Connect@ADP

Insights that empower you and your workforce to be successful

The Secure Payroll Priority: Problems, Processes and Potential Partners

Posted by: The ADP Team on 23 July 2020 in Payroll, Security

Payroll is a tempting target for malicious actors, as the combination of high-value data sets and historically slow IT implementation can make their attacks both lucrative and largely risk-free.

With a new decade underway and new threats emerging, implementing secure payroll policies is priority No. 1. But for organizations looking to balance cost, control and compliance, does it make the most sense to outsource or to stay in-house?

Potential Payroll Problems

Payroll faces a dual detriment: manual processes paired with must-have accessibility. While the goal is error elimination, increasing compensation complexity introduces the real risk of additional mistakes, such as data entry mismatches or secure information being sent over encrypted channels. The increasing need for on-demand accessibility, meanwhile, creates a compliance conundrum, as more than 70% of staff surveyed by the Ponemon Institute said they had access to secure data they didn’t need.

The result is a more profitable landscape for payroll profiteers. Some of the most pressing problems include:

  • Internal issues — Malicious or accidental insider threats can compromise payroll processes. If employees knowingly alter time sheets or HR personnel accidentally enter the wrong pay rates, organizations could lose thousands.
  • Spear phishing — While link-laden phishing attacks remain a secure payroll problem, there is a new version of this classic compromise: emails designed to instill confidence through conversation and convince users to change banking details or redirect payments.
  • Ransomware — File-encrypting ransomware attacks are becoming more common as hackers recognize the willingness of business to pay up rather than risk losing payroll data.
  • Nonexistent employees — Attacks are also leveraging network access to create “ghost” employees who receive regular paychecks. Because they appear legitimate, these ghosts may not activate IT security processes.

Priority Processes for Small Businesses

Payroll data is valuable to malicious actors. Enterprises are under threat — but as ADP’s Senior Director of Cyber Security Marketing, Kim Albarella, notes, small businesses are also in the crosshairs.

“The majority of cyberattacks are now launched at small businesses — but we don’t hear about it in the media,” she says.

According to Small Business Trends, 82% of SMBs say they still review their payroll processes manually, which makes these organizations far more susceptible to attacks on their payroll data.

“Most small businesses don’t even have an IT department, let alone a security department,” she says. “Some may have ‘Joe,’ who does IT on the side and at lunch, or a company that sets up their computers and connects them to the Internet.”

Albarella points to three key areas of focus where businesses of any size (particularly SMBs) can improve payroll security:

  • Training — Albarella recommends that organizations first define what they expect from staff in the form of policies and procedures, and then train people appropriately. She puts it simply: “Investing in the people is the No. 1 thing” for businesses, and it’s relatively inexpensive.
  • Back to basics — Are computers patched? Are firewalls in place? Do you have access controls? For Albarella, it’s about “focusing on basic hygiene activities that will help protect your business on a day-to-day basis.”
  • Resilience planning — “If something goes wrong, what do I do? Who do I call? Where is my data stored?” Having a resilience plan in place helps reduce the impact of potential payroll incidents.

Protective Best Practices

With payroll threats on the rise, what can businesses do to limit the potential impact? Here, three processes take priority:

  • Automation — Introducing automation can help streamline labor-intensive and error-prone tasks including data entry, in turn providing payroll teams more time to identify potential payment outliers.
  • Authentication — Advanced user verification techniques like two-factor authentication and single sign-on can reduce user friction when users log in to payroll systems and can also reduce total risk simultaneously.
  • Adaptation — Security threats are constantly evolving. As a result, organizations need payroll systems capable of keeping pace. This means both regular software updates and regular network assessments are needed to ensure payroll processes are meeting performance and protection expectations.

Secure Payroll: Outsourced vs. In-House

All of this prompts a critical question: Is it better to outsource these processes or to keep payment procedures in-house?

Control remains the most popular reason to keep payroll processes on-site — without the additional layer of a third-party provider, there’s theoretically less risk to protected payment data. But Albarella says this can add a significant burden for business leaders.

“You’re responsible 100% of the time for securing the data that you’re taking from your employees for processing your payroll,” she says. “You’re also responsible for the money itself and how it’s transferred; how are you getting that money from your bank account to your employees? How are you submitting the taxes for that?”

Put simply, there’s a case for in-house payroll if organizations have small staff numbers and streamlined payments processes. Once you introduce elements of large-scale data collection and online access, however, the risks of emerging payroll threats typically outpace the benefits of keeping processes on premises.

Payroll attacks are evolving. To stay safe, enterprises must recognize potential threat vectors, prioritize key processes, implement best practices, and identify the best-fit secure payroll solution for their business.

Original article by ADP Spark.

(Visited 104 times, 1 visits today)

TAGS: data security Payroll payroll outsourcing

Post a response

chloroquine generic says
Suntysany says

plaquenil drug https://hydroxychloroquinex.com/ hydroxychloroquine over the counter hydroxide chloroquine

bactrim antibiotic says

sulfamethoxazole Trimethoprim side effects trimethoprim side effects

pharmacepticacom says

top erectile urologists in san francisco https://www.pharmaceptica.com/

cialis price says

cialis pills buy cialis usa

prednisolonewarnings says

prednisone over the counter prednisone tablets

modafinil says

provigil price https://modalertmodafinil.com/

modafinilotc says

where to buy modafinil reddit modafinil 200mg

bactrim antibiotic says

sulfamethoxazole tmp ds trimethoprim sulfa

prednisoneforgout says

buy prednisone online prednisone interactions

bactrim ds says

bactrim coverage sulfamethoxazole uses

accutane for acne says
bactrim generic says

sulfamethoxazole and alcohol bactrim for uti

darielavmlt says
LaltyKarqgka says
darielaftqw says

darielavswk says
darielamlqj says

https://hydrochloroquinebtc.com/ plaquenil 200 mg

LaltyKarrtdm says

hydroxychloroquine plaquenil https://chloroquine500mg.com/

darielaazqo says

chloroquine phosphate https://hydroxychloroquineth.com/

darielaxlov says

hydroxychloroquine side effects hcq

RkkzAudic says
FnmkPhync says

ivermectin (stromectol). ivermectin for fungus

LaltyKarodmp says

hydroxychloroquine for covid 19 hydroxychloroquine coronavirus

darielalbop says

where can i get hydroxychloroquine chloroquine phosphate online

darielapmdg says

https://chloroquinesop.com/

darielaogye says

antimalarial drugs hydroxychloroquine hydroxychloroquine buy online

darielawjwn says

hydroxychloroquine effectiveness hydroxychloroquine online

Cmkobruib says

why is stromectol prescribed ivermectin topical dosage for humans

DmsAudic says

wholesale pharmacy pharmacy in vancouver canada

RumbAudic says

voltaren canadian pharmacies online classes for pharmacy tech

Dsnitani says

otc viagra alternatives watermelon natural viagra

SwhhCano says

generic cialis 20 mg purchase cialis in montreal

FsjkPhync says
darielagdlq says

hydroxychloroquine update today hydroxychloroquine dose

LaltyKaregfe says

chloroquine 500 mg hydroxychloroquine over the counter

KmsgPhora says

cvs pharmacy store number viagra generic canadian pharmacy

darielapamv says
AnsbPooro says

viagra stories pictures viagra and alcohol

Cahubruib says

cialis 50 mg tablets cialis 5mg vs 20mg

darielafwot says

DsjgAudic says

online pre pharmacy programs pharmacy store online

AnsnTriervems says

pharmacy in canada salary victoza canada pharmacy

darielayatb says

buy plaquenil chloroquine brand name

Hsngshurf says

ed. trusted medstore in cialis where can i get cialis

RnsnAudic says

how does ivermectin kill scabies does ivermectin kill tapeworms in dogs

Dsnnitani says

how does ivermectin work in the body ivermectin topical dosage for humans

FnnkPhync says

canadian pharmacy ed medications osco pharmacy

Mose Siers says

Great site you have here.. It's hard to find good quality writing like yours nowadays. I honestly appreciate people like you! Take care!!|

KhrfPhora says

why is stromectol prescribed ivermectin and covid 19

AannPooro says

ivermectin, metronidazole stromectol buy online

Cnsnbruib says

hcg canadian pharmacy best rx pharmacy

auto approve list says

Nice response in return of this difficulty
with real arguments and explaining everything about that.

DktkAudic says

ivermectin overdose treatment why is stromectol prescribed

Hmrmshurf says

ivermectin dose for covid is ivermectin safe for dogs

KvrdPhora says

cialis free trial voucher 2019 genaric cialis

ShheCano says

sildenafil over the counter sildenafil north carolina

Dnsnitani says
FnwnPhync says

mexico viagra pills female viagra pill canada

AsbdfTriervems says

cialis cipra cialis & dapoxitine

AwnnPooro says

how sildenafil works coupon for sildenafil

Cmembruib says

best viagra tablet viagra gel in india

Hmsmshurf says

tadalafil 10mg online tadalafil troche side effects