Your treasury has no two-key rule

In a Minuteman launch control centre, two officers sit at consoles several metres apart. To arm a launch, each turns a key within a two-second window. The distance is calculated so that one man alone, however determined, however well trained, cannot reach both locks. A second crew, in another centre, has to confirm.
The design dates from the early 1960s, when the Kennedy administration imposed the electronic locks known as Permissive Action Links on the American arsenal. It has never rested on the loyalty of the crews. It starts from the opposite assumption: the individual at the command post can be compromised, turned, coerced, or simply have lost his judgement that night. The system is built so that the assumption changes nothing about the outcome.
Today, in most mid-sized companies, a five million euro wire goes out on the decision of one person, under pressure from a video call.
What the rule actually locks
The two-key rule does not ask officers to be vigilant. It does not ask them to do their job well, or to follow a rigorous procedure. It makes unilateral action mechanically impossible, whatever the quality of the men involved.
That is the whole difference with an internal rule. A double sign-off procedure describes expected behaviour, and expected behaviour bends to urgency, to hierarchy, or to the absence of the second approver on a Thursday in August. An architectural constraint stays in place when everything else gives way.
Your treasury has no equivalent
Ask the question inside your own organisation, setting aside internal procedures and counting only technical constraints: how many people can trigger a movement of funds without a second factor, independent of them and beyond their reach, having to weigh in?
In the large majority of cases, the answer is one.
That architecture is the product of an organisation built on three assumptions. That the identity of a counterpart is recognisable from voice and face. That the authenticity of a message can be read from its form. That procedures will stay stable long enough to be relied upon. All three stopped being true when real-time identity synthesis became available to any motivated attacker.
Why a callback is not a second key
That is the immediate objection: we have a callback, an email confirmation, a manual double signature. Look at what those mechanisms assume.
They assume the attacker plays by the procedural rules. He does not. He supplies the confirmation channel himself. An Arup employee learned this in January 2024 in Hong Kong: he had doubted, he had refused to act on an email alone, and he was offered a video call where his chief financial officer and several colleagues, all synthetic, lifted his doubt. He then executed fifteen transfers to five accounts, totalling around 25 million dollars.
A callback that travels down a channel under the attacker’s control amounts to turning the same lock twice, with the same hand.
The test: compromise of the executor
The question to put to any financial validation system fits in one sentence: does it still work if the person executing it is himself compromised?
If your signature is enough, if your voice is enough, if your face is enough, the answer is no. The finance chief then becomes the central trust node of a system that was never designed to survive the compromise of that node. The position is uncomfortable with no negligence involved: it follows from the structure, and it is corrected at the same level.
Translating the two-key rule into a payment process takes three things. Anchoring the validation to a physical device held by an identified person. Having the second factor operated by parties independent of whoever executes the transfer. Sharing the irrefutable traces produced with the party receiving the instruction, so that it can check without calling anyone back. How Sealfie works rests on those three requirements.
What the courts are starting to ask
The law is moving the same way. UCC Article 4A allocates the loss on a fraudulent wire to the party whose security procedures were not commercially reasonable, a test about procedures that execute rather than people who were briefed. The SEC’s 2023 cybersecurity rules complete the picture by making the governance of those procedures a board-level disclosure item.
The standard under examination has changed in nature. An officer who walks in with an awareness plan and signed security policies mostly documents his hope that his teams would outperform what neuroscience allows under pressure.
The question for the next board meeting
There is an asymmetry few finance teams have internalised: the attacker needs to succeed once, you need to succeed every time. No training programme closes that gap, because the gap is structural.
The two-key rule was born from that observation. Someone understood that a loyal, competent, well-trained officer could still be coerced. The answer they built addressed the system itself, and set aside the idea of training the officers harder.
What is your two-key rule?
Size your exposure
The BEC risk calculator estimates your company’s annual incident probability and expected loss in six questions, with a published methodology and sourced coefficients. No data leaves your browser.