Stopping Business Email Compromise Before Money Moves
The single most effective way to stop business email compromise (BEC) is to require out-of-band verification for any payment or bank-detail change before the money moves. Never trust the request just because it arrived in a familiar-looking email thread. Every other control matters, but this is the one that actually stops the wire.
BEC doesn't rely on malware or clever exploits. It relies on a convincing email, a sense of urgency, and a finance team that's moving fast. The fix isn't purely technical: it's a mix of process discipline and email hardening. Here's what to put in place, in order of impact.
The fastest way to stop BEC: verify every payment change out-of-band
If an email asks you to change a vendor's bank details, redirect a wire, or pay an "urgent" invoice from a new account, stop and verify using a channel that didn't come from that email.
The rule is simple: any request to change payment details or send funds to a new account gets a phone call to a number you already had on file — not one supplied in the email or the signature block. If you can't reach the person by phone within a reasonable time, the payment waits.
Urgency in the email is not a reason to skip verification. It's usually the tell. A new vendor, a new account, or a returning vendor with "updated" details are all treated the same way: verify before you pay.
The obvious objection: what if the vendor is genuinely in a hurry and gets annoyed at the delay? A legitimate counterparty will accept a callback to confirm a wire. It's standard practice at most companies. If someone pushes back hard on a verification call, that itself is a signal worth escalating, not ignoring.
Build a payment-change protocol your finance team can't skip
Verification only works if it's a required step, not a judgment call left to whoever is busiest that day. Put it in writing:
- Define who is authorized to approve a bank-detail change or a new wire recipient, and require a second person to sign off on anything above a threshold you set internally.
- Keep a maintained contact list (name, phone number, verified independently) for every vendor that receives wires. Don't rely on whatever's in the email signature.
- Make "flag anything unusual" safe to do. The person who pauses a $50K wire to make a phone call should never be made to feel like they slowed the business down.
If you don't have a documented finance approval process today, that's the gap to close this week, not the email filter. Most BEC losses happen because the process allowed one person, under time pressure, to approve a change alone. A written protocol plus a mandatory second signer closes that gap even if a fake email gets through.
Harden email itself so fewer fakes reach the inbox
Process stops the money from moving; email controls reduce how often your team faces the decision at all.
- Authenticate your domain. SPF, DKIM, and DMARC make it harder for attackers to spoof your company's domain in emails sent to your customers and vendors. This protects your reputation as much as your inbox.
- Flag lookalike domains automatically. Most email platforms can tag messages from newly registered or similar-looking domains (a swapped letter or added hyphen, for example). Turn this on. It's often free and just switched off by default.
- Add a visible external-sender banner. A simple "this email originated outside your organization" flag on inbound mail catches the classic BEC pattern: an email that looks internal but isn't.
- Restrict inbox rule creation where possible, or review auto-forwarding rules periodically. Attackers who compromise a mailbox often set up silent forwarding rules to monitor invoice threads. This is one of the easiest indicators to check for and one of the most overlooked.
None of this requires a large security team to stand up. If you don't have the internal resources to configure and monitor these controls, a managed security arrangement can own this on an ongoing basis rather than as a one-time setup.
If the wire already went out, speed is everything
Even with good controls, no company is immune. If a fraudulent payment does go through, the first hour matters more than anything else.
- Contact your bank immediately and request a recall or hold on the transfer. The sooner this happens, the better the odds of stopping or reversing it.
- Preserve the email evidence and don't delete the thread. You'll need it for the bank, for law enforcement, and for your own post-incident review.
- Loop in whoever handles incident response early, even if you're not sure yet how serious it is.
In one engagement, we saw firsthand how quickly an active intrusion can escalate once attackers have a foothold. Waiting to "confirm" the problem before acting almost always costs time you don't have.
If you don't have an incident response plan or a point of contact for this scenario today, fix that before you need it, not after. Our incident response service exists for exactly this: a senior response when something's already moving, not a form to fill out.
Where to start this week
You don't need every control above in place simultaneously. Start with the highest-leverage one: put a written, mandatory callback-verification rule in front of every payment-detail change, starting Monday. It costs nothing, takes minutes to implement, and closes the gap that BEC actually exploits.
If you want a second set of eyes on where your email, finance process, and vendor management stand today, our free security review is a low-friction way to find out — no obligation, just a clear picture of where the gaps are.
For broader guidance on protecting against email-based fraud, the Cybersecurity and Infrastructure Security Agency (CISA) also publishes general BEC awareness resources worth sharing with your team.
Originally published at sheersafe.com.












