Join our Newsletter — 33% off our NHI Course
Home FAQ Cyber Security How should security teams prevent business email compromise…
Cyber Security

How should security teams prevent business email compromise in finance workflows without relying on awareness training alone?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated August 24, 2026 Domain: Cyber Security

Teams should combine mandatory verification, strong identity controls, and role-specific workflow protections. High-risk requests such as wire transfers, vendor bank changes, or payroll updates should require a known second channel, dual approval, and MFA on all accounts involved. Training still matters, but it works best when paired with controls that reduce the chance a single deceptive email can trigger a loss.

Why This Matters for Security Teams

business email compromise in finance workflows is not just a phishing problem. It is a control failure that combines identity weakness, process fragility, and poor transaction verification. When an attacker can impersonate an executive, vendor, or payroll contact, the issue is rarely the message alone. It is the absence of layered approval, strong authentication, and a trusted out-of-band confirmation path. Guidance in NIST SP 800-53 Rev 5 Security and Privacy Controls supports the principle that financial workflows need procedural and technical safeguards, not just user judgment.

Security teams often overestimate the value of awareness training because it is easy to measure and easy to deploy. But finance-targeted fraud usually succeeds when a request lands at the right moment, looks routine, and is routed through a process that was never designed to resist impersonation. That is why high-risk actions such as wire transfers, supplier master changes, and payroll rerouting need verification controls that are independent of the email channel. Current AI-enabled phishing and impersonation tactics can also make messages more convincing and more scalable, as reflected in the Anthropic report on first AI-orchestrated cyber espionage campaign. In practice, many security teams encounter BEC only after a payment has already been approved through a familiar but unprotected workflow.

How It Works in Practice

Effective prevention depends on reducing the number of decisions that rely on trust in the inbox. The finance process should treat any change to payment instructions, beneficiary details, or access to payroll systems as a high-risk event. That means the request must be verified using a known second channel, approved by more than one person, and executed only from accounts with the minimum access needed.

Identity controls matter because BEC often succeeds through account takeover or impersonation of legitimate users. MFA should be enforced on all accounts that can initiate, approve, or release payments. Where possible, privileged actions should be protected with step-up authentication and time-bound access. Role design also matters: the person who creates a vendor record should not be the same person who approves payment to that vendor. This is a practical separation of duties issue, and it should be applied consistently across ERP, accounts payable, payroll, and treasury systems.

  • Require callback verification to a previously known number or internal directory entry, not the number in the suspicious email.
  • Use dual approval for wire transfers, bank detail changes, and urgent exceptions.
  • Log and alert on changes to payment destinations, approver lists, and delegation rules.
  • Bind payment workflows to strong authentication and conditional access.
  • Restrict who can create, edit, and release transactions inside finance platforms.

Automation can help, but only if it reinforces controls rather than bypassing them. Security teams should monitor for mailbox compromise, forwarding-rule abuse, and anomalous payment timing, then feed those signals into SIEM and SOAR workflows for fast containment. These controls tend to break down in decentralised finance environments with manual exception handling because urgent approvals bypass normal identity and verification steps.

Common Variations and Edge Cases

Tighter payment controls often increase friction and can slow legitimate business activity, so organisations have to balance fraud resistance against operational speed. That tradeoff becomes more visible in shared service centres, M&A activity, and seasonal payroll changes, where exceptions are frequent and staff may be under pressure to move quickly. The right answer is usually not to loosen controls, but to make exception handling explicit, logged, and independently approved.

Best practice is evolving for AI-assisted impersonation, deepfake voice calls, and multi-channel fraud. There is no universal standard for this yet, but current guidance suggests treating any request that changes financial destination data as high risk regardless of whether it arrives by email, chat, or phone. Finance teams should also review vendor onboarding and bank change procedures for weak identity proofing, because a BEC case may begin long before a payment request is sent.

Where personal data and payment data intersect, privacy, retention, and audit requirements should be aligned so investigators can reconstruct the event without creating unnecessary exposure. For digital workflows that depend on identity assurance, NIST control baselines remain useful for mapping review, approval, logging, and access restrictions to practical safeguards. The safest design assumes that any single inbox, voice call, or chat thread can be forged, so the workflow itself must carry the trust signal.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0 and NIST SP 800-63 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AC-4Least-privilege limits who can initiate or approve risky finance actions.
NIST SP 800-63Identity assurance supports stronger verification for high-risk workflow actions.
OWASP Non-Human Identity Top 10NHI-3Service accounts and workflow identities can be abused in finance automation.

Use stronger identity proofing and authenticators for users who can alter financial instructions.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on August 24, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org