Join our Newsletter — 33% off our NHI Course
Home› FAQ› Threats, Abuse & Incident Response› Why do business email compromise attacks create outsized…
Threats, Abuse & Incident Response

Why do business email compromise attacks create outsized risk even when only a small share of employees reply?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 25, 2026 Domain: Threats, Abuse & Incident Response

Business email compromise is dangerous because attackers need only one successful reply to progress, while defenders must catch every attempt. Even a low reply rate can produce enough footholds for fraud, credential theft, or follow on impersonation. When employees also fail to report most attacks, security teams lose the chance to warn others and remove related messages quickly.

Why a tiny reply rate can still create a large fraud surface

business email compromise is a volume game for the attacker, not a precision game. Even if only a small fraction of people respond, the attacker still gets enough openings to move a payment request, redirect a supplier, or steer a conversation into a higher-value fraud path. The asymmetry is structural, because defenders must stop every attempt while the attacker only needs one successful thread to matter.

The real issue is not just who replies, but what a reply unlocks. A single interaction can confirm a live mailbox, validate naming conventions, expose reporting habits, or create the trust needed for a second message that looks more credible than the first. That is why low engagement can still convert into outsized impact, especially when campaigns are broad and repetitive.

That asymmetry is reinforced by The 52 NHI Breaches Report, which shows how stolen credentials and impersonation can turn one successful foothold into broader compromise. It also aligns with TruffleNet BEC Attack, Stolen AWS Credentials, where credential abuse supported a wider business email compromise campaign.

Why non-reporting makes the exposure worse

Low reply rates are only part of the picture. If employees do not report suspected phishing quickly, security teams lose visibility into the active campaign, cannot warn the rest of the organisation, and may miss the chance to remove matching messages before another person opens them. In practice, that means the attacker can continue testing variants of the same lure against a live population.

Reporting speed matters because BEC campaigns often succeed through repetition and adaptation. Once attackers see which wording, sender pattern, or payment scenario draws a response, they can refine the next message. A weak reporting culture therefore increases dwell time for the campaign itself, even when the first-stage response rate looks modest.

That is one reason incident handling guidance from CISA cyber threat advisories remains useful here, since early notification and rapid containment are central to limiting spread. For teams that need a broader attack-chain view, MITRE ATT&CK Enterprise Matrix helps map where email compromise turns into credential access, privilege escalation, or lateral movement.

Why the downstream loss can be disproportionate to the initial engagement rate

BEC usually pays off through second-order effects. A single reply can lead to invoice rerouting, gift card fraud, payroll diversion, credential harvesting, or a conversation that is later used for impersonation of finance, procurement, or executive staff. The monetary loss often comes from the quality of the follow-on process, not from the first message itself.

This is why BEC should be treated as a trust exploitation problem as much as a spam problem. The attacker is trying to borrow organisational legitimacy from a real sender relationship, then convert that borrowed trust into an action that would normally be hard to obtain. Once that happens, the cost of one successful reply can exceed the cost of many failed attempts by a wide margin.

For teams working from formal control language, NIST Cybersecurity Framework 2.0 is a useful anchor for response and recovery discipline, while NIST AI Risk Management Framework is not the primary lens here but can still be helpful when email automation or AI-assisted fraud detection is part of the defensive workflow.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK addresses the attack and risk surface, while NIST CSF 2.0, CIS Controls v8, NIST SP 800-53 Rev 5 and OWASP ASVS set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
MITRE ATT&CKT1566 — PhishingBEC commonly starts with phishing-style social engineering and message delivery.
T1114 — Email CollectionBEC depends on email interception, mailbox access, or message visibility for impersonation.
Recommendation — Map BEC lures to T1566 and monitor for related delivery, execution and credential capture activity. Hunt for mailbox access, forwarding rules and suspicious message retrieval tied to BEC activity.
NIST CSF 2.0RS.CO-02 — Incidents are coordinated with internal and external stakeholders as appropriateFast reporting and coordinated response reduce the time an active BEC campaign can spread.
Recommendation — Coordinate BEC reporting and containment quickly so matching messages can be removed enterprise-wide.
CIS Controls v8CIS-17 — Incident Response ManagementBEC becomes materially worse when suspected messages are not reported and handled quickly.
Recommendation — Use incident response workflows to triage BEC reports and remove related messages rapidly.
NIST SP 800-53 Rev 5AU-6 — Audit Record Review, Analysis, and ReportingBEC response depends on reviewing email and authentication evidence to spot related activity.
Recommendation — Review and correlate email and access logs to identify related BEC activity and affected users.
OWASP ASVSV16 — Security Logging and Error HandlingThe answer hinges on detecting suspicious message and account activity before the fraud chain expands.
Recommendation — Log suspicious email and account events so BEC indicators can be detected and triaged quickly.

Practitioner Guidance

What to prioritise: Measure BEC by total organisational exposure, not by raw click or reply rate. A small percentage of replies can still be unacceptable if those replies tend to come from finance, executives, or other users who can approve payments or reveal process details.

What to verify: Confirm that reporting is fast enough to shorten the campaign window. If suspected messages are not reaching the response team within minutes, the organisation is probably measuring awareness but not containing active fraud attempts.

Common mistake: Treating low average response as low risk. BEC is often a low-frequency, high-consequence pattern, so the practical question is whether any one reply can create a material loss path before intervention begins.

Practitioner takeaway: The right control objective is not to eliminate every reply, but to make sure one reply cannot quietly turn into payment fraud, credential loss, or a wider impersonation chain.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 25, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org