Business Email Compromise: A Guide
Business email compromise (BEC) is a financially motivated scam in which an attacker poses as a trusted party — a vendor, executive, or colleague — to trick staff into sending money or sensitive data. It is consistently among the costliest cyber crimes reported. Here is KYND's guide to understanding and managing BEC risk.
What is business email compromise?
BEC is a targeted email scam in which an attacker impersonates someone the recipient trusts to request a payment, a change to banking details, or sensitive records. Common forms include vendor or invoice fraud, executive impersonation (“CEO fraud”), payroll diversion, and account takeover, where the attacker sends requests from a genuine compromised mailbox.
Why does BEC succeed?
Most BEC messages contain no malware or malicious links — just a plausible, plain-language request — so they can pass through email filters that catch conventional phishing. Attackers research their targets, reference real projects and invoices, and apply urgency and authority so the request feels routine rather than suspicious.
Why are public entities a target?
Public entities are unusually transparent: budgets, vendor contracts, project awards, and staff directories are often public records, giving attackers everything needed to craft a convincing invoice or payment request. Predictable payment cycles and large construction or services contracts make fraudulent wire requests easier to disguise.
What if we don't address BEC?
A successful BEC attack can redirect taxpayer funds that are rarely fully recoverable once wired. If a staff mailbox is compromised, the incident may also expose resident or employee data, triggering state breach notification duties, audit findings, and public-trust consequences beyond the direct loss.
Which frameworks should we align to?
NIST Cybersecurity Framework (CSF) 2.0 addresses BEC primarily through the Protect and Detect functions. CIS Controls v8 is more specific: Control 9 (Email and Web Browser Protections) and Control 14 (Security Awareness and Skills Training) cover the technical and human defenses that matter most.
Process defenses: verify before you pay
Require out-of-band verification — a call to a known, previously used phone number, never one from the email — before changing any vendor or payroll banking details. Apply dual approval to wires and payment changes above a set threshold, and train finance and HR staff on the specific scenarios they will face.
Technical controls that reduce BEC risk
Enforce MFA (multi-factor authentication) on all email accounts, and deploy the email authentication standards SPF, DKIM, and DMARC so it is harder to spoof your domain. Flag external emails with a visible banner, and monitor for suspicious mailbox rules such as auto-forwarding, a common sign of account takeover.
Checklist
When building or reviewing your defenses against BEC, consider the following:
- Are all changes to vendor or payroll banking details verified by phone using a known, trusted number?
- Is dual authorization required for wire transfers and payment changes above a set threshold?
- Is MFA enforced on all staff email accounts, including executives and finance?
- Are SPF, DKIM, and DMARC configured and set to an enforcement policy for your domains?
- Are external emails visibly flagged, and are mailbox auto-forwarding rules monitored?
- Do finance, payroll, and HR staff receive training on BEC scenarios at least annually?