TL;DR: Up to 44% of vendor email compromise messages trigger a reply or forward, with engagement climbing higher in the largest enterprises, according to Abnormal AI, underscoring how routine-looking social engineering still bypasses human judgment and reporting discipline. The practical issue is not awareness alone but whether identity, process, and detection controls can interrupt action before trust turns into exposure.
Editorial analysis by NHI Mgmt Group, based on content published by Abnormal AI: “Cybersecurity Awareness in Action: How 44% of VEC Attacks Engage Employees”.
Key questions
Q: How should security teams reduce business email compromise risk beyond secure email gateways?
A: They should add controls that operate after delivery and after user interaction, because BEC usually succeeds by exploiting trust and workflow, not by delivering obvious malware.
Q: Why do familiar-looking BEC and VEC emails still lead to action?
A: They work because the attacker exploits routine, urgency, and pre-existing trust in vendor communication.
Practitioner guidance
- Strengthen vendor verification workflows Require callback or secondary-channel confirmation for any payment change, bank detail update, or sensitive vendor request before action is taken.
- Instrument response-to-reporting metrics Track how often suspicious emails are replied to, forwarded, or escalated before they are reported so you can see where trust is turning into exposure.
- Deploy behavior-based email detection Use contextual signals such as sender-recipient history, request type, and unusual timing to flag messages that look legitimate but deviate from normal business behavior.
Bottom line: BEC and VEC remain effective because attackers exploit trust already embedded in normal business communication.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
BEC and VEC are now identity control problems, not just email hygiene problems: The article’s central finding is that familiar-looking messages still produce action at meaningful rates, which means the weak point is the trust boundary around a human identity, not only the inbox. In practice, email verification, vendor callback procedures, and behavioural monitoring must be treated as part of access governance. The practitioner conclusion is simple: if a request can move a person into action without independent validation, it is already inside the control gap.
A question worth separating out:
Q: What should teams do when BEC or VEC targets finance and procurement roles?
A: Prioritise those roles for contextual training, stricter approval checks, and behaviour-based detection because they sit closest to payment and vendor-change decisions. The issue is not just awareness. It is whether the workflow forces verification before the request can become a financial action.
👉 Read our full editorial: Human trust still powers BEC and VEC engagement at scale