Join our Newsletter — 33% off our NHI Course

Why do staffing shortages increase the risk from phishing and business email compromise?

Email remains one of the most heavily targeted attack paths, so thinly staffed teams have less capacity to investigate suspicious messages, tune controls, and respond quickly. When analysts are unavailable, attackers gain more time to exploit malicious links, credential theft, or impersonation. The risk is not only missed alerts, but slower remediation and weaker oversight of recurring email attack patterns.

Why staffing shortages make phishing and BEC more dangerous

Phishing and business email compromise are not only volume problems, they are time-sensitive control problems. When teams are short-staffed, suspicious messages sit longer, recurring patterns are less likely to be correlated, and compromised mailboxes or payment requests are harder to contain before an attacker can act on them.

Short staffing also reduces the quality of the “human control layer” around email. Even with filtering in place, organisations still rely on people to tune detections, review edge-case messages, validate high-risk requests, and close the loop on false negatives that signal an active campaign.

Where email identity and sender authentication matter, the best-known defensive patterns remain email authentication, mailbox protection, and payment verification discipline, as laid out in Email Identity and BEC Guide. In practice, lean teams often struggle most with the sustained follow-up these controls require, not with the initial configuration alone.

What attackers gain when defenders have less capacity

Attackers benefit from delay. If a user reports a suspicious message and no one can investigate quickly, the campaign has more time to harvest credentials, pivot into a mailbox, or redirect a payment conversation. That extra time is often the difference between a blocked attempt and a successful compromise.

Resource constraints also make impersonation easier to exploit. BEC relies on social engineering, context theft, and urgency, so if monitoring is shallow, attackers can imitate executives, suppliers, or internal finance contacts long enough to push through approvals. NHIMG’s TruffleNet BEC Attack, Stolen AWS Credentials shows how stolen credentials can support broader compromise and business email compromise, while Arup deepfake fraud 2024 shows how impersonation pressure can convert into very large financial loss when verification is weak.

Because phishing often precedes credential theft, slower investigation also means slower containment of mailbox takeover, mailbox rules abuse, and token misuse. That is why email compromise is often a chain of failures, not a single bad click, and staffing pressure weakens multiple links at once.

Which controls degrade first under staffing pressure

The first controls to erode are usually the ones that depend on repetition: reviewing alerts, hunting for lookalike sender patterns, checking inbox rule changes, escalating suspicious payment requests, and confirming that authentication controls still reflect current attack techniques. If these activities slip, the organisation may still have tools, but it loses operational assurance.

This is also why email compromise often outpaces routine security work. A team can have good policy language and still miss the practical work of following up on weak signals, such as a mailbox login from an unusual location, a newly created forwarding rule, or a message thread that suddenly changes bank details. The issue is not only prevention, but supervision.

For organisations that want a stronger benchmark on authentication and phishing resistance, NIST SP 800-63 Digital Identity Guidelines remains useful for understanding phishing-resistant authentication, while NIST SP 800-53 Rev 5 Security and Privacy Controls provides the broader control context for identification, authentication, logging, and access oversight. Those standards matter here because staffing shortages usually break execution before they break policy.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

CIS Controls v8 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
CIS Controls v8 CIS-5 — Account Management Email compromise often starts with compromised accounts and abusive inbox access.
Recommendation — Review account access and remove stale or risky email-related accounts promptly.
NIST SP 800-53 Rev 5 AU-6 — Audit Review, Analysis, and Reporting Lean teams struggle to review alerts and email compromise signals quickly.
IA-5 — Authenticator Management Phishing and BEC frequently depend on stolen credentials and weak credential handling.
AC-6 — Least Privilege Reducing mailbox and payment-path privilege limits BEC blast radius.
Recommendation — Prioritise review of email and mailbox audit events that indicate suspicious activity. Rotate and manage authenticators aggressively after suspected phishing exposure. Limit email and payment-path permissions to the minimum needed for each role.

Practitioner Guidance

What to prioritise: Protect the small set of email workflows that can create immediate financial or access impact, especially executive impersonation, invoice change requests, and mailbox rule abuse. If you cannot staff broad review, narrow the focus to the highest-loss paths first.

What to verify: Check whether suspicious-message handling has a measurable response time, not just a mailbox or ticket queue. A control that is “enabled” but routinely reviewed late is weak against BEC because attacker dwell time is the real advantage.

Common mistake: Treating phishing as a user-awareness problem alone. In shortage conditions, the real failure is usually delayed investigation, incomplete follow-through, and weak oversight of repeated patterns that should have triggered containment earlier.

Practitioner takeaway: The main risk from staffing shortages is not that phishing becomes more common, but that every defensive step after the first alert becomes slower, and that is exactly the delay BEC attackers need.