Today, Internet fraud occurs more and more frequently, and its devastating effects for organisations, such as banks, as well as their clients constitutes a continuous nightmare for all parties concerned. With regard to criminal and civil liability of the bank as well as that of the customers, the role the Information Security Policy plays in an organisation, and the possibly binding force of information security policies, it is clear that unless the organisation takes all the necessary steps to educate its clients, it stands a risk of paying hefty damages for loss of money online. Keywords