Join our Newsletter — 33% off our NHI Course
Home› FAQ› Threats, Abuse & Incident Response› Why do smaller organisations often face higher business…
Threats, Abuse & Incident Response

Why do smaller organisations often face higher business email compromise rates than large enterprises?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 27, 2026 Domain: Threats, Abuse & Incident Response

Smaller organisations often have fewer layers of approval, less specialised security staffing, and more concentrated trust relationships, which makes targeted impersonation easier to exploit. Attackers also focus on roles like finance and executives because a believable request can produce direct payment or access outcomes. The lesson is that BEC risk is driven by decision points, not just company size.

Why smaller organisations are easier BEC targets

business email compromise succeeds when an attacker can find a believable requester, a trusted recipient, and a payment or access path that moves quickly. Smaller organisations often have tighter decision chains, fewer verification steps, and less specialised monitoring, so an impersonation campaign can reach a real outcome with fewer obstacles than it would in a large enterprise.

The practical difference is not just headcount, it is control depth. In a smaller firm, one inbox may sit close to finance approval, vendor change requests, and executive communication, which reduces the number of chances for a suspicious request to be challenged before action is taken.

That also means the attacker does not need to compromise the whole company to succeed. A single convincing message, a spoofed vendor invoice, or a fake executive instruction can be enough if the organisation depends on a small number of people to recognise fraud and stop it.

Where the trust model breaks down

Smaller organisations usually rely on informal trust signals such as familiar names, routine payment patterns, and “we know this supplier” judgment. Those signals are efficient, but they are also easy for an attacker to imitate with domain spoofing, lookalike accounts, mailbox takeover, or a well-timed urgent request.

This is why BEC often targets finance, accounts payable, payroll, and executives. Those roles can approve or trigger an action without needing broad system access, so the attacker is aiming at a decision point rather than a technical perimeter. The weaker the separation between request, review, and release, the easier it is to convert persuasion into loss.

Identity and email controls still matter here because they shape how trust is established. Organisations that enforce email authentication, payment verification, and least-privilege access reduce the number of pathways an impersonator can exploit, and resources like Email Identity and BEC Guide are useful because they connect message authenticity to payment verification in one control model.

Why scale helps larger enterprises absorb BEC pressure

Large enterprises are not immune to BEC, but they often have more built-in friction: segregated duties, layered approvals, security operations support, centralised identity controls, and better logging around payment and mailbox activity. Those layers do not stop every attack, yet they increase the number of places where an impostor can be challenged, detected, or delayed.

Larger organisations also tend to have dedicated fraud, IAM, and SOC functions that can spot patterns across many employees and vendors. That wider visibility makes it harder for one attacker-controlled request to blend into normal operations, especially when unusual payment destinations, new beneficiaries, or mailbox-rule changes are monitored.

For smaller organisations, the challenge is that equivalent protection is often implemented by a few people wearing multiple hats. Good controls can still exist, but they are more likely to be manual, inconsistent, or dependent on personal judgement, which gives BEC campaigns more room to succeed.

Risk and Threat Considerations

Smaller organisations face a concentration risk: if one trusted inbox, one finance approver, or one executive assistant is tricked, the attacker may reach the only approval path that matters. That makes the issue less about company size and more about how much authority sits behind a small number of human decisions.

Failure mechanism: The attacker abuses a concentrated trust relationship, such as invoice approval, bank-detail change, or urgent executive instruction, and turns a believable message into an authorised action before independent verification occurs.

Impact: The result can be direct fraud, payment diversion, credential capture, mailbox takeover, or a foothold for further identity abuse if the same communication channel is reused for access or reset workflows.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP API Security Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AA-05 — Least PrivilegeSmaller firms reduce BEC blast radius by limiting who can approve or release sensitive actions.
Recommendation — Restrict payment and mailbox-change authority to the minimum set of roles.
NIST SP 800-53 Rev 5IA-2 — Identification and Authentication (Organizational Users)BEC often succeeds by impersonating users whose identity is trusted in business workflows.
Recommendation — Require strong authentication for users who can trigger financial or access changes.
OWASP API Security Top 10API5 — Broken Function Level AuthorizationBEC is a function-authorization problem when a message can trigger an action without proper approval.
Recommendation — Validate that only explicitly authorised roles can invoke high-impact business actions.
CIS Controls v8CIS-6 — Access Control ManagementAccess governance limits who can act on requests that BEC attackers try to exploit.
Recommendation — Review and restrict who can approve, modify, or release sensitive transactions.
MITRE ATT&CKT1566 — PhishingBEC commonly begins with deceptive email requests that impersonate trusted senders.
Recommendation — Detect and train against phishing lures that target finance and executives.

Practitioner Guidance

What to prioritise: Focus first on the highest-value decision points, not the broadest technology stack. If a request can move money, change supplier details, reset access, or override a normal workflow, it needs a second channel of verification and a clear approval owner.

What to verify: Check whether the organisation can prove who approved a payment, who changed recipient details, and whether the verification step was independent of the email thread itself. In many smaller firms, the control gap is not detection, it is weak transaction verification.

Common mistake: Treating BEC as “an email problem” rather than a business process problem. If the downstream action is easy to authorise, an attacker only needs one believable message, not a full compromise.

Practitioner takeaway: The best BEC defence for a smaller organisation is to reduce the number of single-person trust decisions that can trigger loss, then make the remaining ones easy to verify and hard to rush.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 27, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org