Join our Newsletter — 33% off our NHI Course

What are the signs that a business email compromise defence is failing?

Warning signs include unexpected payment requests, subtle changes in writing style, urgent language, new bank details, and messages that bypass normal approval chains. A failing defence also shows up as employees not reporting suspicious emails, inconsistent use of certificate-based validation, and weak monitoring of login anomalies or unusual sender behaviour. When these signals appear together, the organisation is relying on trust instead of verification.

How to read the warning signs of a failing BEC defence

A failing defence is rarely revealed by one obvious alert. It shows up when social-engineering cues, payment anomalies, and verification failures start reinforcing each other, especially when staff begin treating unusual requests as routine. The core question is not just whether a suspicious email was received, but whether the organisation still has effective challenge, confirmation, and monitoring around it.

Look for repeated signals that the organisation is losing the ability to distinguish legitimate business change from impersonation. That includes payment redirection, language that compresses time or authority, and messages that slip past the normal review path because people assume the sender is already trusted.

Why approval-chain bypass and payment changes matter

Unexpected payment requests and new bank details are high-value indicators because they show the attacker has moved from message delivery to monetisation. If those requests are reaching staff without triggering a hard stop, the defence has probably lost one of its most important control points: verifying whether the request matches the expected business process.

Subtle changes in writing style matter for a different reason. They are often the first sign that an impersonation is close, but the organisation only catches them if recipients are trained to compare context, not just content. When urgent language repeatedly succeeds, the defence is being evaluated by attackers as a path of least resistance, not a barrier.

What weak detection and reporting look like in practice

A second failure mode is silence. If suspicious emails are not being reported, or if reporting is delayed until after payment or account compromise, the detection layer is too weak to interrupt the attack chain. In that state, the organisation is relying on individual judgement rather than a visible, repeatable reporting habit.

Weak monitoring of login anomalies or unusual sender behaviour also matters because BEC is not only a mailbox problem. A defence that does not correlate login location, timing, mailbox rules, forwarding changes, and sender reputation will miss the transition from persuasive email to active account abuse. MITRE ATT&CK Enterprise Matrix is useful here because it frames credential access and lateral movement as part of the same attack chain.

What a mature BEC defence proves before it trusts a message

The strongest indicator of health is not perfect inbox filtering, but consistent verification discipline. Certificate-based validation, call-back checks, dual approval for payment changes, and independent confirmation of bank detail changes should all work together so that a single email cannot complete a high-impact business action.

When those checks are inconsistent, the organisation has created opportunities for attackers to exploit process variation. A defence can look good on paper while still failing in practice if one team verifies, another team does not, and exception handling is easier than normal compliance.

Risk and Threat Considerations

business email compromise becomes materially more dangerous when the same trust cues are allowed to drive both communication and payment. The risk is not just fraudulent transfer, but the erosion of process integrity, because repeated exceptions teach both users and attackers that the approval path can be bypassed.

Failure mechanism: Impersonation, urgency, and familiar-looking requests override verification, while weak monitoring and poor reporting let the attack proceed until funds move or account access is abused.

Impact: Organisations can suffer fraudulent payments, account takeover, reputational harm, and a broader collapse in trust in email-based business processes.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK addresses the attack and risk surface, while NIST SP 800-53 Rev 5 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
MITRE ATT&CK T1114 — Email Collection BEC begins with mailbox abuse and message interception that enables impersonation.
T1566 — Phishing BEC commonly uses social engineering to impersonate executives or vendors and solicit action.
Recommendation — Correlate suspicious email activity with mailbox access and forwarding-rule changes. Hunt for impersonation, urgency cues, and reply-chain abuse in suspicious messages.
NIST SP 800-53 Rev 5 IA-5 — Authenticator Management BEC defence depends on controlling credentials and validating access used in account abuse.
AU-6 — Audit Review, Analysis, and Reporting Failed BEC defences often show up in missed login anomalies and weak report handling.
Recommendation — Rotate and manage authenticators that could enable mailbox or payment-system compromise. Review anomaly logs and user-reported suspicious messages together for response.
CIS Controls v8 CIS-9 — Email and Web Browser Protections BEC is primarily delivered through email and relies on weak message controls.
Recommendation — Harden email protections and block look-alike sender abuse where possible.

Practitioner Guidance

What to prioritise: Treat repeated payment redirection attempts, approval bypasses, and missed suspicious-email reports as control failures, not isolated user mistakes. If those signals appear together, investigate the process gap before tuning mailbox rules or spam filtering.

What to verify: Confirm that high-risk payment and vendor-change requests require an out-of-band check that the requester cannot satisfy alone. Also verify that login-anomaly monitoring, sender-behaviour monitoring, and certificate validation are actually being reviewed, not merely enabled.

Common mistake: Organisations often overestimate the value of email hygiene training and underestimate the importance of enforcing a hard verification step for financial or banking changes. If the process still allows speed to beat confirmation, the defence remains fragile.

Practitioner takeaway: A BEC defence is failing when trust becomes the default control. The deciding test is whether the organisation can still force independent verification before money moves or access changes.