This guide assumes business email compromise (BEC) is already deployed and passing. It covers what breaks at scale and how mature teams operate it.
Edge cases that break a working setup#
- Assuming DMARC protects against BEC from a compromised real account.
- No out-of-band verification policy for finance.
- Mail forwarded through mailing lists or personal forwarders, which alters headers and content.
- Acquisitions and rebrands that introduce domains nobody audited.
- Vendors silently changing their sending infrastructure.
Operating it as infrastructure#
- Assign an owner for each sending domain and each vendor relationship.
- Put DNS records under version control or a change-review process.
- Alert on authentication pass rate drops and reputation changes, not just outages.
- Run a quarterly audit against the setup steps below.
- Document runbooks for the three most common failures.
Reference: the baseline setup#
- Require MFA on all mailboxes and disable legacy authentication protocols.
- Alert on new inbox rules that forward or delete mail, a common attacker persistence step.
- Verify payment changes by phone using a known number, never the one in the email.
- Flag external mail with display names matching internal staff.
Frequently asked questions#
How is BEC different from phishing?
Phishing casts wide for credentials; BEC is targeted social engineering for money, often using a real hijacked account.