Skip to content

Home Topics Email Security Management Business email compromise

Email Security Management · Business email compromise

Business email compromise (BEC) checklist for 2026

Short answer

A complete business email compromise (BEC) checklist has 4 setup items and 2 things to audit against. Work through setup in order, then schedule a quarterly review.

Setup checklist#

  • ☐ Require MFA on all mailboxes and disable legacy authentication protocols.
  • ☐ Alert on new inbox rules that forward or delete mail, a common attacker persistence step.
  • ☐ Verify payment changes by phone using a known number, never the one in the email.
  • ☐ Flag external mail with display names matching internal staff.

Audit checklist#

  • ☐ Confirm you are not: assuming DMARC protects against BEC from a compromised real account.
  • ☐ Confirm you are not: no out-of-band verification policy for finance.

Ongoing monitoring#

  • ☐ Weekly: review provider dashboards (Postmaster Tools, SNDS) and bounce logs
  • ☐ Monthly: re-run the setup verification after any vendor or DNS change
  • ☐ Quarterly: full audit against this checklist

Frequently asked questions#

How is BEC different from phishing?

Phishing casts wide for credentials; BEC is targeted social engineering for money, often using a real hijacked account.

Keep reading on Business email compromise