Join our Newsletter — 33% off our NHI Course

What are the best practices for spotting business email compromise before employees act on a message?

The most effective approach is to combine user awareness with process controls and message authentication. Train employees to pause on urgent, covert requests, verify any change in payment or routing through an out of band channel, and treat messages from personal mailboxes or mobile signatures as suspicious. Add email gateway filtering and authentication checks so spoofed identities are harder to reach the inbox.

How to spot BEC before anyone acts

business email compromise is usually caught by looking for pressure, inconsistency, and a broken verification chain. The strongest warning signs are requests that bypass normal process, especially if the sender wants secrecy, urgency, or an exception to payment or routing controls. The right goal is to slow the decision long enough for a second channel to confirm what the inbox is asking for.

Message patterns that deserve immediate scrutiny

Look first at whether the request matches the sender’s normal behavior. BEC messages often use urgent language, unusual confidentiality, a change in payment details, or a subtle shift in tone that does not fit the executive or vendor the message claims to be. A reply address that differs from display name, a personal mailbox, or a mobile signature that looks hurried can all be useful warning signals.

Formatting and process clues matter as much as wording. A message that asks for wire transfers, gift cards, payroll changes, invoice redirection, or new bank details should be treated as high risk until confirmed. If the request depends on a one-time exception, bypasses approval steps, or asks the recipient not to call the usual contact, the message should be assumed suspicious until the business process is verified.

Email authentication checks help separate a real internal sender from an impersonation attempt. SPF, DKIM, and DMARC reduce spoofing risk, but they do not stop every BEC variant, especially when an attacker has gained access to a real mailbox or is using a compromised vendor account. That is why authentication needs to sit alongside user judgment and payment verification, not replace them. See the Email Identity and BEC Guide for a deeper control model.

Why BEC succeeds even when the inbox looks normal

BEC often works because the message is socially plausible, not because it is technically sophisticated. Attackers abuse trust, timing, and routine business pressure, then wait for a hurried employee to complete the transfer or change the account details. The most dangerous messages are the ones that feel like ordinary work and therefore do not trigger suspicion.

Compromise is more likely when organizations rely on email alone as the approval channel. If a finance or operations team is allowed to act on a request without an out-of-band callback, dual approval, or a known-good contact list, the attacker only needs one convincing message. This is why BEC prevention is partly an identity problem, but it is just as much a process-control problem.

Real-world fraud shows how expensive that shortcut can be. In a widely reported 2024 case, an employee was manipulated through a deepfake video call into making a major transfer, showing that voice, video, and email can all be used together to create false legitimacy. See Arup deepfake fraud 2024 for the broader pattern of executive impersonation and payment fraud.

Practical checks that stop employees from acting too early

Use a verification step that cannot be satisfied by the same message channel. For payment changes, bank detail updates, urgent invoice requests, and executive exceptions, require a known phone number, approved chat channel, or documented callback process before action is taken. Train staff to treat “reply here only” or “do not verify” as a red flag, not a convenience.

Mailbox controls should reinforce the human check. Filtering, impersonation warnings, external sender banners, and suspicious-rule detection help catch spoofed or compromised mail before it reaches a decision-maker. If the organization also monitors for mailbox forwarding, unexpected inbox rules, or unusual login patterns, it can catch the attacker before the message is even used for fraud.

When the message involves a supplier, finance lead, or executive assistant, the best defense is a pre-approved contact path and a documented change protocol. If the request is legitimate, the business can still complete it, but the employee should never be forced to decide based only on the email thread that introduced the request.

Risk and Threat Considerations

BEC is risky because the fraud succeeds at the point of decision, not just at the point of delivery. Once an employee trusts the message, the attacker can redirect funds, alter supplier details, or establish a foothold for follow-on account abuse before security teams see any obvious alert.

Failure mechanism: The attacker combines believable social engineering with mailbox impersonation, compromised accounts, or urgent business language to bypass normal caution and trigger a fast action.

Impact: The result can be direct financial loss, fraudulent payment redirection, and a wider trust failure if staff learn that an apparently routine message can bypass controls.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5, OWASP ASVS and NIST SP 800-63 set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
NIST SP 800-53 Rev 5 IA-2 — Identification and Authentication (Organizational Users) BEC depends on impersonation and compromised inbox access.
IA-5 — Authenticator Management BEC often uses stolen or abused credentials and mailbox access tokens.
AU-6 — Audit Review, Analysis, and Reporting Suspicious mailbox rules, logins, and message actions need review.
Recommendation — Require strong user authentication to reduce mailbox takeover and sender impersonation. Rotate and revoke compromised credentials quickly, and control authenticator lifecycle tightly. Review mail and identity logs for forwarding rules, unusual access, and anomalous payment-related activity.
OWASP ASVS V10 — OAuth and OIDC Compromised mail clients and delegated mail access often rely on token-based authorization.
Recommendation — Validate delegated access and consent flows that could let a compromised account read or send mail.
NIST SP 800-63 AAL — Authenticator Assurance Level Phishing-resistant authentication reduces takeover risk in email-based fraud paths.
Recommendation — Use phishing-resistant authenticators for high-value mail and finance workflows.

Practitioner Guidance

What to verify: Focus on the decision point, not just the message content. If the email asks for a new payee, a routing change, or an exception to process, verify the request through a pre-established channel and confirm it with someone who is independently known to the business.

Common mistake: Teams often over-trust the sender name and under-check the business process. A message can be technically authentic and still be fraudulent if the mailbox is compromised or if the request itself violates normal approval behavior.

Practitioner takeaway: The most reliable BEC defense is to make email insufficient on its own for high-impact actions, so urgency cannot outrun verification.