Skip to main content

Cybersecurity Insight

How to reduce business email compromise risk.

Practical controls that help organisations protect email accounts, reduce impersonation and verify high-risk financial instructions.

Business email compromise can result in fraudulent payments, stolen credentials, data exposure and damage to customer trust.

Understanding the threat

What is business email compromise?

Business email compromise is a form of fraud where attackers use email accounts, impersonation or deceptive messages to manipulate employees, customers or suppliers.

The attacker may compromise a real mailbox or create a convincing imitation of a trusted address. The message may then request a payment, banking-detail change, confidential document or account access.

The email may look completely legitimate.

Attackers often study normal communication, job titles, suppliers and payment processes before sending the fraudulent instruction.

Common attack methods

How business email attacks usually happen.

01

Stolen Credentials

A user enters their password into a fake login page, allowing the attacker to access the real mailbox.

02

Email Impersonation

A similar domain or display name is used to make a fraudulent message appear to come from a trusted person.

03

Mailbox Rule Abuse

Attackers create hidden forwarding or deletion rules to monitor conversations and conceal warnings.

04

Supplier Fraud

Existing invoice conversations are copied or altered to introduce fraudulent banking details.

Recommended controls

Security controls that reduce email compromise risk.

Enable multi-factor authentication

Require an additional verification method for email and cloud accounts. This reduces the value of a stolen password.

Block legacy authentication

Older authentication protocols may not support modern security controls and should be disabled where they are not required.

Configure SPF, DKIM and DMARC

Email-domain authentication helps receiving servers identify which systems are authorised to send mail for the domain.

Monitor suspicious sign-ins

Review alerts for unusual locations, unfamiliar devices, impossible travel and repeated failed login attempts.

Limit administrative access

Administrative privileges should be assigned only where required and protected with stronger controls.

Train employees regularly

Staff should know how to recognise urgent payment requests, unexpected login pages and suspicious attachments.

Financial controls

Verify banking and payment instructions separately.

Email security alone cannot eliminate every risk. Financial and operational procedures must also prevent one fraudulent message from authorising a payment.

Recommended payment-verification checklist

  • Confirm banking-detail changes using a known telephone number.
  • Do not use contact details supplied only in the change-request email.
  • Require dual approval for high-value or unusual payments.
  • Review the sender domain carefully for small spelling differences.
  • Treat urgency and secrecy as warning signs.
  • Record who verified the instruction and how.

A banking-detail change should never be approved solely because the email appears to come from a known supplier or manager.

User awareness

Warning signs employees should recognise.

Unexpected Urgency

Pressure to act immediately without normal verification.

Banking Changes

A request to pay into a new or unfamiliar account.

Unusual Secrecy

Instructions not to discuss the request with colleagues.

Unexpected Login Links

A request to sign in through an unfamiliar page.

Incident response

What to do when compromise is suspected.

01

Reset the password

Change the affected account password from a trusted device.

02

Revoke active sessions

Force sign-out from existing sessions and connected applications.

03

Review mailbox rules

Remove unknown forwarding, deletion or redirection rules.

04

Review sign-in activity

Identify suspicious locations, devices and authentication events.

05

Notify affected parties

Warn relevant employees, customers and suppliers about fraudulent messages.

06

Contact financial institutions

If payment fraud occurred, immediately contact the relevant bank and follow formal reporting procedures.

Respond immediately.

Delays may allow attackers to continue using the mailbox, hide evidence or target more contacts.

Final recommendation

Combine technical security with business process.

The strongest defence combines identity security, email authentication, monitoring, employee awareness and independent financial verification.

Organisations should review these controls regularly and update their response procedures as systems, users and suppliers change.

Improve your email security

Need help protecting your organisation’s email?

Speak to a Security Specialist Call 010 226 9219