8 ways finance and IT teams can reduce cybersecurity risks
Cybersecurity is no longer just an IT responsibility — finance teams are increasingly on the front line. According to SAP Concur CFO Insights Research, 59% of CFOs plan to increase their cybersecurity budget, and 50% believe both finance and IT leaders are jointly responsible for driving cybersecurity progress. Yet with at least 50% of all data breaches impacting small businesses, many organizations are still working without a coordinated cross-functional strategy.
How can finance and IT teams reduce cybersecurity risk?
This tip sheet outlines eight concrete steps finance and IT leaders can take together to strengthen data protection, reduce fraud exposure, and maintain regulatory compliance.
- Build a cross-functional task force. Align IT, finance, compliance, and legal around a shared risk management strategy — integrating cybersecurity policies with financial tools, processes, and controls from the start.
- Ensure transparency to build trust. Define cybersecurity and data privacy requirements at the start of any vendor evaluation and establish clear workflows to monitor suspicious activity in real time.
- Strengthen data access control. Implement MFA, SSO, SAML 2.0, and role-based access controls (RBAC) to limit each user to only the systems and data their role requires.
- Audit your security measures. Conduct regular internal audits and engage third-party auditors to validate security practices and identify gaps before they become incidents.
- Encrypt data in transit and at rest. Verify vendors use AES-256 for data at rest and TLS for data in transit, and hold them to certifications including SOC 2 Type II and ISO 27001.
- Create an incident response plan. Define roles for detecting, investigating, and reporting incidents — and run regular simulations to keep teams prepared for real-world security events.
- Build employee awareness. Finance teams are high-value targets for social engineering. Ongoing training, phishing simulations, and a culture of accountability significantly reduce human error risk.
- Prioritize your greatest risks. Conduct a cybersecurity risk assessment to focus resources on the threats with the biggest potential impact — from ransomware and fraudulent transactions to regulatory non-compliance.
SAP Concur builds security into every layer of its T&E solutions — with full-stack encryption, continuous monitoring, embedded access controls, and AI capabilities governed by the SAP Global AI Ethics Policy. Critically, your data will never be used to train a large language model (LLM), giving finance and IT teams confidence that organizational data stays private and secure.
Frequently Asked Questions
Why should finance teams be involved in cybersecurity?
Finance teams handle sensitive financial data, payment processes, and vendor transactions — making them high-value targets and critical stakeholders in any security strategy. According to SAP Concur CFO Insights Research, 50% of CFOs believe both finance and IT leaders are jointly responsible for driving cybersecurity progress. Leaving security solely to IT creates blind spots that cybercriminals can exploit.
What is the most common cybersecurity risk for finance teams?
Finance professionals face phishing, social engineering, ransomware, and unauthorized data access. Because they have access to payment systems and sensitive financial data, they are among the most targeted groups within an organization. Regular training and simulated phishing tests are among the most effective defenses against these threats.
How should finance and IT teams collaborate on cybersecurity?
A cross-functional task force that includes IT, finance, compliance, and legal stakeholders creates a unified approach to risk management. Teams should define cybersecurity requirements at the start of any vendor evaluation, conduct regular joint audits, and establish clear incident-response protocols. SAP Concur CFO Insights Research found that 20% of CFOs plan to enhance their collaboration with the CISO and IT department.
What security certifications should a T&E vendor hold?
Finance and IT leaders should look for vendors with SOC 1 Type II, SOC 2 Type II, ISO 27001, and PCI DSS certifications, alongside AES-256 encryption for data at rest and TLS for data in transit. Vendors should also provide documented disaster recovery plans and transparent penetration testing results.
How does SAP Concur protect customer data from AI risks?
SAP Concur's AI capabilities are governed by the SAP Global AI Ethics Policy. SAP Concur never uses customer data to train a large language model (LLM). SAP Concur applies its highest level of security to prevent data leaks to public LLMs, vets AI partners against customer data use policies, and analyzes every AI feature for security, compliance, and data privacy before deployment.
Download the Tip Sheet
Download this tip sheet for eight actionable steps finance and IT teams can take together to strengthen cybersecurity, protect sensitive financial data, and maintain compliance with GDPR, SOX, and PCI DSS.