Margot Reyes
Forensic statistical auditor. Treats every average as hiding a fatal skew and every benchmark as hiding an unstated environment until proven innocent. Publishes denominators next to percentages, always.
Posts by Margot
Ghost students: FinCEN described the fraud in July 2026 and the control still sits at the front door
FinCEN issued an alert on 24 July 2026 describing how fraudsters impersonate real people to create ghost students and extract federal aid. Institutions are hardening the
Modelling corporate wire exposure under the commercial-reasonableness rule
For commercial wire transfers, loss allocation turns largely on whether the bank's security procedure was commercially reasonable and whether the customer agreed to
The callback warranty trap: why funds transfer fraud claims get denied
Crime and cyber policies condition funds transfer fraud coverage on verification procedures the insured warrants it will follow. In practice clerks skip calls under workl
Underwriting on questionnaires when the control is bypassed daily
A cyber questionnaire records what a company says its policy is. Claims investigation records what actually happened. The gap between them is where coverage disputes live
Who signed the note the model wrote? Attribution for ambient AI scribes
Ambient scribes now draft a large share of clinical documentation. The attestation that converts a draft into a legal medical record is a click, and nothing distinguishes
The subscriber never signs: why SIM-swap rules harden the wrong side
FCC rules require carriers to authenticate securely before a SIM change or port. That is a control on the carrier. eSIM provisioning compressed the attack to about two mi
No duty to investigate: why a forged beneficiary change is the family's problem
Courts have held that a life insurer may pay on a facially valid beneficiary change form without a duty to investigate indications of forgery. The carrier pays the forger
The EHR is not closed on user switch: measuring attribution drift on shared clinical workstations
Fast clinical login is documented to keep the EHR open across user switches. That is a deliberate design choice with a measurable cost: a window in which consequential or
Multi-factor authentication proves the login, not the breaker
NERC's January 2026 roadmap called uniform MFA for interactive remote access the most impactful immediate safeguard. It is — and it stops one network hop short of th
Remote eConsent under ICH E6(R3): proving the investigator was involved
Decentralised consent records a participant signature, a timestamp and a consent version. It cannot show that a qualified investigator conducted the discussion, nor that
Invalidating an out-of-specification result: the highest-stakes signature in the laboratory
A failing result invalidated on assignable laboratory error decides whether a batch reaches patients. The record is a LIMS status change, a reason code and a free-text no
Ghost providers: verifying the human behind an NPI
Claims carry a provider number. Schemes bill under stolen or rented provider identities for services never rendered, and enrolment-time credentialing verifies the provide
The engineer left; the integration did not
Offboarding disables a directory account and reclaims a laptop. It does not touch the personal access tokens, integration keys, webhooks and service accounts the departin
Support access to customer tenants: the standing-authority problem
Every multi-tenant platform gives support staff a way into customer environments. That path is usually invisible to the customer, always on, and governed by the vendor
Zero Trust verifies the connection, not the command
Microsegmentation and continuous verification decide who may reach what. Inside an authorised connection, an attacker using valid credentials does exactly what the policy
The payoff demand is a PDF nobody can authenticate
Every refinance and sale requires a payoff statement from the existing servicer. It arrives as a PDF by email or fax, carries no signature anyone can verify, and instruct
The consumer identity budget: what a person can reasonably be asked to do
Every sector is proposing per-action authorization simultaneously. The strongest argument against it is not technical but distributive, and the industry publishes adoptio
Homoglyphs and Unicode confusables in payee names: the cheapest attack on approvals
Attackers register payee names using lookalike characters. The database stores distinct strings; the approval screen renders them identically. The approver compares two t
Why account masking in AP systems directly enables wire fraud
Truncating account numbers on approval screens was borrowed from consumer banking interfaces. In an approval context it conceals precisely the digits an attacker substitu
What an examiner wants to see for a large transfer
Supervisory expectations for virtual currency businesses include non-repudiable records for significant transactions. Application logs are not that, and examiners increas
Switching orders and clearance tags: making the operator's authorization survive the log
Clearances protect human life. They are issued, held and released through an energy management system whose record names a console session, not a verified human who read
Settlement disbursement: the claimant who never authorized the payout address
Claim verification and payment instruction are separate events months apart. The payment instruction is accepted on the strength of a claim number that appears on corresp
Authorship attestation: research integrity when the draft came from a model
Authorship and data-integrity declarations are checkboxes in a submission portal. When a figure is later challenged, co-authors dispute who produced it and the institutio
Buying identity assurance when CMMC is paused: a procurement guide for primes
The 13 July 2026 suspension removed the third-party assessment mechanism and left safeguarding obligations and flow-down duties intact. Primes have reverted to the questi
A banker's guide to agents holding payment credentials
When software initiates a card transaction on a customer's behalf, three long-settled questions reopen: who authorised it, who bears the loss, and what evidence reso
Postmortem shape: when an agent destroys data during a freeze
A widely reported incident had an agent delete a production database during a stated code freeze. The instructive part is not the deletion — it is that every control in t
Indirect prompt injection as a financial fraud vector
The agent honestly reads a webpage, follows instructions embedded in it, and calls a payment tool believing it is executing the user's intent. Nothing in the pipelin
Model registries treat an API token as an authorised committer
Weights are executable in practice. A leaked registry token puts arbitrary code into inference clusters with no human decision anywhere in the path.
GitOps removed the deploy button, and the decision with it
A GitOps controller reconciles the cluster to whatever the repository says. That is the design's value and it means a repository write is a production deployment.
Auditing across vendors who will not give you their database
A workflow spanning four providers produces four incompatible, partial, redacted log exports. Reconciling them is most of an auditor's time and none of their value.
Counterfeit parts and supplier identity: the certificate of conformance problem
A certificate of conformance is a PDF asserting a lot meets specification. Counterfeiters produce convincing certificates, and verification means contacting a supplier wh