INSIGHT / EMAIL SECURITY
Phishing and Business Email Compromise: How to Defend Your Organisation
How phishing and business email compromise work, the technical controls that stop them and the procedures that protect payments.
Business email compromise (BEC) is fraud carried out through email: an attacker impersonates an executive, supplier or client, or takes over a real mailbox, and persuades someone to change payment details or send funds. It succeeds because it exploits routine and trust rather than software flaws, which is why a combination of technical controls and verification procedures is needed.
01How the attacks unfold
Many attacks begin with a phishing message that harvests a password, after which the attacker quietly reads mail, learns who pays whom and when, and creates inbox rules to hide replies. Weeks later, they send a convincing request to alter bank details on a genuine invoice. Others skip compromise and simply spoof a name or register a look-alike domain. Knowing the chain helps you place controls at several points.
02Authenticate your own domain
Publish SPF, DKIM and DMARC records and progress DMARC to a reject policy once reports show legitimate mail is aligned. This makes it much harder for criminals to send mail that appears to come from your exact domain. Also consider registering common look-alike domains if your brand is frequently impersonated.
03Filter and inspect
Use advanced email filtering with link rewriting, attachment sandboxing and impersonation protection for executives and finance staff. Warn users about external senders and first-time correspondents. Block automatic forwarding to external addresses and alert on newly created inbox rules, because these are classic signs of compromise.
04Protect accounts with strong authentication
Multi-factor authentication stops the majority of password-based takeovers. Use phishing-resistant methods such as security keys for administrators and finance leaders where feasible, and block legacy protocols that bypass MFA. Monitor for impossible-travel and unfamiliar sign-ins, and revoke sessions quickly when something looks wrong.
05Verification procedures for payments
Technical controls cannot catch every well-crafted request, so build a rule: any change to payment details or an unusual urgent transfer must be verified by calling a known number, not one in the email. Require dual approval above a threshold and keep a vendor master file with change history. Write the rule down and have executives endorse it publicly.
06Train people and make reporting easy
Short monthly lessons and simulated phishing build habits, but the key metric is reporting rate. Give staff a one-click report button, thank them for reporting, and never punish an honest mistake. Quick reports allow security teams to remove the message from every inbox and reset credentials within minutes.
07If it happens
Act fast. Isolate the account, reset credentials, revoke sessions, review inbox rules and sign-in logs and contact your bank immediately if funds moved, as quick action can sometimes recall transfers. Preserve evidence, notify your insurer and assess privacy obligations, including PIPEDA breach reporting where personal information was accessed. Afterwards, update controls based on what you learn.
08Mistakes that leave the door open
Frequent errors include protecting only the main mailbox while ignoring shared mailboxes and service accounts, enabling MFA for staff but not for executives who were granted exceptions, leaving DMARC in monitoring mode indefinitely and relying on a single annual training session. Another is treating payment verification as optional for senior requests, even though executives are the most commonly impersonated. Close these gaps and make the call-back rule universal, with no exceptions for rank.
09A 60-day defence plan
In the first 30 days, enforce MFA everywhere, disable legacy protocols, block external auto-forwarding and publish DMARC in monitoring mode. In the next 30 days, deploy advanced filtering and impersonation protection, start monthly simulated phishing, introduce the report button and write the payment-verification procedure. Then review DMARC reports and move towards enforcement. Report progress to leadership with simple measures such as MFA coverage, report rate and click rate.
10Who is targeted in different sectors
Real estate and law firms are targeted for trust-account and closing-fund fraud. Construction and manufacturing are targeted through supplier invoice changes. Nonprofits are targeted through donation and grant payments. Accounting firms are targeted for client credentials and tax data. In each case attackers research the organisation, which is why specific procedures for how payments and changes are approved matter more than generic reminders.
11Details that are easy to overlook
Review how vendors can request changes to bank details and ensure the process is documented and followed. Protect shared and role mailboxes such as accounts payable. Watch for look-alike domains and display-name spoofing in addition to exact-domain spoofing. Consider mobile devices, where it is harder to inspect sender addresses, and text-message or collaboration-platform phishing that bypasses email filters. Include contractors and temporary staff in training and policies.
12Questions for your leadership team
Who can approve a change to supplier banking details, and how is that verified? What is the largest payment one person can release alone? Do executives agree to follow the same verification rules as everyone else? How quickly could we find and remove a malicious message from every inbox? How will staff be thanked for reporting suspicious messages? These choices shape culture as much as technology.
Checklist
- DMARC at enforcement
- MFA on every mailbox
- External forwarding blocked
- Alerts on new inbox rules
- Call-back rule for bank-detail changes
- Dual approval for large payments
- Monthly phishing simulations
- One-click report button deployed
Where this fits in your IT plan
Guidance like this works best when it is part of a coordinated programme rather than a one-off fix. These IT Experts services address the topic directly:
Google Workspace
We run Google Workspace for organisations that prefer Google's collaboration model: user lifecycle, shared drives, security policies, context-aware access and migration from legacy mail.
SVC / PROTECTBusiness Continuity Planning
Business continuity planning documents how your organisation keeps operating - and communicates - when a building, a vendor or a platform is unavailable. We build plans that people can actually follow at 2 a.m.
SVC / PROTECTBackup & Disaster Recovery
Backup and Disaster Recovery (BDR) is the service that lets you say with evidence how quickly you can recover and how much data you could lose. We design to your recovery time and recovery point objectives and test restores on a schedule.
How IT Experts can help
IT Experts is a sub-brand of SAZ.ca, led by Ali Sedighi, MBA, combining senior-partner strategy with hands-on IT delivery. If this topic matches a situation in your organisation, book a free 30-minute consultation: call (604) 632-4959 or email info@SAZ.ca. We will give you a plain-language view of your options and, if useful, a fixed-price scope. We are an IT services and consulting firm, not a reseller, and there is no lock-in.
Frequently asked questions
What is the difference between phishing and BEC?
Phishing is a broad technique to steal credentials or deliver malware. BEC is a targeted fraud, often using a compromised or spoofed account, that aims to redirect money.
Does MFA fully stop account takeover?
It stops most, but attackers can use token theft or fatigue attacks. Phishing-resistant methods and conditional access reduce the remaining risk.
Should we ban external email forwarding?
Generally yes. Allow exceptions deliberately and log them.
Can you test our staff?
Yes. Our security awareness service includes simulated phishing with reporting by team.