Join our Newsletter — 33% off our NHI Course

How should teams measure employee susceptibility to business email compromise?

Use simulations that mirror actual workflow abuse, including manager, colleague, and vendor requests that look legitimate but create false urgency or financial pressure. Measure whether employees reply, comply, escalate, or challenge the request, then use those patterns to guide targeted coaching.

What to measure when testing susceptibility

Measure susceptibility as observed behavior under realistic social pressure, not as a self-reported confidence score. The useful signal is whether people act on the request, delay it, verify it, or escalate it when the message appears to come from someone with authority or urgency. That gives you a practical view of who is most exposed to workflow-abuse style BEC.

Good simulations should reflect the organization’s real attack surface: finance requests, payroll changes, gift card or invoice pressure, vendor bank-detail updates, and executive exceptions. The closer the scenario is to normal business language, timing, and approval paths, the more likely it is to expose genuine susceptibility rather than test only obvious phishing recognition.

Teams should also separate outcome types. A reply is not the same as compliance, and compliance is not the same as successful fraud prevention. Tracking whether the employee questions the request, routes it to a second channel, or checks the payment workflow shows whether awareness has translated into a defensive habit.

Which behaviors show real vulnerability to BEC

The strongest indicators are responses that collapse verification under urgency: approving a payment change without callback verification, sharing credentials or access details to “help” the sender, or bypassing standard process because the request appears to come from a trusted manager or vendor. Those are the moments where business process, not just email content, has been compromised.

It is also useful to measure who follows the request chain versus who breaks it. Employees who pause, verify independently, or involve the right approver are demonstrating resilience. Employees who comply quickly because the tone feels plausible are showing susceptibility even if the simulation never reaches a completed fraud event.

For a practical benchmark, track patterns by role and context. Finance, executive support, operations, procurement, and help desk staff often see different lures, so a single enterprise average can hide concentration risk. The meaningful question is which workflows are most likely to fail when the message looks legitimate and the pressure is time-sensitive.

How to turn simulation results into a better control model

Use the results to map where training alone is insufficient and where process controls need to do more of the work. If people repeatedly comply with payment or vendor-change requests, the issue is not just awareness, it is weak out-of-band verification, poor approval design, or excessive trust in email as a business channel. The fix should tighten the workflow, not just add another awareness module.

Where simulation data shows repeated challenge behavior, that is a sign the control environment is working. Where it shows repeated compliance, the team should redesign the step that makes the fraud easy, for example by requiring a second-channel callback, separating request initiation from approval, or adding mandatory review for high-risk payment changes.

Good measurement also avoids vanity metrics. Completion rates for annual training are not a strong predictor of BEC resilience if employees still respond to plausible pressure. Focus on the behavior that matters: verify, escalate, delay, or comply. That produces a much better signal for coaching and control investment.

Risk and Threat Considerations

business email compromise succeeds when attackers exploit trust in routine business workflows, not when they merely send a suspicious-looking email. The real risk is that a legitimate-seeming request reaches a person who has enough authority to move money, disclose information, or reset access before the request is verified.

Failure mechanism: A simulated or real lure creates urgency, authority, or apparent familiarity, and the recipient follows the request path without an independent verification step. That breaks the control at the human decision point and allows the attacker to convert social trust into financial loss or account abuse.

Impact: The result can be fraudulent payment, vendor diversion, credential exposure, or a wider compromise if the email exchange is used to pivot into mailbox takeover or other trusted communications.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK addresses the attack and risk surface, while CIS Controls v8, NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
MITRE ATT&CK T1566 — Phishing BEC simulations test social-engineering lures that induce action through deceptive messages.
Recommendation — Map observed simulation failures to phishing techniques and tighten detection and reporting controls.
CIS Controls v8 CIS-14 — Security Awareness and Skills Training Measuring susceptibility is part of assessing whether awareness training changes user behavior.
Recommendation — Use realistic simulations to validate training and target repeat-failure workflows.
NIST CSF 2.0 PR.AT-01 — All users are informed and trained The question is about whether training and practice reduce user susceptibility to email-based fraud.
PR.AA-03 — Remote access is managed BEC often exploits trusted request paths that lead to unauthorized payment or account action.
Recommendation — Use simulation outcomes to verify whether training actually changes employee response behavior. Require verified approval paths before allowing high-risk business actions.
NIST SP 800-53 Rev 5 AT-2 — Awareness Training Simulations and targeted coaching are classic awareness-training measures for social engineering risk.
AU-6 — Audit Review, Analysis, and Reporting Behavioral outcomes from simulations should be reviewed to identify repeat failure patterns.
Recommendation — Run role-based awareness exercises that measure actual response under pressure. Analyze simulation results by role and workflow to find recurring control weaknesses.

Practitioner Guidance

What to measure: Track behavior by scenario type, not just pass/fail. The most useful breakdown is whether employees reply, comply, escalate, or verify through a second channel, because each outcome points to a different control gap.

What to prioritize: Build scenarios around the business processes most likely to carry fraud impact, especially payment changes, invoice handling, and executive or vendor requests. That gives you a truer measure of organizational exposure than generic “phishing clicks.”

Common mistake: Treating awareness scores as the control objective. For BEC, the objective is dependable verification under pressure, so the best programs measure whether the employee breaks the attack chain before money or access changes hands.

Practitioner takeaway: The most meaningful susceptibility metric is not who recognizes a fake email, it is who still verifies before acting when the request looks operationally normal and time-critical.