Business email compromise (BEC) is not just a technical phishing problem. It is a fraud pattern that uses impersonation, urgency, and a believable business relationship to cause a payment, bank-detail change, payroll redirect, or data disclosure. Strong email authentication helps, but prevention also requires clear human verification rules.
Know the common patterns
An attacker may impersonate an owner asking for a rushed wire, a vendor changing payment details, an employee requesting payroll updates, or a lawyer handling a confidential transaction. They often use a lookalike domain, a compromised legitimate mailbox, or a spoofed From address. The message is designed to bypass normal skepticism with urgency and authority.
Make verification independent
Any request to change bank details, release funds, buy gift cards, or disclose sensitive information should require out-of-band verification. Call a known phone number from your internal records, not one supplied in the email. Use a second approver for material payments. A reply to the suspicious thread is not independent verification because the attacker may control that conversation.
Reduce impersonation opportunities
Enable MFA for every mailbox, remove stale forwarding rules, review administrator access, and train staff to report suspicious requests quickly. Configure SPF, DKIM, and DMARC for the business domain. See how email authentication works and how to prevent domain spoofing. These controls reduce successful impersonation but do not replace approval controls.
Build a response playbook
Define who can pause a payment, who contacts the bank, who preserves headers, and who communicates with vendors or customers. Report an attempted fraud promptly; speed matters if money or credentials were sent. Test the process with a short tabletop exercise so staff know that pausing for verification is expected, not disruptive.
Monitor the domain’s public signals
New sending services, DNS changes, and expired settings can weaken protection quietly. Keep an inventory of approved senders and review DMARC reports. Run Beacon’s free check to review SPF, DKIM, and DMARC before an impersonation attempt becomes a customer-trust problem.
Use technical controls as layers
Authentication makes direct spoofing harder, while MFA and access reviews reduce the chance an attacker can use a real mailbox. Configure alerts for unusual forwarding rules or administrator changes where your provider supports them. These layers matter because BEC often begins with one weak point and succeeds when no one verifies the next step.
Measure the process
Track suspicious-payment reports, verification exceptions, and time to escalation. The goal is not to punish staff for caution; it is to make independent verification a normal, fast business process. Revisit it after a new payment platform or finance workflow is introduced.
When a payment has been sent
Contact the bank immediately, preserve evidence, and notify the affected vendor through a known channel. Do not wait for a full technical investigation before initiating time-sensitive recovery steps.
Train for the decision point
Short, recurring training should focus on the moment money or data could leave the business: a changed bank account, urgent executive request, password-reset prompt, or supplier invoice. Staff need permission to pause and verify without fearing that they are slowing work down. Test the process with realistic but safe examples and improve the escalation path when it feels unclear.
Keep vendors in the process
Tell regular vendors how bank-detail changes will be verified and use contacts already in your records. This reduces the chance that an attacker can insert a fraudulent change through a convincing email thread. Good process makes a technical incident less likely to become a financial loss.
For the authentication foundation, review how to check a DMARC record.