Perspectives

High spend deserves a high-security spend platform

Headshot of Henry BewickeHenry BewickeJuly 30, 2026
High spend deserves a high-security spend platform header image

When a company's spend volume grows, its financial risk compounds with it. More vendors means more supplier relationships that can be impersonated. More active payment credentials means more points of compromise. More employees with spending authority means more approval pathways, and more routes for fraudulent requests to pass through.

But companies rarely stay low-spend forever, and security posture rarely keeps pace with spend growth.

The FBI's 2025 Internet Crime Report documented $3.05 billion (€2.7 billion) in losses from business email compromise. These are attacks that target spend processes, not software vulnerabilities.  Meanwhile, Vendor Email Compromise, which exploits established supplier relationships to redirect payments, rose 66% in the first half of 2024 (Perception Point, 2024).

These attacks are directed specifically at the financial processes of companies with significant spend.

The attack surface you're probably not measuring

The most concrete version of this problem is the shared card. A corporate card used across multiple vendor relationships is a credential that, once compromised, exposes every transaction attached to it.

Each vendor that stores the card number extends the exposure. Each SaaS subscription activated under a shared card and never logged to IT stays live after the employee who signed it up has left. These ‘ghost cards’ which are invisible to offboarding, can still be charged and targeted as an attack vector.

Mid-market companies typically manage hundreds of active SaaS applications, a meaningful proportion of which sit outside any centralised visibility.

‘Manager approves everything’ isn't a security model

The ACFE's 2024 Report to the Nations, which covered 1,921 fraud cases across 138 countries, found that more than half of occupational fraud succeeds either because internal controls are absent (32%) or because existing controls are overridden (19%).

Manager approval of all spend is precisely the kind of control that gets overridden, whether that’s by time pressure, by volume, or the working assumption that everything usually goes through without question.

The same report found that expense fraud persists for an average of 18 months before detection and carries a median loss of $145,000.

When every transaction routes through the same checkpoint regardless of its nature, size, or risk level, the process satisfies an audit requirement while leaving the actual exposure intact.

What high-spend security looks like in practice

High-spend security requires being able to answer a lot more than simply whether approvals are happening. You need to be able to answer who can spend, how much, in which context, and with what approval path.

You need to be able to answer these questions at the point of transaction, rather than reconstructing them afterwards, because they define what the platform can and cannot prevent.

Virtual cards per vendor are the clearest structural control available. Each supplier relationship should get its own card, its own limit, its own expiry. When a subscription ends, the card is cancelled and nothing else is affected. Card-not-present fraud accounted for 71% of US payment card fraud losses in 2024 (Nilson Report, 2024). That’s where virtual cards, which prevent payment credentials from being reused across vendor contexts, come in. They account for a disproportionately small share of fraud cases relative to how widely they're used. The structural isolation does real protective work.

Use risk to weight your approval logic

Approval logic that is risk-weighted rather than uniform applies scrutiny where it's needed. A routine reimbursement within established limits routes quickly. An unfamiliar vendor, an out-of-policy category, or a transaction above the approver's delegated authority, should all route differently, to the right person, with the right context, before the payment clears.

Real-time spend visibility completes the model. Governance built on month-end reconciliation records what went wrong. But a live view of committed and actual spend, including every transaction tagged and policy-mapped as it occurs, makes anomalies visible while they can still be acted on.

Prioritise control that doesn't slow the business

The objection to stronger spend controls is almost always the same: they'll slow people down. In practice, they don't, at least not for employees that are spending within policy.

Controls built into the spend platform are invisible to the employee spending within their limits, in an approved category, with the right documentation. They surface only at the edges when there’s an unusual vendor, an out-of-policy request, an amount above the delegated threshold. That's precisely where human judgment belongs.

High-spend companies running on this model have a smaller attack surface, a spend record that reflects policy in real time, and an approval process that functions as a real form of control.

This is what many high-spend companies, that are still set up as though they were low-spend companies, are missing.

Moss is built for spend controls that are structural rather than procedural, with real-time visibility, and approval logic that scales with your business. Book a demo with our team to find out more.