Join our Newsletter — 33% off our NHI Course

Business email compromise: what should IAM teams actually do?

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20739
Topic starter  

TL;DR: Business email compromise was absent from the FBI’s 2013 complaint report, became the second most financially devastating crime a year later, took the top spot in 2015, and drove $2.4 billion in losses last year, according to Abnormal AI. The pattern persists because trust, approval, and payment workflows remain easier to subvert than to harden.

Editorial analysis by NHI Mgmt Group, based on content published by Abnormal AI: “The Art of the (Im)possible: Overcoming Business Email Compromise”.

Key questions

Q: What breaks when email approval is treated as business approval?

A: When email approval is treated as business approval, attackers can impersonate trusted senders and push victims straight into payment, credential, or data-transfer actions.

Q: Why do phishing and business email compromise continue to succeed even when organisations invest in awareness training?

A: Phishing succeeds because attackers exploit timing, trust, and human judgment, not just technical gaps.

Practitioner guidance

  • Separate approval from message receipt Require an independent validation step for payments, bank detail changes, and sensitive account actions before any request is executed.
  • Harden executive impersonation workflows Flag requests involving senior leaders, urgent transfers, or confidentiality pressure for mandatory out-of-band confirmation.
  • Reduce trust in reply-thread requests Treat instructions that arrive inside an existing thread as untrusted until verified against a second channel or known workflow.

Bottom line: Business email compromise succeeds by abusing trust and approval flows, not only by bypassing inbox security.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 3 days ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21474
 

Business email compromise is a governance failure in trust routing, not a mail-security problem alone. The attacker does not need to defeat every control if the organisation lets an inbox message stand in for verified authority. That is why BEC persists even as filtering and awareness improve. Practitioners should separate message delivery from business approval.

A question worth separating out:

Q: How should teams respond when a payment request comes from a trusted mailbox?

A: Treat the request as unverified until a second channel confirms both the sender and the business need. The right response is to stop the workflow, validate the request against known records, and require a separate approver. Trusted mailboxes are still common fraud entry points.

👉 Read our full editorial: Business email compromise keeps outpacing enterprise defences


This post was modified 3 days ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.