Business email compromise is the type of attack that your EDR doesn’t detect, your spam filter doesn’t flag, and your SOC doesn’t receive an alert about. There’s no attachment, no malicious link, and no unusual connection. It contains a request that seems legitimate: the right tone, the right timing, and references to ongoing projects. The FBI’s 2025 Internet Crime Report paints a stark picture. Business email compromise caused $3.05 billion in reported losses, compared to $32.3 million for ransomware. That’s nearly a hundred times as much, with a fraction of the attention and virtually no security budget.
Why Your Tooling Is Structurally Blind in This Area
The NCSC succinctly describes the core problem: because these are not mass-sent spam or phishing messages, it is difficult for spam filters to detect BEC messages. An attacker does not send ten thousand emails, but just one—addressed to the accounts payable department—written after spending days monitoring a compromised email account.
That makes business email compromise a detection problem that can’t be solved simply by purchasing a solution. The red flags aren’t in the message itself but in the surrounding context: a supplier who suddenly provides a different account number after three years, an executive who requests confidentiality, or a payment request that falls just outside the usual procedure. Only a person with knowledge of the process can spot these.
The Dutch figures underscore the urgency of the situation. According to the NCSC, the average cost of a BEC attack is approximately 118,000 euros per incident, and 79 percent of small and medium-sized businesses face an attempt every week. Incident responders cited in that article reported losses ranging from 750,000 euros to more than 4 million.
Three variants that require different checks
Business email compromise is a general term for attacks that are quite different from one another in terms of how they are carried out. The first type of business email compromise comes from the top down: someone impersonates a CEO and pressures an employee in the finance department to quickly transfer a sum of money. The safeguard against this is organizational, not technical, because the employee is doing exactly what they believe their boss is asking them to do.
The second type of business email compromise originates from outside the organization. An attacker impersonates a supplier from whom you are expecting an invoice, using the same letterhead and a modified account number. There is only one reliable way to verify this: verify any change in bank details by phone, using a number from your own records—not the one provided in the email.
The third type of business email compromise is the compromised mailbox, and it is the most dangerous. The attacker does not send emails from a fake domain but from the actual account of a colleague, supplier, or customer. Authentication checks do not trigger an alert because the email is technically completely legitimate. Only behavioral analysis of the account itself—such as unusual login locations, new forwarding rules, or suspicious OAuth authorizations—can uncover this.
The detection chain extends into finance, not just security
This is the organizational crux of the matter. With virtually every other type of attack, the security team detects the incident and notifies the business. With business email compromise, it’s the other way around: the first person to notice something is an accounts payable employee who thinks an invoice looks suspicious. If that employee has no way to contact security—or thinks it’s not worth the trouble—the chain of response stops there.
An effective framework for combating business email compromise establishes three key elements. The Finance department is provided with a clear reporting procedure for suspicious payment cases, with the explicit message that delaying a payment is never a problem, whereas making an incorrect payment is. The Security department is tasked with assessing every report within an hour to determine whether an account has been compromised—not just based on the email itself. And both parties agree that a blocked legitimate payment is not an error but a successful security check.
That last point is crucial. In organizations where holding up a legitimate invoice is seen as a blunder, no one reports anything after the first time. This is the same dynamic we described in the context of effective security processes: the process only works if the person carrying it out isn’t held accountable for it.
Four checks that make the biggest difference
To combat business email compromise, the NCSC lists two measures that can be implemented without a budget and prevent the majority of the damage. The four-eyes principle for payments ensures that a single employee cannot make a harmful decision under pressure. Verifying changes to bank account numbers by phone is simple and highly effective, provided the number comes from the company’s own records.
This includes two technical checks that you can require your IT service provider to perform. Impersonation protection in the email environment blocks similar-looking domains. Monitoring for suspicious logins, new forwarding rules, and OAuth applications detects a compromised email account before it is exploited. The NCSC explicitly advises small and medium-sized businesses to ask their MSSP about these measures, including the disabling of legacy authentication.
What you’re buying here is time, and in the case of business email compromise, time is literally money. The FBI reports that in 2025, the Recovery Asset Team managed to freeze more than $679 million out of $1.16 billion in attempted theft across 3,900 cases—a success rate of 58 percent. That chance exists only if the incident is reported within a few hours. Anyone who doesn’t discover that something is wrong until a week later can write off the money, as our analysis of the true cost of a cyber incident also shows.
The skills this requires from your team
Investigating business email compromise is like the work of an analyst—but without the usual leads. There’s no hash to look up and no IP address to block. What is available, however, are email headers that reveal the actual route, audit logs that show when a particular account logged in from where, and forwarding rules that someone has quietly set up. This type of analysis can be learned and is at the heart of the SOC T1 + T2 Analyst training program, where teams learn to work in a structured manner, moving from an initial indicator to a well-founded conclusion.
If the investigation continues—for example, because an email account was found to have been compromised for weeks—the SOC T3 Analyst training program comes into play for conducting an independent investigation into the full scope of the incident. And because a BEC case almost always results in a police report or an insurance claim, the quality of the evidence matters; the Cyber Forensics Expert training program focuses on securing evidence that will hold up in court later on.
The non-technical side is just as important—if not more so—and is most often overlooked. Employees in finance, procurement, and executive administration are the target audience for this attack, not the IT department. Targeted cyber awareness training tailored specifically to those roles is more effective than an organization-wide campaign, because the scenarios align with the work they do every day. We explained why generic awareness falls short in our article “Why Security Awareness Training Doesn’t Work.”
Training at the Moment of Decision-Making
Knowing about business email compromise is not the same as being able to resist it. Virtually everyone who falls victim was aware of the phenomenon. The difference lies in the moment: Thursday afternoon, four pending tasks, a request from the CEO who is going on vacation tomorrow. Under those circumstances, routine trumps knowledge.
That’s why practicing business email compromise works better than just explaining it. A short session in which finance and security teams work through three realistic scenarios together reveals, within an hour, where the procedure breaks down and who doesn’t feel empowered to say no. That’s the same logic behind our playbook for incident response exercises, and the reason why we prioritize simulations over training courses when it comes to performing under pressure.
A session like this can be kept small. Two hours, the relevant finance staff, someone from security, and three scenarios: a changed account number for an existing supplier, an urgent payment on behalf of management, and an invoice sent from the actual address of a known business contact. Afterward, don’t evaluate who fell for it, but rather which step in the procedure was missing. For organizations that want to build this capability more broadly, our article on cybersecurity boot camps for businesses explains when an intensive team program is worthwhile and when it isn’t.
Measuring and Anchoring
Three metrics show whether you have business email compromise under control. The number of quarterly reports from the finance department indicates whether the reporting process is effective. The turnaround time from report to assessment shows whether security can handle the process. And the percentage of payments with a changed account number that have been verified by phone shows whether the verification is actually being carried out rather than just described. Our article on meaningful cybersecurity KPIs explains how to set up such metrics without falling into the trap of meaningless numbers.
Smaller organizations sometimes think this is beyond their capabilities, but it is precisely SMEs that are vulnerable due to short chains of command and informal decision-making—exactly as the NCSC points out. Our article on building cybersecurity on a small budget explains how to set priorities with limited resources, and for sectors with high volumes of payment transactions, we outlined the specific requirements in “Cybersecurity in the Financial Sector.”
The common thread is that business email compromise isn’t solved with a product, but with trained people in the right place within the process—the same conclusion as in structurally improving information security. The page for employers explains how to build that capacity using your current staff, ranging from short, targeted training to a comprehensive in-company program. You’ll find the level overview for all training programs, including the comprehensive Cyber Security Specialist program for employees advancing to a security role.
Would you like to test how your organization responds to a credible but fraudulent payment request? Check out the upcoming start dates or schedule an introductory meeting to discuss the options.



