FirstHR

Payroll Security: A Practical Guide for Small Business

What payroll security means, the fraud schemes targeting small employers, the controls that work without an IT team, and what to do after a breach.

Nick Anisimov

Nick Anisimov

FirstHR Founder

Payroll
19 min

Payroll Security

The threats that actually target small employers, the controls worth your time, and what to do in the first hour if something goes wrong

Almost every guide on this subject is written as though you have a security team. Encrypt data at rest, implement zero-trust architecture, conduct penetration testing. All reasonable, none of it actionable for a company where the person running payroll is also the person answering the phone.

Here is the version that matches reality. The attack most likely to cost you money is an email, asking payroll to update someone's bank details before Friday. It requires no technical sophistication, it targets a person rather than a system, and the control that stops it is a phone call. No encryption involved.

This guide covers what payroll security means in practice, the specific schemes that target businesses with five to a hundred employees, the controls worth your limited time in the order I would do them, and a first-hour playbook for when something goes wrong, which almost no small-business guide includes. I build FirstHR for companies at this size. This is general information rather than legal or security advice.

TL;DR
Payroll security is protecting payroll data and payroll funds from theft, fraud, and unauthorized access. Two risk categories: outsiders using email deception to redirect payments or steal W-2 data, and insiders exploiting weak controls through ghost employees or inflated hours. The five controls that cover most realistic risk are multi-factor authentication, role-based access, two-channel verification for bank changes, no personal data by email, and a quarterly access and roster review. None requires an IT department.

What Is Payroll Security?

Payroll security is the set of controls, processes, and technologies a business uses to protect payroll data and payroll funds from theft, fraud, and unauthorized access.

Definition
Payroll Security
Payroll security refers to the safeguards an employer puts in place to protect the payroll process from theft of funds and theft of data. It spans access controls determining who can view or change payroll information, verification procedures for high-risk changes such as bank details, internal controls that make fraud by employees harder to commit and easier to detect, and the technical protections provided by the payroll system itself. It addresses both external attackers and internal misuse, which require different countermeasures.

The definition splits usefully into two halves that people tend to conflate. Protecting the money is about payments going where they should, which is threatened by both email fraud from outside and manipulation from inside. Protecting the data is about Social Security numbers, addresses, and bank details not leaving your control, which carries legal consequences separate from any financial loss.

Both matter, and the controls overlap, but the distinction is worth holding because the failure modes look completely different. A diverted paycheck is discovered within days when someone complains. A stolen W-2 file may not surface until employees start having tax returns rejected months later.

Why Small Businesses Are Targeted

Not because they hold more valuable data, but because they hold the same data with fewer controls around it, and attackers know it.

Per the Association of Certified Fraud Examiners' Occupational Fraud 2024: A Report to the Nations, the typical organization loses an estimated 5 percent of revenue to fraud each year, the median loss per case was $145,000, and cases ran a median of 12 months before being detected. More than half of cases traced to either a lack of internal controls or an override of the controls that existed.

That last finding is the one that matters most at small scale, because it describes exactly the situation a growing business is in: controls have not been built yet, or one person is trusted enough to bypass them. Neither is negligence. Both are how a company with eight people naturally operates until someone decides otherwise.

Detection Time Is the Real Cost Driver
The ACFE found that 43 percent of frauds were detected by a tip, more than three times the next most common method, and that frauds caught within the first six months carried a median loss of $30,000 against $250,000 for those lasting two to three years. The lesson for a small employer is not that you need sophisticated detection. It is that a review cadence and a way for people to raise concerns are worth more than any technical control, because the cost of fraud scales with how long it runs undetected.

The Threats That Actually Happen

Five schemes account for nearly everything a small employer will realistically face. Two come from outside, three from inside, and the countermeasures differ accordingly.

Direct deposit diversionOutsider, by email
An email that looks like it came from an employee asks payroll to update their bank details before the next run. The money goes to a prepaid card and is gone. This is the single highest-value control to fix because the fix is free.
W-2 phishingOutsider, by email
A spoofed message appearing to come from an executive asks payroll or HR for a list of all employees and their W-2 forms. One reply exposes every Social Security number in the company at once.
Ghost employeesInsider
Someone who never worked there, or who left and was never removed, stays on the payroll with pay routed to an account the perpetrator controls. Small teams are especially exposed because one person often controls the whole process.
Inflated hours or ratesInsider
Timesheets padded, overtime added, or a pay rate quietly adjusted upward. Individually small, cumulatively significant, and invisible without someone reviewing changes against an approved record.
Expense and reimbursement abuseInsider
Duplicate submissions, personal costs claimed as business, or inflated amounts. Sits next to payroll rather than inside it, but is caught by the same control: someone other than the submitter approving.

Notice the split in the right-hand column. Outsider attacks target a person, using email to make a fraudulent request look routine, and are stopped by verification procedures. Insider fraud exploits a process, using the absence of a second pair of eyes, and is stopped by separation of duties and review. Investing entirely in one category leaves the other wide open, which is the most common structural mistake in small-business payroll security.

Still Using Spreadsheets for Onboarding?
Automate documents, training assignments, task management, and track onboarding progress in real time.
See How It Works

Direct Deposit Diversion: The Highest-Value Fix

If you do one thing after reading this, do this one. It is the attack with the best ratio of loss prevented to effort required, and the control is free.

The scheme is simple. Payroll receives an email that appears to come from an employee, asking to update their direct deposit details before the next run. The tone is casual and the timing is plausible. The new account is usually a prepaid card, and the funds are withdrawn before anyone notices the paycheck did not arrive.

Per an FBI Internet Crime Complaint Center public service announcement, 1,053 complaints reporting this evolution of the payroll diversion scheme were filed between January 1, 2018 and June 30, 2019, with total reported losses of $8,323,354 and an average loss of $7,904 per complaint. The dollar loss from direct deposit change requests increased more than 815 percent over that period.

The Rule: Never Act on an Email Alone
Every bank detail change gets verified through a second channel. If the request comes by email, you call the employee on a number you already hold, not one supplied in the message. If it comes by phone, you confirm in writing to their known address. This takes two minutes and closes the attack path completely, because the criminal controls the email and nothing else. Write it down as a rule so it survives the day when the request looks urgent and the person asking sounds impatient.

The stronger version of this control removes payroll from the loop entirely: employees update their own bank details through a self-service portal protected by multi-factor authentication, and payroll never processes a change based on a message at all. If your system supports employee self-service, turning it on is a security decision as much as a convenience one. The mechanics of the payment method itself are covered in the direct deposit guide.

W-2 Phishing

The second outsider attack, and the one with the worse aftermath, because it exposes every employee at once rather than diverting one paycheck.

A spoofed email appearing to come from a company executive lands with someone in payroll or HR, asking for a list of all employees and their Forms W-2. It arrives during tax season when such a request seems ordinary. One reply hands over names, addresses, and Social Security numbers for the entire workforce, which criminals use to file fraudulent tax refunds before the real employees file.

The IRS maintains dedicated reporting channels for exactly this scheme, which tells you how routine it has become. Per the IRS guidance for businesses and payroll service providers, employers that lose data should email dataloss@irs.gov with W2 Data Loss in the subject line, providing business name, EIN, contact details, a summary of how the loss occurred, and the number of employees affected, without attaching any employee personal data.

Two controls prevent it. First, a standing rule that bulk employee data is never sent by email, to anyone, including the owner. Second, telling your team explicitly that no executive will ever email asking for W-2 information, so the request itself is the red flag rather than something to be evaluated on its merits.

What worked for me
The thing that changed my thinking was realizing the attack does not target the system, it targets the instinct to be helpful. Someone senior asks for something urgently, and a good employee complies quickly. That is the whole exploit. What worked was not a policy document. It was saying out loud, in a team meeting, that nobody will ever be criticized for slowing down to verify a request about money or personal data, and that if a request from me looks odd, the right response is to call me. Removing the social pressure to comply fast is the actual control.

Insider Fraud and Ghost Employees

Less discussed than email attacks and harder to talk about, because it involves the possibility that someone you trust is stealing. The controls are not accusations. They are the things that make trust unnecessary.

Ghost employees are the classic scheme: someone on the payroll who does not work there, either invented outright or a departed employee never removed, with pay routed to an account the perpetrator controls. It requires the ability to add or retain a payee without anyone checking, which is precisely what a one-person payroll function provides.

Inflated hours and rate changes are subtler and more common. Extra hours added to a timesheet, overtime that was never worked, or a pay rate nudged upward. Each instance is small enough to look like an error if caught, which is what makes the scheme durable.

The detection method for all of these is the same and takes fifteen minutes: compare the payroll register against your actual roster, name by name, every quarter. Anyone being paid who should not be shows up immediately. Then check that pay rates match what was approved, and look at any overtime against the approvals. The deeper version of this exercise is covered in the payroll audit guide, and offboarding is where the departed-employee version gets prevented in the first place, via the offboarding checklist.

The Controls That Matter

Ordered by return on your time rather than by security-framework category. The first group closes most of the realistic risk and costs nothing.

Do this weekFree, fast, and covers the majority of realistic risk.
Turn on multi-factor authentication for every payroll and email account
Adopt a two-channel rule for bank detail changes: never act on email alone
List everyone who can access payroll and remove anyone who no longer needs it
Stop emailing spreadsheets containing Social Security numbers, permanently
Tell your team that no executive will ever email asking for W-2 data
Do this monthStructural changes that take a little setup and then run themselves.
Set role-based access so people see only what their job requires
Move employees to self-service for their own bank and address changes
Confirm your payroll system keeps an audit log of who changed what and when
Add payroll access removal to your offboarding checklist
Write down who approves payroll and who runs it, and make them different people where possible
Do every quarterThe recurring review that catches what the controls miss.
Compare the payroll register against your actual employee roster, name by name
Review all bank detail changes made since the last check
Review the access list again, since it drifts faster than anyone expects
Spot-check a few timesheets and any overtime against approvals

The honest assessment: if you only ever do the first group, you have addressed the majority of what actually happens to businesses your size. Multi-factor authentication and a verification rule for bank changes between them close both high-value outsider attacks. The second and third groups are what turn a set of good habits into something that survives staff changes and growth.

One item deserves emphasis because it is invisible until it matters: removing payroll access when someone leaves. Access lists drift constantly, and an ex-employee or ex-contractor with live credentials is a risk that grows with every departure. Attaching deprovisioning to your IT offboarding checklist is what makes it happen reliably rather than when someone remembers.

Separation of Duties on a Tiny Team

The standard advice here is useless at small scale, so here is the version that works when you have eight people and one of them does everything administrative.

Separation of duties when there is nobody to separate
The textbook control is that different people prepare payroll, approve it, and reconcile it. At eight employees that is not available. Here is the version that is.
Split approval from executionIf your office manager runs payroll, the owner reviews and approves the register before it is submitted. Not a signature on a total: a look at the names and the amounts.
Use your accountant as the second pair of eyesAn external bookkeeper or accountant who reconciles payroll to the bank is functionally a second person, and you are probably already paying them. Ask them to flag new names and changed bank details.
Let the software be the thirdAn audit log that records every change and who made it does not prevent fraud, but it makes it visible and attributable, which is most of the deterrent effect at this size.
The goal is not perfect segregation. It is ensuring that no single person can add a payee, change bank details, and release the money without anyone else seeing it.

The reason this matters more than it sounds is the ACFE finding cited earlier: most fraud traces to missing controls or overridden ones. At a small company the control is usually missing rather than overridden, simply because nobody built it. Building the minimum version costs one review step per pay run.

Companies Using FirstHR Onboard 3x Faster
Join hundreds of small businesses who transformed their new hire experience.
See It in Action

What to Look For in Payroll Software

Your software choice handles the technical layer you cannot build yourself. Five features carry most of the weight, and they are worth checking before you buy rather than after.

FeatureWhat it doesWhy it matters at your size
Multi-factor authenticationRequires a second factor beyond the password to sign inStolen credentials are the most common way into any system; this makes a stolen password insufficient on its own
Role-based access controlLimits what each user can see and change based on their roleLets you give someone the access their job needs without exposing every salary and Social Security number in the company
Audit loggingRecords who changed what and when, permanentlyMakes changes attributable, which is both a deterrent and the only way to reconstruct what happened after an incident
Employee self-serviceEmployees update their own bank details and addressesRemoves the email-request attack path entirely, because payroll never processes a change from a message
Independent security certificationA third party has audited the provider's security controlsYou cannot audit a vendor yourself; a recognized certification is the practical substitute

The last row is the closest thing to a shortcut available to a small employer. You have no realistic way to evaluate a vendor's internal security posture, so a recognized independent audit standing behind it is what you have instead. Ask for it during evaluation; a provider that cannot produce anything is telling you something. The wider software question is covered in the HR technology guide, and where payroll data lives alongside everything else in the HR document management guide.

Remote and Hybrid Payroll Processing

Payroll used to be run from one machine in one office. Now it is frequently run from a kitchen table, and the assumptions built into older security advice no longer hold.

Four things change. The network is not yours, and home routers are patched less often than office equipment. The device may be personal, shared with family and running whatever software the household installed. Public Wi-Fi becomes a possibility for someone processing payroll from a coffee shop. And screens are visible to people who should not be seeing salary data.

The mini-policy is short enough to fit in an email: payroll is processed on a company-managed device or a personal device that is password-protected and up to date, never over public Wi-Fi, always with multi-factor authentication enabled, and never with payroll data downloaded to the local machine. That last point does the most work, because data that stays in the system cannot be lost with the laptop. The wider set of remote working practices is in the remote work guide.

If It Happens: The First Hour

Almost no small-business guide covers this, and it is the part you will need under pressure, when reading calmly is not an option. Print it or save it somewhere findable.

1Contact your bank immediately. Recovery depends almost entirely on speed, and the window is measured in hours rather than days.
2File a complaint with the FBI Internet Crime Complaint Center at ic3.gov. Note the scheme type in the body of the complaint.
3If W-2 or Social Security data was exposed, email dataloss@irs.gov with the subject line W2 Data Loss. Include your business name, EIN, contact details, a summary of what happened, and the number of employees affected. Do not attach any employee personal data.
4Forward the phishing email itself to phishing@irs.gov with the subject line W-2 scam, sent as an attachment rather than forwarded inline where possible.
5Tell the affected employees the same day. They need to place fraud alerts and watch for fraudulent tax filings, and delay makes both harder.
6Reset credentials for every account involved and check for mailbox rules the attacker may have added to hide alerts.
7Check your state breach notification law, since exposure of Social Security numbers triggers notice obligations in most states on defined timelines.
General information rather than legal advice. Breach notification obligations vary by state and by the type of data exposed; get counsel involved early if personal data has left your control.

Two points about the sequence. The bank comes first because recovery of diverted funds depends almost entirely on how fast the transfer is flagged, and the window closes in hours. Telling employees comes early, not after you have finished investigating, because they need to act on their own behalf and the delay is what turns a data incident into a trust problem.

Worth noting what is not on the list: figuring out who is at fault. That question matters later and helps nothing in the first hour. The employee who replied to a convincing spoofed email did what the attack was designed to make them do, and treating it as a personal failure makes the next person hesitate to report, which is a far more expensive outcome.

Quick Self-Check

Six questions. Any no is a specific thing to fix this week rather than a general concern.

Is multi-factor authentication on for payroll and email?
Email matters as much as payroll here, because a compromised mailbox is how attackers make fraudulent requests look genuine. Both, not one.
Do you have a written rule for bank detail changes?
Two-channel verification, no exceptions. Written down, because the value of the rule is that it holds on the day someone is being pushy about urgency.
Do you know exactly who can access payroll right now?
Not who should be able to. Who actually can, including former staff, contractors, and anyone who was given temporary access and never lost it.
When did you last compare the payroll register to your roster?
Fifteen minutes, quarterly. It is the only reliable way to catch a name on payroll that should not be there.
Does your payroll system keep an audit log you could actually read?
Having one is table stakes. Being able to find out who changed a bank detail last Tuesday is the version that helps during an incident.
Would your team know what to do in the first hour?
Bank, then ic3.gov, then dataloss@irs.gov if W-2 data was exposed, then employees. Knowing the sequence in advance is what makes speed possible.

None of this requires security expertise. It requires deciding who can do what, verifying changes that move money, and looking at the payroll register four times a year. How this fits into running payroll generally is in the running payroll guide, and the wider compliance picture in the payroll compliance guide.

Key Takeaways
Payroll security protects two things: the funds and the data. They fail differently, and both need attention.
The highest-value control is free: never change bank details based on an email alone. Verify through a second channel every time.
Per the FBI Internet Crime Complaint Center, 1,053 payroll diversion complaints between January 2018 and June 2019 produced reported losses of $8,323,354, with direct deposit change losses up more than 815 percent.
W-2 phishing exposes every employee at once. A standing rule that bulk employee data is never emailed prevents it.
Insider schemes such as ghost employees and inflated hours are caught by comparing the payroll register to your actual roster, name by name, every quarter.
Per the ACFE 2024 report, the typical organization loses about 5 percent of revenue to fraud, median loss per case was $145,000, and more than half of cases traced to missing or overridden internal controls.
Detection speed drives cost: frauds caught within six months had a median loss of $30,000 against $250,000 for those running two to three years.
Five controls cover most realistic risk: multi-factor authentication, role-based access, two-channel verification for bank changes, no personal data by email, and a quarterly access and roster review.
Separation of duties is achievable on a tiny team: split approval from execution, use your accountant as the second reviewer, and rely on audit logs as the third.
Know the incident sequence before you need it: bank first, then ic3.gov, then dataloss@irs.gov if W-2 data was exposed, then affected employees the same day.

Frequently Asked Questions

What is payroll security?

Payroll security is the set of controls, processes, and technologies a business uses to protect payroll data and payroll funds from theft, fraud, and unauthorized access. It covers two distinct risks: outsiders trying to redirect payments or steal employee data, and insiders exploiting weak internal controls to pay themselves more than they are owed. For a small business it comes down to controlling who can access payroll, verifying changes to bank details, and reviewing what was actually paid against what should have been paid.

How do you keep payroll data secure?

Five controls cover most of the realistic risk. Turn on multi-factor authentication for payroll and email accounts. Set role-based access so people can only see what their job requires. Verify any request to change bank details through a second channel, never by email alone. Stop emailing files that contain Social Security numbers and use a self-service portal instead. And review who has payroll access every quarter, since access lists drift as people change roles and leave.

What is payroll fraud?

Payroll fraud is the manipulation of a payroll system to obtain money the perpetrator is not entitled to. The common schemes are ghost employees, where someone who does not work at the company remains on payroll; falsified hours or overtime; unauthorized changes to pay rates; expense reimbursement abuse; and direct deposit diversion, where bank details are changed so pay goes to an account the fraudster controls. Some schemes are run by insiders and some by outsiders using email deception.

How common is payroll fraud at small businesses?

Occupational fraud generally is significant: per the Association of Certified Fraud Examiners' 2024 Report to the Nations, the typical organization loses an estimated 5 percent of revenue to fraud each year, the median loss per case was $145,000, and cases ran a median of 12 months before detection. Smaller organizations are disproportionately affected because they have fewer internal controls. The ACFE also found that more than half of cases traced to either a lack of internal controls or an override of the controls that existed.

What is payroll diversion fraud?

Payroll diversion is a form of business email compromise in which a criminal sends payroll or HR an email that appears to come from an employee, requesting a change to their direct deposit details before the next pay run. The new account is typically a prepaid card, and the money is withdrawn quickly. Per an FBI Internet Crime Complaint Center advisory, 1,053 complaints reporting this scheme were filed between January 2018 and June 2019 with reported losses of $8,323,354, and the dollar loss of direct deposit change requests rose more than 815 percent over that period.

How do I stop direct deposit change fraud?

Require verification through a second channel for every bank detail change, without exception. If the request arrives by email, confirm it by phone using a number you already have on file, not a number supplied in the message. Better still, require employees to make the change themselves in a self-service portal secured with multi-factor authentication, so payroll never processes a change based on a message at all. This single control costs nothing and closes the highest-loss attack path against small employers.

What is the W-2 phishing scam?

A criminal spoofs an email to look as though it came from a company executive and sends it to someone in payroll or HR, asking for a list of all employees and their Forms W-2. A single reply exposes names, addresses, and Social Security numbers for the entire workforce, which is then used to file fraudulent tax refunds. The IRS maintains reporting channels specifically for this: businesses that lose data should email dataloss@irs.gov, and the scam email itself should be sent to phishing@irs.gov.

Do I need an IT department to secure payroll?

No. The controls that eliminate most small-business payroll risk are administrative rather than technical: multi-factor authentication, role-based access, a verification rule for bank changes, removing access when people leave, and a quarterly review of who is on the payroll. Choosing payroll or HR software that provides access controls and audit logs handles the technical layer for you. What you cannot outsource is the decision about who is allowed to do what, and the discipline of actually reviewing it.

How often should I audit payroll?

A light review every quarter and a deeper one annually works for most small businesses. The quarterly review compares the payroll register against your actual roster to catch anyone being paid who should not be, checks bank detail changes made since the last review, and re-checks the access list. The annual review goes further into pay rates, overtime patterns, and reconciliation against tax filings. The point of the quarterly cadence is that fraud detected in three months costs dramatically less than fraud detected in a year.

What should I do if payroll data is breached?

Move fast, because recovery depends on speed. Contact your bank immediately if funds were diverted. File a complaint with the FBI at ic3.gov. If W-2 or Social Security data was exposed, notify the IRS at dataloss@irs.gov with the subject line W2 Data Loss, including your business name, EIN, contact details, a summary of the incident, and the number of employees affected, but no employee personal data. Tell affected employees the same day, reset credentials, and check your state's breach notification requirements.

Ready to transform your onboarding?

7-day free trial No credit card required
Start Your Free Trial