Skip to content

Home Topics Email Security Management Business email compromise

Email Security Management · Business email compromise

Advanced business email compromise (BEC): edge cases, scale, and monitoring

Short answer

At scale, business email compromise (BEC) problems come from change: new vendors, DNS edits, volume spikes, and forwarding. The fix is treating it as monitored infrastructure with owners, alerts, and a change process, not a one-time setup.

This guide assumes business email compromise (BEC) is already deployed and passing. It covers what breaks at scale and how mature teams operate it.

Edge cases that break a working setup#

  • Assuming DMARC protects against BEC from a compromised real account.
  • No out-of-band verification policy for finance.
  • Mail forwarded through mailing lists or personal forwarders, which alters headers and content.
  • Acquisitions and rebrands that introduce domains nobody audited.
  • Vendors silently changing their sending infrastructure.

Operating it as infrastructure#

  1. Assign an owner for each sending domain and each vendor relationship.
  2. Put DNS records under version control or a change-review process.
  3. Alert on authentication pass rate drops and reputation changes, not just outages.
  4. Run a quarterly audit against the setup steps below.
  5. Document runbooks for the three most common failures.

Reference: the baseline setup#

  1. Require MFA on all mailboxes and disable legacy authentication protocols.
  2. Alert on new inbox rules that forward or delete mail, a common attacker persistence step.
  3. Verify payment changes by phone using a known number, never the one in the email.
  4. Flag external mail with display names matching internal staff.

Frequently asked questions#

How is BEC different from phishing?

Phishing casts wide for credentials; BEC is targeted social engineering for money, often using a real hijacked account.

Keep reading on Business email compromise