TL;DR: Email remains a high-risk attack channel, and Abnormal AI’s Vision 2023 conference focused on how cybercrime and cybersecurity are changing through sessions on CISO concerns, business email compromise, and Microsoft 365 protection, with on-demand access and up to 7 ISC2 CPE credits. The core takeaway is that email governance still depends on identity controls, because attacker success often begins where authentication, trust, and user behaviour intersect.
Editorial analysis by NHI Mgmt Group, based on content published by Abnormal AI: “Vision 2023: Looking Ahead at 2023 Cyber Threats”.
Key questions
Q: How should security teams reduce business email compromise risk beyond secure email gateways?
A: They should add controls that operate after delivery and after user interaction, because BEC usually succeeds by exploiting trust and workflow, not by delivering obvious malware.
Q: Why does email still create identity risk even with strong security tools?
A: Because the attacker often does not need to defeat the toolset if they can exploit trust in the sender or the workflow.
Practitioner guidance
- Harden business email verification points Require out-of-band confirmation for payment changes, banking updates, executive requests, and other high-impact actions that arrive by email.
- Align Microsoft 365 controls with identity governance Review mailbox access, forwarding rules, MFA strength, conditional access, and privileged admin paths together rather than as separate programmes.
- Map email-driven workflows to fraud exposure Identify where email initiates spend, account changes, or data release, then add step-up checks for those workflows.
Bottom line: Business email compromise remains effective because it exploits trust in identity and workflow, not just weaknesses in mail filtering.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Email compromise is an identity failure before it is a messaging failure. Business email compromise works because organisations still let mailbox trust stand in for request trust. The real weakness is not the transport layer alone, but the gap between who can send a message and who can legitimately initiate a business action. Practitioners should treat this as a governance problem spanning authentication, verification, and process design.
A question worth separating out:
Q: How should security teams balance awareness training and process controls for BEC?
A: Use awareness training to reduce mistakes, but rely on process controls to stop the loss path. The practical answer is layered verification, segregation of duties, and callback rules for high-risk requests, because trained users can still be bypassed when attackers exploit urgency and fear.
👉 Read our full editorial: Email security and BEC threats remain a live CISO concern