Payroll Security: A Practical Guide for Small Business
What payroll security means, the fraud schemes targeting small employers, the controls that work without an IT team, and what to do after a breach.
Payroll Security
The threats that actually target small employers, the controls worth your time, and what to do in the first hour if something goes wrong
Almost every guide on this subject is written as though you have a security team. Encrypt data at rest, implement zero-trust architecture, conduct penetration testing. All reasonable, none of it actionable for a company where the person running payroll is also the person answering the phone.
Here is the version that matches reality. The attack most likely to cost you money is an email, asking payroll to update someone's bank details before Friday. It requires no technical sophistication, it targets a person rather than a system, and the control that stops it is a phone call. No encryption involved.
This guide covers what payroll security means in practice, the specific schemes that target businesses with five to a hundred employees, the controls worth your limited time in the order I would do them, and a first-hour playbook for when something goes wrong, which almost no small-business guide includes. I build FirstHR for companies at this size. This is general information rather than legal or security advice.
What Is Payroll Security?
Payroll security is the set of controls, processes, and technologies a business uses to protect payroll data and payroll funds from theft, fraud, and unauthorized access.
The definition splits usefully into two halves that people tend to conflate. Protecting the money is about payments going where they should, which is threatened by both email fraud from outside and manipulation from inside. Protecting the data is about Social Security numbers, addresses, and bank details not leaving your control, which carries legal consequences separate from any financial loss.
Both matter, and the controls overlap, but the distinction is worth holding because the failure modes look completely different. A diverted paycheck is discovered within days when someone complains. A stolen W-2 file may not surface until employees start having tax returns rejected months later.
Why Small Businesses Are Targeted
Not because they hold more valuable data, but because they hold the same data with fewer controls around it, and attackers know it.
Per the Association of Certified Fraud Examiners' Occupational Fraud 2024: A Report to the Nations, the typical organization loses an estimated 5 percent of revenue to fraud each year, the median loss per case was $145,000, and cases ran a median of 12 months before being detected. More than half of cases traced to either a lack of internal controls or an override of the controls that existed.
That last finding is the one that matters most at small scale, because it describes exactly the situation a growing business is in: controls have not been built yet, or one person is trusted enough to bypass them. Neither is negligence. Both are how a company with eight people naturally operates until someone decides otherwise.
The Threats That Actually Happen
Five schemes account for nearly everything a small employer will realistically face. Two come from outside, three from inside, and the countermeasures differ accordingly.
Notice the split in the right-hand column. Outsider attacks target a person, using email to make a fraudulent request look routine, and are stopped by verification procedures. Insider fraud exploits a process, using the absence of a second pair of eyes, and is stopped by separation of duties and review. Investing entirely in one category leaves the other wide open, which is the most common structural mistake in small-business payroll security.
Direct Deposit Diversion: The Highest-Value Fix
If you do one thing after reading this, do this one. It is the attack with the best ratio of loss prevented to effort required, and the control is free.
The scheme is simple. Payroll receives an email that appears to come from an employee, asking to update their direct deposit details before the next run. The tone is casual and the timing is plausible. The new account is usually a prepaid card, and the funds are withdrawn before anyone notices the paycheck did not arrive.
Per an FBI Internet Crime Complaint Center public service announcement, 1,053 complaints reporting this evolution of the payroll diversion scheme were filed between January 1, 2018 and June 30, 2019, with total reported losses of $8,323,354 and an average loss of $7,904 per complaint. The dollar loss from direct deposit change requests increased more than 815 percent over that period.
The stronger version of this control removes payroll from the loop entirely: employees update their own bank details through a self-service portal protected by multi-factor authentication, and payroll never processes a change based on a message at all. If your system supports employee self-service, turning it on is a security decision as much as a convenience one. The mechanics of the payment method itself are covered in the direct deposit guide.
W-2 Phishing
The second outsider attack, and the one with the worse aftermath, because it exposes every employee at once rather than diverting one paycheck.
A spoofed email appearing to come from a company executive lands with someone in payroll or HR, asking for a list of all employees and their Forms W-2. It arrives during tax season when such a request seems ordinary. One reply hands over names, addresses, and Social Security numbers for the entire workforce, which criminals use to file fraudulent tax refunds before the real employees file.
The IRS maintains dedicated reporting channels for exactly this scheme, which tells you how routine it has become. Per the IRS guidance for businesses and payroll service providers, employers that lose data should email dataloss@irs.gov with W2 Data Loss in the subject line, providing business name, EIN, contact details, a summary of how the loss occurred, and the number of employees affected, without attaching any employee personal data.
Two controls prevent it. First, a standing rule that bulk employee data is never sent by email, to anyone, including the owner. Second, telling your team explicitly that no executive will ever email asking for W-2 information, so the request itself is the red flag rather than something to be evaluated on its merits.
Insider Fraud and Ghost Employees
Less discussed than email attacks and harder to talk about, because it involves the possibility that someone you trust is stealing. The controls are not accusations. They are the things that make trust unnecessary.
Ghost employees are the classic scheme: someone on the payroll who does not work there, either invented outright or a departed employee never removed, with pay routed to an account the perpetrator controls. It requires the ability to add or retain a payee without anyone checking, which is precisely what a one-person payroll function provides.
Inflated hours and rate changes are subtler and more common. Extra hours added to a timesheet, overtime that was never worked, or a pay rate nudged upward. Each instance is small enough to look like an error if caught, which is what makes the scheme durable.
The detection method for all of these is the same and takes fifteen minutes: compare the payroll register against your actual roster, name by name, every quarter. Anyone being paid who should not be shows up immediately. Then check that pay rates match what was approved, and look at any overtime against the approvals. The deeper version of this exercise is covered in the payroll audit guide, and offboarding is where the departed-employee version gets prevented in the first place, via the offboarding checklist.
The Controls That Matter
Ordered by return on your time rather than by security-framework category. The first group closes most of the realistic risk and costs nothing.
The honest assessment: if you only ever do the first group, you have addressed the majority of what actually happens to businesses your size. Multi-factor authentication and a verification rule for bank changes between them close both high-value outsider attacks. The second and third groups are what turn a set of good habits into something that survives staff changes and growth.
One item deserves emphasis because it is invisible until it matters: removing payroll access when someone leaves. Access lists drift constantly, and an ex-employee or ex-contractor with live credentials is a risk that grows with every departure. Attaching deprovisioning to your IT offboarding checklist is what makes it happen reliably rather than when someone remembers.
Separation of Duties on a Tiny Team
The standard advice here is useless at small scale, so here is the version that works when you have eight people and one of them does everything administrative.
The reason this matters more than it sounds is the ACFE finding cited earlier: most fraud traces to missing controls or overridden ones. At a small company the control is usually missing rather than overridden, simply because nobody built it. Building the minimum version costs one review step per pay run.
What to Look For in Payroll Software
Your software choice handles the technical layer you cannot build yourself. Five features carry most of the weight, and they are worth checking before you buy rather than after.
| Feature | What it does | Why it matters at your size |
|---|---|---|
| Multi-factor authentication | Requires a second factor beyond the password to sign in | Stolen credentials are the most common way into any system; this makes a stolen password insufficient on its own |
| Role-based access control | Limits what each user can see and change based on their role | Lets you give someone the access their job needs without exposing every salary and Social Security number in the company |
| Audit logging | Records who changed what and when, permanently | Makes changes attributable, which is both a deterrent and the only way to reconstruct what happened after an incident |
| Employee self-service | Employees update their own bank details and addresses | Removes the email-request attack path entirely, because payroll never processes a change from a message |
| Independent security certification | A third party has audited the provider's security controls | You cannot audit a vendor yourself; a recognized certification is the practical substitute |
The last row is the closest thing to a shortcut available to a small employer. You have no realistic way to evaluate a vendor's internal security posture, so a recognized independent audit standing behind it is what you have instead. Ask for it during evaluation; a provider that cannot produce anything is telling you something. The wider software question is covered in the HR technology guide, and where payroll data lives alongside everything else in the HR document management guide.
Remote and Hybrid Payroll Processing
Payroll used to be run from one machine in one office. Now it is frequently run from a kitchen table, and the assumptions built into older security advice no longer hold.
Four things change. The network is not yours, and home routers are patched less often than office equipment. The device may be personal, shared with family and running whatever software the household installed. Public Wi-Fi becomes a possibility for someone processing payroll from a coffee shop. And screens are visible to people who should not be seeing salary data.
The mini-policy is short enough to fit in an email: payroll is processed on a company-managed device or a personal device that is password-protected and up to date, never over public Wi-Fi, always with multi-factor authentication enabled, and never with payroll data downloaded to the local machine. That last point does the most work, because data that stays in the system cannot be lost with the laptop. The wider set of remote working practices is in the remote work guide.
If It Happens: The First Hour
Almost no small-business guide covers this, and it is the part you will need under pressure, when reading calmly is not an option. Print it or save it somewhere findable.
Two points about the sequence. The bank comes first because recovery of diverted funds depends almost entirely on how fast the transfer is flagged, and the window closes in hours. Telling employees comes early, not after you have finished investigating, because they need to act on their own behalf and the delay is what turns a data incident into a trust problem.
Worth noting what is not on the list: figuring out who is at fault. That question matters later and helps nothing in the first hour. The employee who replied to a convincing spoofed email did what the attack was designed to make them do, and treating it as a personal failure makes the next person hesitate to report, which is a far more expensive outcome.
Quick Self-Check
Six questions. Any no is a specific thing to fix this week rather than a general concern.
None of this requires security expertise. It requires deciding who can do what, verifying changes that move money, and looking at the payroll register four times a year. How this fits into running payroll generally is in the running payroll guide, and the wider compliance picture in the payroll compliance guide.
Frequently Asked Questions
What is payroll security?
Payroll security is the set of controls, processes, and technologies a business uses to protect payroll data and payroll funds from theft, fraud, and unauthorized access. It covers two distinct risks: outsiders trying to redirect payments or steal employee data, and insiders exploiting weak internal controls to pay themselves more than they are owed. For a small business it comes down to controlling who can access payroll, verifying changes to bank details, and reviewing what was actually paid against what should have been paid.
How do you keep payroll data secure?
Five controls cover most of the realistic risk. Turn on multi-factor authentication for payroll and email accounts. Set role-based access so people can only see what their job requires. Verify any request to change bank details through a second channel, never by email alone. Stop emailing files that contain Social Security numbers and use a self-service portal instead. And review who has payroll access every quarter, since access lists drift as people change roles and leave.
What is payroll fraud?
Payroll fraud is the manipulation of a payroll system to obtain money the perpetrator is not entitled to. The common schemes are ghost employees, where someone who does not work at the company remains on payroll; falsified hours or overtime; unauthorized changes to pay rates; expense reimbursement abuse; and direct deposit diversion, where bank details are changed so pay goes to an account the fraudster controls. Some schemes are run by insiders and some by outsiders using email deception.
How common is payroll fraud at small businesses?
Occupational fraud generally is significant: per the Association of Certified Fraud Examiners' 2024 Report to the Nations, the typical organization loses an estimated 5 percent of revenue to fraud each year, the median loss per case was $145,000, and cases ran a median of 12 months before detection. Smaller organizations are disproportionately affected because they have fewer internal controls. The ACFE also found that more than half of cases traced to either a lack of internal controls or an override of the controls that existed.
What is payroll diversion fraud?
Payroll diversion is a form of business email compromise in which a criminal sends payroll or HR an email that appears to come from an employee, requesting a change to their direct deposit details before the next pay run. The new account is typically a prepaid card, and the money is withdrawn quickly. Per an FBI Internet Crime Complaint Center advisory, 1,053 complaints reporting this scheme were filed between January 2018 and June 2019 with reported losses of $8,323,354, and the dollar loss of direct deposit change requests rose more than 815 percent over that period.
How do I stop direct deposit change fraud?
Require verification through a second channel for every bank detail change, without exception. If the request arrives by email, confirm it by phone using a number you already have on file, not a number supplied in the message. Better still, require employees to make the change themselves in a self-service portal secured with multi-factor authentication, so payroll never processes a change based on a message at all. This single control costs nothing and closes the highest-loss attack path against small employers.
What is the W-2 phishing scam?
A criminal spoofs an email to look as though it came from a company executive and sends it to someone in payroll or HR, asking for a list of all employees and their Forms W-2. A single reply exposes names, addresses, and Social Security numbers for the entire workforce, which is then used to file fraudulent tax refunds. The IRS maintains reporting channels specifically for this: businesses that lose data should email dataloss@irs.gov, and the scam email itself should be sent to phishing@irs.gov.
Do I need an IT department to secure payroll?
No. The controls that eliminate most small-business payroll risk are administrative rather than technical: multi-factor authentication, role-based access, a verification rule for bank changes, removing access when people leave, and a quarterly review of who is on the payroll. Choosing payroll or HR software that provides access controls and audit logs handles the technical layer for you. What you cannot outsource is the decision about who is allowed to do what, and the discipline of actually reviewing it.
How often should I audit payroll?
A light review every quarter and a deeper one annually works for most small businesses. The quarterly review compares the payroll register against your actual roster to catch anyone being paid who should not be, checks bank detail changes made since the last review, and re-checks the access list. The annual review goes further into pay rates, overtime patterns, and reconciliation against tax filings. The point of the quarterly cadence is that fraud detected in three months costs dramatically less than fraud detected in a year.
What should I do if payroll data is breached?
Move fast, because recovery depends on speed. Contact your bank immediately if funds were diverted. File a complaint with the FBI at ic3.gov. If W-2 or Social Security data was exposed, notify the IRS at dataloss@irs.gov with the subject line W2 Data Loss, including your business name, EIN, contact details, a summary of the incident, and the number of employees affected, but no employee personal data. Tell affected employees the same day, reset credentials, and check your state's breach notification requirements.