
Costs
Part of Impersonation runs both ways: protecting your name and your trust in others
Impersonation policy template: what belongs in each section
A working impersonation policy for a small team or group: the decisions it has to settle, a skeleton to adapt, and the drills that make it hold.
Most impersonation policies fail in the same way. They describe the problem, they assign a coordinator, and they say nothing about what an ordinary member does at nine in the evening when a message arrives claiming to be from someone senior.
A usable policy answers a small number of questions in advance so that nobody has to be brave in the moment. This is a skeleton for a club, a small business, a volunteer group, or a family that shares money decisions. Adapt it, and keep it short enough that somebody reads it.
What to take away
- A policy earns its place by removing decisions from the moment of pressure, not by describing threats.
- The two rules that do the work are a callback rule and a no-blame reporting rule.
- Anything untested is a document rather than a policy, so write one drill into it.
What the policy has to settle
Six questions. If a draft does not answer these, it is not finished.
| The question | Why it has to be decided in advance |
|---|---|
| What channels are official | Otherwise every new channel looks plausible |
| How a request for money or data is confirmed | Because confirming in the moment favors the confident |
| Who can approve a payment, and how | So an urgent instruction from a name has no route |
| What a member does when they suspect impersonation | Reporting has to be easier than staying quiet |
| Who speaks publicly, and when | To stop five contradictory statements |
| What happens after, and to whom | So the person who reported is not the person punished |
The skeleton
Adapt the wording. Keep the structure.
Scope. This applies to anyone acting for the group: staff, volunteers, committee members, contractors. It covers our name being used on outsiders and outside names being used on us.
Official channels. Our official accounts and addresses are listed here, maintained by one named role. We announce a new channel from an existing one before using it. We never announce a channel from the new channel itself.
The callback rule. Any request involving money, credentials, personal data, or urgency is confirmed on a channel other than the one it arrived on, using contact details held by us rather than details supplied in the request. This applies regardless of who the request appears to come from, and seniority does not waive it. A person who cannot wait for a callback is not somebody we transact with.
Payment authority. Payments and changes to payment details follow the process below and no other route. Changes to a supplier's bank details are confirmed by callback to a number held on file before the change, never a number in the request. Nobody may approve their own exception.
Codes and credentials. No member ever shares a one-time code, a password, or a screen with anybody, including anybody claiming to be internal support. Our own support will never ask.
Reporting. Anybody who suspects impersonation reports to the named role immediately, and reports it whether or not they acted on it. Reports made in good faith carry no consequence, including when the person already sent money. This clause is the one that decides whether the policy works.
Response. The named role collects the evidence, reports to the platform, warns the people likely to be contacted, and issues one public statement. Members do not engage with the account.
Review. Reviewed twice a year and after any incident, by the named role, with the date recorded on the document.
Adapting it honestly
Three adjustments matter more than the wording.
Name real people rather than titles, since a title with nobody in it is where policies die. Set the payment threshold at a number this group would genuinely feel, rather than a number copied from a larger organization.
And write the callback rule so it protects the junior person. Include the sentence that no member will ever face criticism for slowing a request down, and that anyone who applies pressure to skip the check is treated as a warning sign.
The reasoning behind putting recovery settings and account access ahead of the public response is in account security.
The drills worth running
Twenty minutes, twice a year, and they find more than the document does.
Ask three members to say from memory what they would do with an urgent payment message from the person in charge. Try to reach the named role using only the policy's contact details and see whether they still work.
Take one supplier and confirm the process for a change of bank details actually exists. Read the last incident and check whether the person who reported it would report it again.
The failure modes these expose are the ordinary ones described in impersonation risks: a channel nobody maintains, a role nobody fills, and a reporting route that costs somebody their standing.
After an incident
Write the record while it is fresh, and keep it factual.
What arrived, on what channel, what was asked for, what happened, when it was noticed, who was told, and what was reported where, with reference numbers. That record is what a bank, a platform, or an insurer will ask for, and it is the material for the review.
Report it externally as well as internally. In the US, consumer fraud reports go to the Federal Trade Commission's reporting route, and internet-enabled crime reports go to the FBI's Internet Crime Complaint Center, which explains what a complaint can and cannot do. Where a payment moved, the provider comes first and the sequence is in reporting and recovery.
What to leave out
Short policies get read. Long ones get filed.
Leave out descriptions of how attacks are constructed, which help nobody who has to follow the policy. Leave out a list of red flags, which ages badly and trains people to look for a style rather than to apply a rule: recognition belongs in training, and the pattern-level version of it sits in phishing scams.
Leave out any promise about how quickly a platform will act, because you do not control that. And leave out consequences for members who fell for something, unless you want the next incident reported a week late.
Common questions
Is a policy worth it for a group of five people?
Yes, at one page. The callback rule and the no-blame rule are the entire benefit, and both fit in two sentences.
Who should hold the named role?
Somebody who is usually reachable, not necessarily the most senior person. A role nobody can reach at nine in the evening produces the delay the policy exists to remove.
Should the policy be public?
The parts that tell outsiders how we contact them should be, since that is what makes a fake approach checkable. The internal thresholds should not be.
What if the impersonation targets our customers rather than us?
Warn them directly and quickly, on the channels they already use, and say plainly what you will never ask for. That warning does more than any takedown request.
How do we know the policy is working?
By the number of near misses reported, which should rise rather than fall. A group that reports nothing is not a group without approaches.







