arrived on, replacing one-time authentication codes with passkeys and FIDO2 authentication, and shifting your team's training from spotting a fake to following a procedure — regardless of how convincing the request looks. The third control is the one most organizations skip, and it's the one that matters most now that AI has made every signal your team was trained to trust trivially easy to fake.
You'll leave with three concrete actions you can assign tomorrow afternoon: a one-page callback rule, one question for your IT provider, and a call to your bank's fraud desk before you ever need it.
AI for the C Suite™ podcast keeps C-Suite leaders informed and engaged in the world of AI for business. If you're a CEO, President, Owner, or C-suite leader looking to understand how AI will impact your organization, you've found the right podcast.
https://aiforthecsuite.com/#chadharvey #aiforthecsuite #aic