By NHI Mgmt Group Editorial TeamBased on Abnormal AI: “The Human Element of BEC: What's Real, What's Hype, and What's Next” (June 26, 2026)

TL;DR: Business email compromise still works because attackers exploit human decision-making, and AI is making those social engineering campaigns more convincing and scalable, according to Abnormal AI. The defensive shift is away from fear-based awareness alone and toward behaviour-aware controls that reduce user exposure and improve detection.


At a glance

What this is: This on-demand webinar argues that BEC remains a human-behaviour problem, with AI increasing the realism and scale of social engineering while behavioural AI is positioned as a detection layer.

Why it matters: IAM and security teams need to treat BEC as an identity-and-decision risk, not just an email problem, because user trust, approval habits, and detection signals all shape exposure.


Context

Business email compromise is a trust and decision-making problem before it is a mailbox problem. Attackers win when users are nudged into acting quickly, overriding normal verification steps, or authorising payments and credential changes without sufficient scrutiny.

This webinar frames the human attack surface as the central challenge and argues that AI is amplifying both persuasion quality and campaign volume. For identity and access teams, that puts behaviour, verification habits, and detection timing in the same control conversation.


Key questions

Q: How should security teams reduce phishing risk when AI makes scam messages more convincing?

A: Teams should stop relying on obvious spelling mistakes and train people to verify the sender, destination, and request through a separate channel. The better control is a combination of realistic simulations, password managers, and simple confirmation habits for urgent or payment-related messages. That reduces both click risk and downstream credential theft.

Q: What breaks when organisations rely on awareness training alone?

A: Training without workflow controls leaves employees responsible for detecting deception in real time, under pressure, and with limited context. That is not a reliable control for high-value requests. Organisations need policy, verification, and approval design that make a fake request harder to complete even when a user is uncertain.

Q: Why do normal email security controls miss many business email compromise attacks?

A: Because BEC often uses socially plausible language and trusted-looking identities rather than malware or obvious malicious attachments. That means inbox filtering can be bypassed even when the message is not technically suspicious. Detection has to look at relationship patterns, request behaviour and downstream actions, not just content reputation.

Q: What should teams do when a payment request looks legitimate but arrives unexpectedly?

A: Treat it as a verification event, not a routine transaction. Confirm the request through an independent channel, validate the business context and check whether the request fits the sender’s usual behaviour. The goal is to slow the decision just enough that urgency cannot substitute for control.


Background and context

Why human psychology drives BEC success

Business email compromise works because the attacker is not trying to break cryptography or bypass a hardened API, but to influence a person into taking an unsafe action. Social engineering exploits urgency, authority, routine and empathy, which are all normal human decision shortcuts. In IAM terms, this is a trust failure at the point of action, where the user becomes the control plane. The article’s premise is that no single employee is immune, so the variance is in how much friction, verification and monitoring the organisation adds around the decision.

Practical implication: design verification steps around the decision point, not just around the inbox.

How AI changes social engineering scale and realism

AI does not create a new attack class here, but it lowers the cost of producing personalised, believable and repeated messages at scale. That means the same psychological pressure can be delivered more consistently across many targets, with better timing and fewer linguistic tells. The result is a broader attack surface for BEC, because campaign quality is no longer constrained by attacker labour. For defenders, this shifts the problem from spotting bad grammar to spotting abnormal behaviour and unusual request patterns.

Practical implication: tune detection for behavioural anomalies and request context, not only message content.

Behavioural AI as a complementary control

Behavioural AI in this context means using patterns of normal user and mailbox activity to flag deviations that may indicate coercion, impersonation or account takeover. It is not a replacement for user training or policy, but it can surface suspicious sequences such as a sudden change in payment behaviour, atypical conversation flow or unusual sender-recipient combinations. That matters because BEC often succeeds precisely when the message itself looks plausible. Detection has to look beyond text to transaction context and identity behaviour.

Practical implication: pair user education with telemetry that can spot abnormal communication and action patterns.


NHI Mgmt Group analysis

BEC is a decision-control problem, not just a content-filtering problem. The article’s core claim is that the weak point is human judgement under pressure, which means email security alone cannot absorb the risk. Organisations that treat BEC as a message-recognition issue miss the fact that the decisive failure happens when a person authorises an unsafe action. The practitioner implication is to move controls closer to approval behaviour and workflow verification.

AI changes the economics of persuasion, not the underlying governance flaw. Human susceptibility was already enough for BEC to work; AI simply makes the same manipulation easier to personalise and repeat. That means the operating assumption that malicious messages will look obviously wrong is no longer dependable. Security teams should read this as a demand for stronger behavioural telemetry and tighter out-of-band verification, not just better awareness content.

Empathy-based security culture is a resilience control, not a soft option. The article argues that fear-based messaging is less sustainable than a culture that helps users surface doubt and seek confirmation. That is relevant because BEC thrives when users feel pressured to move quickly and silently. The more an organisation normalises escalation and verification, the more it reduces the attacker’s ability to exploit social friction. The implication is that culture design belongs in the control set.

Identity trust drift: BEC succeeds when everyday trust in a sender, relationship or request quietly expands beyond what the identity signal actually supports. As AI improves impersonation quality, that drift becomes harder to spot in routine workflows and approval chains. The practitioner conclusion is that identity governance must account for trust calibration, not only authentication strength.

From our research library:

  • 74% of all breaches included the human element, through error, privilege misuse, stolen credentials or social engineering, according to Verizon's 2023 Data Breach Investigations Report.

What this signals

Behaviour-aware controls now matter more than message inspection alone. BEC campaigns are becoming more convincing because AI can scale personalised persuasion, so organisations need controls that understand who is asking, what is being asked and whether the action fits the normal pattern. That is a governance problem as much as a detection problem.

Empathy is part of the security model. If staff expect punishment for escalating doubt, they are more likely to comply with a suspicious request under pressure. A resilient programme makes verification socially safe, because attackers depend on silence, speed and misplaced confidence.


For practitioners

  • Tighten payment and change-request verification Require a second, out-of-band confirmation for requests that change bank details, release funds or alter recipient accounts. Make the verification step routine enough that urgency does not bypass it.
  • Instrument behavioural signals around approvals Monitor unusual sender-recipient patterns, time-of-day anomalies, and abrupt shifts in request type so suspicious BEC activity is visible before a user completes the action.
  • Reduce fear-based awareness messaging Train staff to pause, verify and escalate uncertainty without penalty, so the organisation can surface suspicious requests instead of rewarding speed over scrutiny.
  • Use conversation context in detection rules Blend mailbox, identity and workflow context so a message that looks normal in isolation is still flagged when the surrounding request behaviour is abnormal.

Key takeaways

  • BEC remains effective because it exploits human judgement under pressure, not because defenders lack technical controls alone.
  • AI increases the scale and plausibility of social engineering, which raises the value of behaviour-based detection and workflow verification.
  • Organisations reduce BEC risk by normalising confirmation, instrumenting unusual request patterns and making escalation safe for employees.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK addresses the attack and risk surface, while NIST CSF 2.0, NIST SP 800-63 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
MITRE ATT&CKTA0001;TA0006 — Initial Access; Credential AccessBEC relies on initial social-engineering access and sometimes credential capture.
Recommendation — Map BEC scenarios to Initial Access and Credential Access to improve detections and response playbooks.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsApproval workflows and request validation shape who can authorise sensitive actions.
Recommendation — Review approval paths and authorisation checks for sensitive actions under PR.AA-05.
NIST SP 800-63SP 800-63B — AuthenticationHuman trust decisions are intertwined with authentication and step-up verification flows.
Recommendation — Use SP 800-63B controls to strengthen step-up verification for high-risk requests.
CIS Controls v8CIS-14 — Security Awareness and Skills TrainingThe article argues for better human response, not fear-based training alone.
Recommendation — Use CIS-14 to train staff on verification habits and reporting suspicious requests.

Key terms

  • Business email compromise: A form of social engineering where an attacker impersonates a trusted person or domain to manipulate payment, change banking details, or extract sensitive information. It often succeeds without malware because the attacker targets process trust and human judgement instead of technical controls.
  • Behavioral AI: Behavioral AI is an analytics approach that looks for meaningful deviations in activity patterns rather than relying only on static indicators or signatures. In identity and security operations, it is used to identify suspicious sequences, unusual timing, and context shifts that suggest an attacker is adapting faster than conventional controls.
  • Out-Of-Band Verification: A confirmation step that uses a different channel or method than the original request. It reduces the chance that a single spoofed email, voice call, or video session can authorize privileged activity or financial transfer.
  • Social Engineering: Social engineering is the use of deception, urgency, and authority to persuade a person to reveal information or take a risky action. It targets human decision-making rather than software defects, and often turns legitimate identity workflows into the attack path.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 27, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org