Skip to content

Home Topics Email Security Management Business email compromise

Email Security Management · Business email compromise

2 common business email compromise (BEC) mistakes and how to fix them

Short answer

The most common business email compromise (BEC) mistakes are: assuming DMARC protects against BEC from a compromised real account; no out-of-band verification policy for finance.

BEC causes more financial loss than any other cybercrime category, and it frequently passes authentication because the mailbox is real.

Mistake 1: Assuming DMARC protects against BEC from a compromised real account#

Why it hurts: this undermines business email compromise (BEC) at the point where mailbox providers make their decision, and it is rarely surfaced by your own tooling until placement drops.

Fix: Require MFA on all mailboxes and disable legacy authentication protocols.

Mistake 2: No out-of-band verification policy for finance#

Why it hurts: this undermines business email compromise (BEC) at the point where mailbox providers make their decision, and it is rarely surfaced by your own tooling until placement drops.

Fix: Alert on new inbox rules that forward or delete mail, a common attacker persistence step.

Frequently asked questions#

How is BEC different from phishing?

Phishing casts wide for credentials; BEC is targeted social engineering for money, often using a real hijacked account.

Keep reading on Business email compromise