Subscribe to the Non-Human & AI Identity Journal
Home FAQ Cyber Security Why does business email compromise need identity telemetry…
Cyber Security

Why does business email compromise need identity telemetry as well as email logs?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated August 1, 2026 Domain: Cyber Security

BEC often begins with account compromise, but the fraud happens through legitimate mailbox actions. Identity telemetry shows who authenticated and from where, while email logs show what the account did next. Joining the two helps teams distinguish ordinary workflow from malicious persistence and diversion.

Why This Matters for Security Teams

business email compromise is rarely just an email problem. The attack usually starts with stolen credentials, session hijacking, or consent abuse, then shifts into legitimate-looking mailbox activity such as forwarding rules, invoice edits, or reply-chain fraud. Email logs show the message trail, but identity telemetry reveals the authentication context, device posture, location, and sign-in anomalies that explain why the mailbox became trustworthy to the attacker. That distinction matters because response decisions change once compromise, not just suspicious content, is confirmed. NIST SP 800-53 Rev. 5 helps frame this as a combined logging, access control, and monitoring problem, not a single-control issue. NIST SP 800-53 Rev 5 Security and Privacy Controls

Teams that rely only on email alerts often miss the earliest abuse signal: a normal-looking login from an unusual network, followed by mailbox rule creation and covert diversion. Identity telemetry also helps separate a genuine travelling executive from an attacker using a valid session token. In practice, many security teams encounter the fraud only after payment instructions have already been altered or internal trust has already been weaponised.

How It Works in Practice

Effective BEC detection requires stitching identity events and mailbox events into one timeline. Identity telemetry typically includes interactive sign-ins, MFA challenges, impossible travel, token issuance, device compliance, and privileged session activity. Email telemetry adds inbox rule changes, suspicious forwarding, new delegation grants, message impersonation, mass downloads, and outbound replies that match known payment workflows. On their own, each data source is incomplete. Together, they show the sequence from access to abuse.

Operationally, analysts should look for identity-first indicators that explain why a mailbox is suddenly acting differently, then validate that against email-side behaviour. For example, a successful sign-in from a new device followed by creation of an inbox rule that hides replies is more meaningful than either event alone. A mailbox that sends a wire-transfer request after a fresh MFA reset deserves more attention than one that merely receives a suspicious attachment. MITRE ATT&CK is useful here because BEC often combines credential access, valid accounts, and mail collection techniques, while identity telemetry exposes the supporting access layer. MITRE ATT&CK

  • Correlate sign-in risk with mailbox rule creation and forwarding changes.
  • Track impossible travel, unfamiliar devices, and token reuse before trusting email content.
  • Alert on new delegation, auto-forwarding, and external recipient patterns in high-value mailboxes.
  • Preserve the timeline so responders can see whether authentication preceded manipulation or vice versa.

This approach also supports triage at scale: help desks can confirm whether a reset restored control, while investigators can decide whether to revoke sessions, remove mailbox rules, or search for lateral fraud in related accounts. Current guidance suggests that the strongest detections combine identity, email, and collaboration telemetry rather than trying to infer compromise from message content alone. These controls tend to break down in federated, multi-tenant environments because identity logs and mailbox events are often owned by different teams and collected at different retention intervals.

Common Variations and Edge Cases

Tighter correlation between identity and email telemetry often increases logging, storage, and analyst workload, requiring organisations to balance faster fraud detection against operational noise. That tradeoff becomes more pronounced when remote work, bring-your-own-device access, or legacy mail systems introduce legitimate sign-ins that look unusual on paper. Best practice is evolving, but the core principle is stable: if identity evidence is missing, email findings are easy to misread.

There are a few edge cases where the standard answer needs adjustment. In consent-phishing scenarios, the attacker may never need a password, so identity telemetry may show a clean sign-in while the mail activity is entirely malicious. In token theft cases, the mailbox can appear authenticated without an obvious MFA prompt, making session telemetry more important than password telemetry. In managed service or executive-assistant workflows, delegation and shared access can resemble abuse unless role boundaries are explicitly documented. Anthropic’s report on AI-orchestrated espionage is a reminder that automation can scale the speed of these abuse chains, even when the initial access pattern still looks like ordinary user activity. Anthropic — first AI-orchestrated cyber espionage campaign report

The practical rule is to trust neither log source in isolation. Identity telemetry explains access legitimacy; email telemetry explains post-access intent. Where organisations lack unified retention, common timestamps, and shared investigation playbooks, BEC investigations become slower and attribution becomes weaker.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK and OWASP Agentic AI Top 10 address the attack and risk surface, while NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0DE.AECorrelating identity and email activity improves anomaly detection for mailbox abuse.
NIST SP 800-53 Rev 5AU-2BEC analysis depends on event logging across identity and email systems.
MITRE ATT&CKT1078BEC commonly abuses valid accounts after initial access is gained.
OWASP Agentic AI Top 10Automation can amplify fraud workflows and speed up mailbox abuse patterns.

Build detections that join sign-in anomalies with mailbox actions before treating an event as routine.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on August 1, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org