Free Business Email Compromise (BEC) Checklist:
See If Your Business Can Stop a Wire Fraud Attack
- 9 quick questions
- Takes about 2 minutes
- No sign-up to see your result
Your top next moves
Use the interactive BEC exposure check below to see where your business actually stands against wire fraud.
Answer 9 quick questions and get your risk assessment in about 2 minutes. It includes the specific gaps to fix and a checklist you can hand to your team or IT provider.
No sign-up to see your result.
What Business Email Compromise Actually Is (The Short Version)
Business email compromise (BEC) is a targeted financial fraud where attackers impersonate a trusted person, your CEO, a vendor, a bank, to trick someone in your business into wiring money or changing payment details.
No malware required.
The attacker sends a convincing email, your team follows the instructions, and the money leaves. By the time anyone catches it, it’s usually gone.
BEC is the #1 cybercrime by dollar losses in the United States. It works because it targets the human side of your business, not your firewall. The attack vectors are narrow but devastating:
- Fake wire transfer requests
- Vendor payment-detail changes
- Payroll direct deposit redirects
- CEO impersonation
The controls that stop most of them are a combination of process rules (call-back verification, dual approval) and technical configuration (DMARC enforcement, MFA on email). The checklist below covers both.
The BEC Exposure Checklist:
Work through each area. Anything you can’t confirm is a gap. Use the interactive tool above to get a scored result; use the checklist below for the full detail behind each question.
- 1. Out-of-Band Verification on Wire and Payment Requests:
✓ Any email request to wire money, make an ACH payment, or change a vendor’s bank account details triggers a mandatory phone call to confirm, using a number already on file, not a number from the email.
✓ This one process rule stops the majority of BEC wire fraud cold. An attacker who controls a compromised or lookalike email account cannot intercept a phone call to the real contact. - 2. Dual Approval for Wire Transfers and ACH Payments Above a Threshold:
✓ Payments above a set dollar amount (common starting points: $5,000 or $10,000) require sign-off from two separate named approvers before the money moves.
✓ A single compromised or deceived employee cannot authorize a fraudulent transfer on their own. This is built into your accounting software or your bank’s payment controls, not just a verbal agreement. - 3. DMARC Enforcement on your Company’s Email Domain:
✓ Your domain has a DMARC record and the policy is set to `p=quarantine` or `p=reject`, not `p=none` (monitor-only mode).
✓ Without enforcement, an attacker can send email that appears to come from your CEO or your accounting team to your vendors or your own employees. DMARC enforcement makes that technically impossible.
✓ Your IT provider or email admin can confirm your current DMARC status in minutes. Moving from `p=none` to `p=quarantine` typically takes one DNS change. - 4. Multi-Factor Authentication on Finance and Executive Email:
✓ Every member of your finance team and every executive who approves payments uses multi-factor authentication (MFA) to log in to their email account.
✓ Finance and executive mailboxes are the primary BEC targets: control of one account lets an attacker intercept real payment threads, read historical context, and redirect funds before anyone notices.|
✓ Microsoft 365 and Google Workspace both include MFA at no extra cost. - 5. Spoofing and Lookalike-Domain Awareness Training:
✓ Employees have received training in the past 12 months on how to spot display-name spoofing (the sender’s name looks right but the actual email address is different) and lookalike domains (one letter swapped, a hyphen added, a different TLD).
✓ The fix is simple: hover over or click the sender name to see the actual address. Training staff to check the address, especially on any email requesting a payment action, stops this class of attack before it starts. - 6. Verified Process for Payroll Direct Deposit Changes:
✓ Employees who want to change their direct deposit bank account cannot do so by emailing HR. The change requires verification through a self-service portal with MFA, or an in-person request with ID.
✓ Payroll diversion, where an attacker impersonates an employee and emails HR to redirect their paycheck, is one of the most common BEC variants. Removing email-to-HR as an accepted method closes the door on this attack entirely. - 7. A Written Fraud Response Plan the Team Knows About:
✓ Your team knows exactly what to do if a fraudulent wire transfer is suspected or confirmed: call your bank’s fraud line immediately, file a complaint at ic3.gov within the same hour, and preserve all related emails.
✓ The FBI’s Financial Fraud Kill Chain can freeze or recover funds in transit, but only if the bank and IC3.gov are notified within hours of the transfer. Most businesses lose that window because no one knows the steps in advance. source: FBI Internet Crime Complaint Center (IC3) - 8. Quarterly Review of Email Forwarding and Filtering Rules:
✓ Someone has reviewed email accounts, especially finance and executive accounts, in the past 90 days to confirm that no unknown forwarding or filtering rules have been set up.
✓ Attackers who compromise a mailbox often create hidden inbox rules that silently copy or forward payment-related emails to an outside address. These rules survive a password reset and can persist for months undetected.
✓ In Microsoft 365 this can be done through the Security and Compliance Center. Your IT provider should schedule this quarterly.
How to read your gaps?
Most of the technical items above (MFA, encryption, audit logging, tested backups) live in your IT setup, not a policy binder, which is the half of HIPAA a managed IT partner operates for you.
- 0 – 2 Gaps
Your core controls are in place and you are not an easy target.
- 3 – 5 Gaps
Real, exploitable openings that BEC attackers specifically look for.
- 6+ Gaps
Multiple gaps that threat actors target, wire fraud losses average well into six figures per incident, and the controls that close most of this are process changes, not expensive tools.
BEC Exposure Check FAQ
A BEC checklist is a structured self-audit of the process and technical controls that stop business email compromise attacks. A complete checklist covers the eight areas most exploited in real BEC incidents: out-of-band verification on wire requests, dual approval for high-dollar transfers, DMARC enforcement on your email domain, MFA on finance and executive mailboxes, spoofing awareness training, a verified process for payroll changes, a written fraud response plan, and periodic review of email forwarding rules. The interactive tool at the top of this page walks through all eight and gives you a scored result.
An attacker sends a carefully crafted email that appears to come from a trusted source, your CEO, a vendor, your bank, or a colleague. The email requests an urgent wire transfer, a change to a vendor’s bank account, or a payroll update. Because the request looks legitimate and often cites real context, the target follows the instructions and the money moves. BEC doesn’t require hacking your systems: it exploits trust, urgency, and the gap between “looks right” and “is right.”
DMARC (Domain-based Message Authentication, Reporting, and Conformance) is a technical standard that tells receiving email servers what to do when someone sends email that claims to come from your domain but fails authentication. Without a `p=quarantine` or `p=reject` policy, an attacker can impersonate your company and send convincing fraudulent emails to your vendors, partners, or employees. Enforcing DMARC closes the spoofing door at the domain level, it doesn’t stop all BEC (attackers also use compromised accounts and lookalike domains), but it eliminates one of the most common entry points.
Act within the hour: first, call your bank’s fraud line and request a wire recall or payment stop. Second, file a complaint at ic3.gov immediately, the FBI’s Financial Fraud Kill Chain can freeze funds in transit, but only if it’s activated fast. Third, preserve every email related to the transaction without altering them. Fourth, notify your IT provider to secure the affected email accounts and check for hidden forwarding rules. The first two steps are time-critical. Most businesses that lose the recovery window do so because they wait until the next business day.
Most cyber insurance policies include some social engineering or funds transfer fraud coverage, but coverage limits, sublimits, and conditions vary widely. Many policies require that specific internal controls were in place at the time of the incident, dual approval, call-back verification, and MFA are commonly listed requirements. Check your policy’s social engineering endorsement and funds transfer fraud section before an incident, not after.
Phishing is broad, it typically sends the same malicious link or attachment to a large list of targets hoping someone clicks. BEC is targeted and financially specific: the attacker researches your business, impersonates a known contact, and crafts a single email designed to trigger one financial action. BEC rarely involves malware; the entire attack is in the email itself. Because there’s nothing technical to block at the endpoint level, process controls (verification, dual approval) and email authentication (DMARC, MFA) do most of the work.
Yes. Smaller businesses are targeted because they typically have fewer internal controls and less scrutiny on payment requests. The average BEC incident loss does not scale by company size, a 20-person firm wiring $80,000 to a fraudster loses the same $80,000 as a larger company. The attack is simple enough to run against any business that wires money, pays vendors, or runs payroll.
Ready to close your gaps?
If your result flagged two or more gaps, the controls that close most of this are straightforward, call-back verification policies, dual-approval rules, a DMARC configuration change, and MFA on email.
LeadingIT has worked with Chicagoland businesses to prevent wire fraud and secure email environments since 2010.
Email yourself the full result from the tool above, book a free 30-minute call, or contact us online.