Categories
Cyber Security

How to Prevent Business Email Compromise

Learn how to prevent business email compromise with practical checks, staff habits and email controls that protect payments, data and daily operations.

A finance manager receives an email from the managing director asking for an urgent supplier payment. The wording is familiar, the signature looks right and the request arrives just before close of business. One detail has changed: the sender’s account has been compromised, or the address differs by a single character.

Knowing how to prevent business email compromise means preparing for this exact moment. Business email compromise, often shortened to BEC, is not always a technical attack that triggers an obvious warning. It is a confidence trick aimed at people, processes and the everyday pressure to act quickly. For a UK business, the consequences can include misdirected payments, payroll fraud, exposed client data, disrupted operations and difficult conversations with customers or regulators.

The most effective protection combines sensible technology with clear financial controls and staff who know they are allowed to pause and check. That approach gives leaders one less thing to worry about without expecting every employee to become a cybersecurity specialist.

What business email compromise looks like

BEC attacks exploit trusted relationships. Criminals may impersonate a director, supplier, solicitor, customer or colleague. In more serious cases, they gain access to a genuine mailbox using stolen credentials and read email conversations before sending a convincing request at the right time.

A common example is invoice fraud. The attacker monitors correspondence with a supplier, then sends amended bank details shortly before an expected payment. Other attacks target payroll teams with requests to change an employee’s bank account, or persuade staff to buy gift cards and send the codes. Professional services firms may be targeted for client funds or sensitive documents, while logistics businesses can be pressured by time-sensitive delivery and supplier requests.

The message may not contain malware or an obviously malicious link. That is why spam filtering alone cannot solve the problem. If the request appears to come from a genuine account, the decision-making process around it becomes the final line of defence.

How to prevent business email compromise with layered controls

No single product or policy prevents every BEC attempt. The practical answer is to create layers that make impersonation harder, restrict an attacker’s access and stop a single email from authorising a financial or data-sensitive action.

Make payment verification independent of email

Your payment process should assume that bank detail changes and unusual payment requests could be fraudulent, even when they arrive from a familiar contact. Do not verify a change by replying to the same email thread or using a telephone number supplied in the message. Instead, call a known contact using a number held in your records or on the supplier’s established website.

For significant payments, require a second person to approve the transaction. This should be a meaningful check, not a quick confirmation between two people who are both working from the same suspicious email. Set clear thresholds for dual approval and ensure cover arrangements apply during holidays, busy periods and absences.

It can feel slower than approving an urgent request immediately. However, a short verification call is considerably less disruptive than trying to recover a payment once funds have left the account. The right level of control depends on your payment volumes and operational needs, but no organisation should allow bank detail changes to be approved by email alone.

Protect Microsoft 365 accounts properly

A compromised Microsoft 365 account gives a criminal valuable context: names, invoices, meeting arrangements and writing styles. Strong, unique passwords remain essential, but they are not enough on their own.

Multi-factor authentication should be enabled for all users, with particular attention to directors, finance teams, administrators and anyone with access to sensitive client data. Where possible, use phishing-resistant methods such as authenticator app number matching or security keys rather than relying solely on text messages. Text-message codes are better than no second factor, but they can be vulnerable to social engineering and number takeover attacks.

Also review who has administrator privileges. Staff should only have the access needed for their role, and dormant accounts should be removed promptly. Conditional access rules can add another useful layer by challenging unexpected sign-ins, blocking high-risk access and reducing exposure from unmanaged devices. These controls need careful configuration, especially for organisations with travelling or remote-working staff, so security does not become a barrier to legitimate work.

Secure your email domain and watch for lookalikes

Email authentication helps receiving systems assess whether a message genuinely came from your domain. SPF, DKIM and DMARC work together to reduce the chance that criminals can spoof your business name and send convincing messages to customers or colleagues.

Configuration matters. An incomplete or overly permissive setup can give a false sense of security, while a strict policy applied without preparation may affect legitimate messages sent by third-party systems. Start by identifying every approved sender, monitor the results, then move towards a policy that rejects unauthorised use of your domain.

It is also worth registering alerts for domains that closely resemble your business name. Criminals often use small substitutions that staff may miss at a glance, particularly on mobile devices. Good email protection can flag suspicious display names, unusual sender patterns and impersonation attempts before they reach the inbox.

Check for the quiet signs of account takeover

When a mailbox is compromised, attackers often create inbox rules to hide replies, forward messages externally or move warnings into deleted folders. These rules can give them time to continue a conversation unnoticed.

Your IT team or managed provider should monitor for unusual sign-ins, impossible travel, unexpected forwarding rules and changes to authentication settings. Regularly review mailbox delegation and shared mailbox permissions too. A former employee, an unnecessary external forward or an overlooked administrator account can become an avoidable route into the business.

Endpoint protection and secure web browsing controls are part of this picture. Credential theft often begins when someone enters their details on a convincing fake Microsoft 365 sign-in page. Blocking known malicious sites and detecting suspicious activity on devices reduces the chance that a stolen password becomes a compromised mailbox.

Give staff a simple, repeatable response

Awareness training is most useful when it reflects the decisions people actually make at work. A generic annual presentation will not prepare someone to challenge an email that appears to come from their managing director at 4.45pm on a Friday.

Teach staff to slow down when a request involves money, bank details, passwords, sensitive files, gift cards or a change in normal process. Urgency, secrecy and authority are common pressure tactics. A request such as “I need this dealt with privately” should prompt verification, not compliance.

Employees should feel confident reporting a suspicious email without worrying that they are wasting IT’s time. Make reporting easy through a clear button, mailbox or helpdesk route, and explain what happens next. Quick reporting can protect more than one person: an email sent to a single finance colleague may have reached several others.

Targeted phishing simulations can help teams practise safely, provided they are used constructively. The aim is to improve recognition and reporting, not to embarrass people. Look for patterns in results, such as recurring supplier impersonation attempts or users struggling with credential prompts, then tailor training to the risk.

Prepare for the moment something gets through

Even well-managed organisations can face a convincing attack. A short, tested incident process prevents confusion when time matters.

If someone suspects they have responded to a fraudulent request, changed bank details or entered credentials into a suspicious site, they should report it immediately. The priority is to contain the issue: reset credentials, revoke active sessions, check mailbox rules, review account activity and block malicious senders or domains. If a payment has been made, contact the bank without delay and provide the details required for its fraud response process.

Preserve the suspicious email and relevant records rather than deleting everything straight away. Your IT support team will need headers, timestamps, affected accounts and details of what was shared or approved. Where personal data may be involved, assess your reporting responsibilities promptly. Regulated organisations should ensure their incident process aligns with their wider compliance and data protection obligations.

Put ownership behind the controls

Business email compromise prevention is often weakened by unclear ownership. Finance may own payment approvals, IT may manage email security and HR may oversee payroll changes, but the gaps between those responsibilities are where attackers succeed.

Assign named owners for payment controls, Microsoft 365 security, supplier verification and staff awareness. Review the arrangement after a near miss, a supplier change or a significant change in how people work. For many small and medium-sized businesses, outsourced monitoring and practical support can be the sensible option, particularly where there is no internal IT team available to investigate suspicious account activity.

The goal is not to make every transaction difficult. It is to make high-risk requests deliberately harder to complete without an independent check. When staff have clear rules, reliable technology and responsive human support behind them, they can protect the business while getting on with the work that keeps it moving.