TL;DR: Business email compromise still works because attackers exploit human decision-making, and AI is making those social engineering campaigns more convincing and scalable, according to Abnormal AI. The defensive shift is away from fear-based awareness alone and toward behaviour-aware controls that reduce user exposure and improve detection.
Editorial analysis by NHI Mgmt Group, based on content published by Abnormal AI: “The Human Element of BEC: What's Real, What's Hype, and What's Next”.
Key questions
Q: How should security teams reduce phishing risk when AI makes scam messages more convincing?
A: Teams should stop relying on obvious spelling mistakes and train people to verify the sender, destination, and request through a separate channel.
Q: What breaks when organisations rely on awareness training alone?
A: Training without workflow controls leaves employees responsible for detecting deception in real time, under pressure, and with limited context.
Practitioner guidance
- Tighten payment and change-request verification Require a second, out-of-band confirmation for requests that change bank details, release funds or alter recipient accounts.
- Instrument behavioural signals around approvals Monitor unusual sender-recipient patterns, time-of-day anomalies, and abrupt shifts in request type so suspicious BEC activity is visible before a user completes the action.
- Reduce fear-based awareness messaging Train staff to pause, verify and escalate uncertainty without penalty, so the organisation can surface suspicious requests instead of rewarding speed over scrutiny.
Bottom line: BEC remains effective because it exploits human judgement under pressure, not because defenders lack technical controls alone.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
BEC is a decision-control problem, not just a content-filtering problem. The article’s core claim is that the weak point is human judgement under pressure, which means email security alone cannot absorb the risk. Organisations that treat BEC as a message-recognition issue miss the fact that the decisive failure happens when a person authorises an unsafe action. The practitioner implication is to move controls closer to approval behaviour and workflow verification.
A few things that frame the scale:
- 74% of all breaches included the human element, through error, privilege misuse, stolen credentials or social engineering, according to Verizon's 2023 Data Breach Investigations Report.
A question worth separating out:
Q: What should teams do when a payment request looks legitimate but arrives unexpectedly?
A: Treat it as a verification event, not a routine transaction. Confirm the request through an independent channel, validate the business context and check whether the request fits the sender’s usual behaviour. The goal is to slow the decision just enough that urgency cannot substitute for control.
👉 Read our full editorial: Human psychology is still the weak link in BEC defence