AI cloud on the horizon

The Security Horizon in the Age of AI

It's hard to talk about security these days without AI dominating the conversation, but we must not forget the basics.
 

When we scanned the security horizon in our 2018 article, AI didn't rate a mention. Perhaps it was hiding on the dark side of the moon. Fast forward to the present day, and it hovers over us like a storm cloud, raining down threat or opportunity (or both), depending on your perspective.

Rather than just disappearing down the AI rabbit hole, this article reminds us that other security threats are as relevant today as ever.

We will:

  • Send up a drone for a big-picture, 360-degree scan of the security horizon.
  • Recount some "epic fails” to illustrate what can happen when security goes seriously wrong.
  • Discuss how your existing business system, supported by the creative use of Orchid add-ons, can contribute to enhanced security.

Security-thinking shouldn't be considered just the responsibility of IT and operations. It must also be firmly embedded into corporate culture and day-to-day tasks.

The Drone's Eye View

In 2018, we sent up a helicopter to scan the security horizon. These days, we can achieve the same end, and cut costs, with a state-of-the-art drone. 

The detail differs from business to business, but if we fly high enough, the horizon flattens out, and some common features emerge from the security landscape. Most security considerations can be squeezed into one or more of these three broad categories:

  1. Physical: Let’s take this to encompass everything from the lock on the office or warehouse door, to the physical assets, documents and inventory held within.
     
  2. Technical: All that stuff we should be paying IT and network security experts to advise us on, including AI-based threats. Add to that the checks and balances in our business software that can give us early warning of threats much closer to home - more on that later!
     
  3. Cultural: This is where it gets personal. What example do our leaders set, and how lax are our internal processes? Is there a culture where theft, fraud or other security breaches are not just possible, but perhaps even implicitly tolerated? Sophisticated scams, often AI-powered, also require a company-wide culture of eternal vigilance.

5% of business revenue is lost to fraud each year. A typical scheme runs for 12 months before anyone notices, and it usually starts with someone trusted (1).

(1) ACFE, Occupational Fraud 2026: A Report to the Nations (2,402 cases, 143 countries)

Crash Landings & Epic Fails

Space capsule crashing into ocean

 

OK, so you're cutting a few corners, but what's the worst that could happen? These real-life case studies illustrate the possible consequences when things go seriously wrong. 

For every disaster that makes the international headlines, countless others fly beneath the media radar. An appropriate response might be “There, but for the grace of God, go I”.

Before laughing at their misfortune, it would serve us all well to ensure we have our own houses in order. 

Epic Fail 1 (Physical Security):  Buckingham Palace break-in, UK, 1982. An oldie, but a goodie. Michael Fagan makes a mockery of palace security, on two separate occasions. He rests on the throne, gets a maid to bring a cigarette, and ends up visiting Queen Elizabeth in her bedroom.

Epic Fail 2 (Physical Security): Louvre Heist, France, 2025. A newbie, and a doozy. Thieves disguised as construction workers erect a mobile furniture lift near the banks of the Seine in broad daylight, then break into a window and display cases. They flee 8 minutes later with many of the priceless French crown jewels...dropping the Crown of Empress Eugénie in the street as they go.

Epic Fail 3 (Document Security): Cabinet Files scandal, Australia, 2018. A man buys 2 locked filing cabinets for $10 each at an ex-government furniture auction. They turn out to be packed with highly classified documents showing the internal deliberations at the highest level of successive Australian governments.

Epic Fail 4 (Network Security): Jaguar Land Rover cyberattack, UK, 2025: A cyberattack halts car production for around five weeks. Estimated cost to the UK economy: £1.9 billion, across 5,000+ businesses.

Epic Fail 4 (Data Security): Coincheck theft, Japan, 2018: Coincheck, one of Japan’s largest digital currency exchanges, admitted to being hacked out of $534 million worth of cryptocurrency in the world’s biggest digital currency theft.

Epic Fail 5 (Internal Security): Enron Scandal, US, 2001: Texas giant Enron Corporation lived up to its “America’s Most Innovative Company” tag when the CEO and CFO found creative ways to keep huge debts off the balance sheet. It came unravelled big time, with Enron bankrupt, shareholders losing a cool $74 billion, Authur Andersen going down with the ship, and lots of other collateral damage.

Epic Fail 6 (AI-related Scams): Arup Deepfake Scam, Hong Kong, 2024:  A finance employee joins a video call with the CFO and colleagues. Every face on the call is an AI-generated deepfake. Fifteen transfers later, US$25.6 million is gone.

Where Orchid's Sage Add-ons can help!

While an ERP system won’t lock the office door behind you, it can be used to add layers of security to your business. With the judicious use of 3rd party add-ons, you have the potential to take this much further. Here are some of the ways that Sage Add-ons from Orchid Systems can contribute.

Sage Intacct Add-Ons:

  • EFT Processing for Sage Intacct
    • Supports direct upload of EFT files to your bank via SFTP
    • Extensive audit logs of EFT files created, plus all changes to banking details
    • Reduce risk of cheque theft/fraud by no longer printing or mailing physical cheques.
    • Uses Industry-leading WebAssembly technology, so mapping of your banking information takes place within your environment, not on a 3rd party site

Sage 300 Add-ons:

  • EFT Processing for Sage 300
    • The EFT features above, plus...
    • Bank account details can be stored in an encrypted form. You control who has the authority to view or amend account details.
    • If you still need to produce physical cheques, create ‘Positive Pay’ files so participating banks will only honour presented cheques that match the details provided
       
  • Inter Entity Transactions & Trade
    • Automatically generating accounting entries for complex transactions not only increases accuracy, but also removes opportunities for fraud by taking this out of the hands of individuals.
    • The resulting transparency and visibility across entities increases the chances of early detection for any anomalies, which in turn creates a deterrent for anyone contemplating fraud.
       
  • Process Scheduler
    • Automated scheduling of integrity checks & backups
    • Schedule of custom Extender scripts to identify and manage exceptions
       
  • Extender
    • Logging and alerting of changes to sensitive data
    • Custom alerting of exception transactions, based on parameters you define. (E.g. suspicious AR or inventory write-offs, long overdue invoices.)
    • Custom (field-level) validation and security, plus segregation of duties. (E.g. employees enter transactions, but only their supervisor can post.)
    • Trigger external validations, e.g. check company details for new customers or vendors.
    • Trigger workflows for multi-person review and approval of sensitive transactions.
    • Use in conjunction with Process Scheduler to regularly check and report on exceptions.
       
  • Return Materials Authorizations, Bin Tracking
    • Improved visibility of inventory locations and movements means more transparency, fewer stock losses/leakage, reduced write-offs.
       
  • Notes, Document Management Link, Info-Explorer
    • Staff have access to context-sensitive information and documents when and where it's needed.
    • Greater transparency increases the chance that anomalies will be picked up early.
    • Reduced reliance on physical documents removes a security risk.

 

 

Latest

AI cloud on the horizon
The Security Horizon in the Age of AI
It's hard to talk about security these days without AI dominating the conversation, but we must not forget the basics.