Organisations should require a second verification step for any urgent payment, wire transfer, or sensitive request that arrives by email. Staff should pause when messages bypass normal approval paths, use confidentiality pressure, or demand quick action. The safest control is to verify the request through an independent channel, then follow internal authorization procedures before any money moves.
Why BEC Requests Fail When Email Is Treated as Approval
business email compromise succeeds when the message is treated as an instruction rather than a claim that still needs verification. The control point is not the email itself, but whether the request can survive an independent check against known authority, known process, and known context before any payment or account action is taken.
That means the organisation should define email as a notification channel, not a final authorization path. When an urgent request arrives, the deciding question is whether the request can be confirmed through a separate channel and reconciled with the normal approval chain before staff act.
What Verification Has to Prove Before Money Moves
Verification should establish three things: the requester is genuine, the instruction is expected, and the transaction is permitted under internal controls. A legitimate urgent request still needs a callback, ticket, or other out-of-band confirmation that is independent of the original message thread.
Good verification also checks for process drift. If the message asks people to bypass standard review, change payment details, or create secrecy around the request, that is a sign the request must be held until normal authorization is completed. The safest pattern is to make the second check mandatory for high-risk requests, not optional for suspicious ones.
- Use an independent channel that the attacker cannot control through the compromised mailbox.
- Require confirmation from a pre-registered approver or known contact path.
- Keep payment, banking, and vendor-change requests inside normal approval workflows.
- Escalate any request that pressures staff to ignore routine controls.
Why BEC is an Authorization Problem, Not Just an Email Problem
Business email compromise is often framed as social engineering, but the operational failure is usually weak authorization discipline. If email can trigger a transfer, a bank detail change, or a sensitive exception without a second control, then the request path is too permissive. Identity proof alone is not enough when the decision itself is high impact.
That is why verification and authorization have to be paired. One person receiving a believable message should not be sufficient to move funds or approve a sensitive change. The control should force a separate decision point that is hard to spoof through the same communication channel.
Risk and Threat Considerations
When organisations let urgent email requests bypass verification, they create a direct path from mailbox compromise or impersonation to financial loss. Attackers often rely on pressure, urgency, and confidentiality demands because those cues make staff skip the second check that would otherwise stop the transfer.
Failure mechanism: The attacker either controls the sender account or convincingly impersonates a trusted party, then pushes the target to approve outside normal channels before the request is independently confirmed.
Impact: Funds can be transferred to the wrong account, payment details can be altered, and the organisation may lose both money and recovery time while trying to reverse an authorised-looking action.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK addresses the attack and risk surface, while NIST SP 800-53 Rev 5, CIS Controls v8 and OWASP ASVS set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | IA-5 — Authenticator Management | Controls the credential and approval step behind high-risk request handling. |
| AC-6 — Least Privilege | Limits who can approve or execute payment-related actions after email requests. | |
| Recommendation — Require independent verification before authorising any urgent transfer or sensitive change. Restrict approval and execution rights to the smallest set of authorised roles. | ||
| CIS Controls v8 | CIS-6 — Access Control Management | Supports restricting and reviewing who can approve business-critical actions. |
| Recommendation — Define and review approval paths so email cannot bypass authorised control gates. | ||
| OWASP ASVS | V8 — Authorization | Maps to ensuring sensitive actions require proper authorization, not just a received email. |
| Recommendation — Enforce explicit authorization checks before processing sensitive requests. | ||
| MITRE ATT&CK | T1566 — Phishing | BEC commonly uses email impersonation and deception to trigger unsafe action. |
| Recommendation — Detect and train against phishing-led request abuse before action is taken. | ||
Practitioner Guidance
What to verify: For every urgent payment or sensitive change, verify the requester through a channel that is separate from the email thread and already known to the business. If the request cannot be confirmed quickly, hold it rather than treating delay as a failure.
What good looks like: Staff can explain which requests always require second-step confirmation, who can approve them, and which channel is considered authoritative for each request type. The process should be routine enough that urgency does not weaken it.
Common mistake: Teams often rely on “recognising” the sender or checking for spelling errors, but BEC often succeeds even when the email looks polished. The control is the verification path, not the visual quality of the message.
Practitioner takeaway: The strongest defence is to make high-risk requests impossible to execute from email alone, because a request that can move money without an independent check is already too trusted.
Related resources from NHI Mgmt Group
- What breaks when organisations rely only on email authenticity checks to stop business email compromise?
- What happens when organisations rely on secure email gateways alone to stop business email compromise?
- How should organisations reduce business email compromise risk when attackers use generative AI?
- How should organisations reduce business email compromise risk without relying only on awareness training?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 27, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org