Barakat helps banks and transaction-heavy organisations harden business email, block phishing infrastructure, test staff response, and monitor suspicious financial activity in a way that supports Sections 41-42 of Sierra Leone's Cyber Security and Crime Act, 2021, reflects the harmful-message risk addressed in Section 44, and reduces the brand and domain abuse exposure addressed in Section 45.
For organisations handling payments, customer accounts, approvals, or high-trust communications, phishing is not just a training issue. It is an operational and regulatory risk that can quickly become financial loss, customer distrust, executive embarrassment, or evidence of weak control discipline.
Section 41 of Sierra Leone's Cyber Security and Crime Act, 2021 addresses computer-related fraud where data, programs, or system functioning are manipulated dishonestly to procure economic benefit. Section 42 is especially important for financial institutions because it addresses identity theft and phishing committed by persons engaged in their services using special knowledge, and it also covers fraudulent use of electronic signatures, passwords, and other unique identification features, as well as impersonation for gain or to cause disadvantage.
Section 45 addresses cybersquatting and unauthorised use of names, trademarks, and domain names to interfere with the rightful owner, which makes domain monitoring and typo-squatting controls commercially relevant. Section 44 is broader than fraud control, but it also covers false or harmful electronic messages; in practice, that reinforces the need to reduce malicious messaging and impersonation campaigns before they damage customers, staff, or the organisation's reputation. This engagement focuses on trusted email delivery, phishing-domain blocking, staff testing, and anomaly monitoring around financial abuse.
Best suited to organisations where fraudulent payment instructions, supplier impersonation, fake login pages, privileged account abuse, or customer-facing phishing can create immediate financial and reputational damage.
Many fraud incidents still begin with a message that looks legitimate enough to trigger payment, credential entry, or account compromise. We harden the organisation's email environment so malicious messages are blocked earlier and impersonation attempts are easier to detect before staff act on them.
Even where email filtering improves, users can still reach phishing pages, fake banking portals, and other malicious destinations by clicking links or typing lookalike domains. We add DNS-layer controls so those destinations are blocked earlier and logged for follow-up.
Fraud awareness becomes more credible when it is tested against realistic scenarios instead of assumed. We run controlled simulations so management can see which teams still fall for payment scams, credential lures, and impersonation messages, and where immediate retraining is needed.
Not every fraud event starts outside the organisation. In financial environments, unusual use of privileged access, abnormal approval behaviour, and large data movement can be early indicators that deserve immediate attention. We configure monitoring so suspicious patterns surface sooner and can be reviewed before the damage grows.
Deliverables: Email security configuration, DNS filtering, quarterly phishing simulation reports, annual fraud risk assessment, and insider anomaly alert setup.
Urgency: If a fake payment request, a spoofed executive email, or abnormal insider access could still move money or sensitive customer data today, the fraud-control gap should be closed before the next incident makes it visible.
Book Anti-Fraud Review