Security teams should combine sender authentication, attachment controls, and user awareness. Enforce SPF, DKIM, and DMARC, quarantine or detonate risky file types, and block unexpected IMG, ISO, and CAB attachments where possible. Pair that with phishing training that focuses on business email compromise cues, because attackers often exploit plausible project language, trusted brands, and urgency to bypass careful but busy employees.
How spoofed business email campaigns succeed
spear phishing works because the message often looks operationally normal: a familiar sender pattern, a realistic project thread, and an attachment that appears to match the work context. The control problem is not just blocking obvious malicious mail, it is reducing the attacker’s ability to borrow trust from routine business communication and to land payloads in a mailbox, inbox preview, or file handler.
Defence starts with the email channel itself. Sender authentication reduces impersonation risk, but it is only effective when organisations actually enforce it and treat failures as suspicious, not as nuisance noise. Attachment handling is the other half of the problem, because malicious documents and archive formats are frequently used to shift execution into a less inspected path, especially when the payload is disguised as a quote, invoice, brief, or internal memo.
Operationally, the strongest programmes pair protocol controls with mailbox and endpoint inspection. That means checking whether suspicious files are quarantined, detonated, or blocked before a user can open them, and making sure the policy is tuned for the attachment types attackers really use in business email compromise rather than for generic malware alone.
Controls that materially raise the cost of the attack
Business email spoofing is most effective when trust is assumed too early. SPF, DKIM, and DMARC help distinguish authorised sending infrastructure from unauthorised senders, but they do not eliminate phishing by themselves. They work best as part of a layered email trust model that also includes anti-spoofing rejection, lookalike-domain monitoring, and mailbox rules that flag unusual sender, reply-to, or routing behaviour.
Attachment controls should be driven by what the organisation can safely inspect and what it should never receive in routine business exchange. Files that commonly carry code or hidden content, including ISO and CAB archives, should be blocked where business need does not justify them. When such files are permitted, they need detonation or equivalent sandbox inspection, plus endpoint controls that prevent a single open from becoming silent execution.
- Prefer policy that blocks the highest-risk attachment families by default, then grant exceptions only for documented business workflows.
- Treat a passed authentication check as one signal, not proof of legitimacy, because attackers can still abuse compromised or trusted accounts.
- Use routing and quarantine logic to slow delivery of messages that combine urgency, external origin, and attachment delivery in the same thread.
For background on adversarial email and identity abuse patterns, see NHI Mgmt Group’s Ultimate Guide to Non-Human Identities, which includes attack-surface and credential risk data that helps frame broader compromise pathways. For incident-driven context on phishing and credential abuse, compare Poland Military Breach and MailChimp Breach.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK address the attack and risk surface, while CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| CIS Controls v8 | CIS 9 — Email and Web Browser Protections | Stops phishing delivery and risky attachments at the mail edge. |
| CIS 8 — Audit Log Management | Supports detection of spoofing, quarantine events, and suspicious mailbox activity. | |
| CIS 17 — Incident Response Management | Phishing campaigns need rehearsed response for containment, reporting, and recovery. | |
| Recommendation — Harden email controls to filter spoofed messages and detonate suspicious attachments before user access. Centralise email and endpoint logs to spot phishing delivery and post-click abuse quickly. Define and rehearse phishing triage, containment, and reset procedures for suspected compromise. | ||
| NIST CSF 2.0 | PR.AC — Identity Management, Authentication and Access Control | Sender authentication and mailbox trust controls reduce spoofing success. |
| DE.CM — Continuous Monitoring | Monitoring is needed to detect suspicious mail patterns and attachment abuse. | |
| RS.MI — Incident Mitigation | Phishing campaigns require rapid containment after a malicious message is delivered or opened. | |
| Recommendation — Apply authentication and access controls that limit unauthorised email impersonation. Monitor mail flow and endpoint events for spoofing, quarantine, and detonated attachment activity. Contain suspected phishing quickly by isolating affected mailboxes, hosts, and credentials. | ||
| MITRE ATT&CK | T1566 — Phishing | The question is directly about spear phishing delivery and malicious attachments. |
| T1204 — User Execution | Malicious attachments depend on user interaction to trigger payloads. | |
| Recommendation — Map observed lure and attachment activity to phishing techniques and tune detections accordingly. Hunt for user-execution conditions that enable attachment-based payload delivery. | ||
Practitioner Guidance
What to prioritise: Put strongest friction in front of the exact path the attacker needs, message authenticity, risky attachment delivery, and rapid user action. If you only improve user awareness but leave spoofing and attachment execution paths open, you are still depending on perfect human judgment under time pressure.
What to verify: Confirm that spoofed mail is actually rejected or quarantined, not merely tagged, and that your attachment policy covers the formats attackers use to hide code or redirect execution. A good test is whether a crafted business-email lure with an ISO or CAB attachment would be stopped before the user can interact with it.
Common mistake: Treating “looks internal” as a meaningful trust signal. The more credible the pretext, the more your team should assume that urgency and familiarity are being used to suppress scrutiny, so controls must fail closed before the user makes a judgment call.
Practitioner takeaway: The best defence is not a single filter, it is layered resistance that stops unauthorised senders, contains risky file types, and gives users less opportunity to be rushed into opening an attachment that should never have arrived.
Related resources from NHI Mgmt Group
- How should security teams defend against phishing campaigns that use malicious attachments to deliver persistence mechanisms and staged malware?
- How should security teams defend against TOAD phishing campaigns that use phone callbacks?
- How should security teams defend against spear phishing in environments where attackers use generative AI to personalise lures?
- How should security teams defend against phishing campaigns that use open redirects and CAPTCHA pages to hide the final payload?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 20, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org