Join our Newsletter — 33% off our NHI Course
Home› FAQ› Cyber Security› How should organisations reduce the risk of BEC…
Cyber Security

How should organisations reduce the risk of BEC payroll diversion scams in payroll operations?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 25, 2026 Domain: Cyber Security

Security teams should combine detection, user awareness, and process controls. Inspect all messages, not just executive mailboxes, because payroll diversion often targets HR and payroll staff rather than VIPs. Add warning tags for suspicious requests, train employees on social engineering cues, and restrict public exposure of payroll procedures so attackers have less context for convincing changes.

Why BEC payroll diversion succeeds in payroll operations

payroll diversion scams work because the attacker does not need to break the payroll system first. They only need to persuade staff to change a payment destination, reroute a file, or approve an exception. That makes the weak point the business process around payroll, especially where changes can be requested by email and acted on quickly.

The highest-risk moments are usually small process gaps: a rushed change window, a single approver, a casual exception, or a team member who has not seen a well-formed impersonation request before. The scam becomes easier when payroll procedures are visible publicly, because attackers can mirror the language, timing, and approval path that employees expect.

Because the target is often HR or payroll rather than executives, organisations should assume the attacker is mapping the workflow, not just the inbox. The practical question is whether a request can move money without a second, independent check on the requestor, the destination account, and the business reason.

Controls that reduce diversion opportunities

Effective reduction is usually layered: spot suspicious requests early, make impersonation less believable, and make fraudulent changes harder to execute. That means warning banners or tags for externally sourced payment-change requests, staff training focused on social engineering cues, and tighter handling of payroll process details that would help an attacker craft a convincing message.

Process control matters as much as awareness. Payroll change requests should be treated as high-risk events, with callback verification or another out-of-band confirmation for bank detail changes, new payees, or urgent exceptions. Where possible, require two-person approval for sensitive payroll changes so one compromised mailbox or one hurried employee cannot complete the diversion alone.

Public exposure should also be reduced. If an attacker can find the payroll calendar, naming conventions, escalation routes, or typical exception language, they can write with more credibility. Limiting what is posted externally makes it harder for the scam to feel legitimate, and it also reduces the chance that a spoofed request will match the organisation’s actual workflow.

How to make payroll diversion harder to complete

The most resilient payroll operations assume some messages will look plausible. The control objective is not to identify every spoof, but to stop a single deceptive request from becoming a payment instruction. That requires verifying who is asking, what changed, and whether the request fits the normal payroll path before any downstream action occurs.

A useful rule is to separate convenience from authority. Email can initiate a request, but it should not be the sole authority to change payment details. When the process can be completed from one inbox, one approval, or one shared inbox thread, the organisation has made the scam too efficient for the attacker.

Payroll teams should also review whether exceptions are overused. Fast-track handling is attractive to attackers because it creates urgency and reduces scrutiny. If urgent payments, last-minute employee changes, or manual overrides are common, the organisation should treat those paths as control exceptions and monitor them more closely than routine payroll runs.

Risk and Threat Considerations

Payroll diversion is a business-email-compromise problem with direct financial impact, but it also creates secondary exposure through delay, rework, employee trust, and potential privacy leakage if personal payroll data is misused. The risk increases when payroll change authority is concentrated in a small number of people or when one compromised mailbox can influence payment instructions.

Failure mechanism: The attacker impersonates a trusted sender, exploits process familiarity, and pushes a payment-change request through a channel that lacks independent verification or clear exception handling.

Impact: Funds may be redirected before the fraud is recognised, and recovery becomes harder once the payment has left the normal payroll path.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

CIS Controls v8, NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
CIS Controls v8CIS-9 — Email and Web Browser ProtectionsPays payroll BEC often arrives by email and needs mail filtering and warning signals.
CIS-14 — Security Awareness and Skills TrainingPayroll diversion relies on social engineering cues that staff must recognise.
Recommendation — Harden email handling and add controls that flag suspicious payment-change requests. Train payroll and HR staff to verify urgent bank-change requests out of band.
NIST CSF 2.0PR.AA-05 — Manage Identity Access for Users and ProcessesPayroll changes should require verified authority, not a single email request.
PR.AT-01 — Personnel are provided cybersecurity awareness and trainingStaff need role-specific awareness to detect impersonation and urgency cues.
DE.CM-09 — Personnel are trained on and follow applicable policies, processes, and proceduresProcess compliance is essential where attackers exploit payroll workflow exceptions.
Recommendation — Require independent authorization before changing payroll destination details. Deliver targeted anti-BEC training to payroll and HR teams. Monitor adherence to payroll change procedures and flag exception-driven deviations.
NIST SP 800-53 Rev 5AU-2 — Event LoggingPayroll change events need auditable records for detection and investigation.
IA-5 — Authenticator ManagementStrong account controls help reduce mailbox compromise that enables BEC.
AC-3 — Access EnforcementRestricting who can change payroll details limits fraudulent diversion paths.
Recommendation — Log payroll change requests, approvals, and destination-account edits. Manage authenticators tightly and rotate credentials that protect payroll systems. Enforce least privilege for payroll modification actions.

Practitioner Guidance

What to prioritise: Start with the payment-change workflow, not generic mailbox hygiene. Map every step that can alter a bank account, destination, or exception, then identify where email alone can still move the request forward.

What to verify: Confirm that every sensitive payroll change has an out-of-band verification step, a second approver where practical, and a clear rule for rejecting urgent requests that bypass normal payroll controls.

Common mistake: Treating payroll fraud as an awareness issue only. Training helps, but if the process still permits one deceptive message to trigger a payout change, the control design is incomplete.

Practitioner takeaway: The strongest defence is a payroll process that assumes messages can be forged, and therefore requires independent verification before any payment instruction can become real.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 25, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org