Skip to main content
  • For Support:

    815-308-2095

  • New Client
    815-788-6041

How to Prevent Business Email Compromise: A Controls Checklist for Small Businesses

July 14, 2026

Learning how to prevent business email compromise requires a mix of strict financial processes, hardened technology, and alert employees. Business email compromise prevention is a severe financial security threat that targets the way your company moves money, and it demands action from every layer of your organization, not just your IT department.

In 2024, the FBI Internet Crime Complaint Center received 21,442 BEC complaints with adjusted losses of $2.77 billion, making BEC the second-highest loss category among all reported internet crimes for the year.

Hackers use compromised accounts to trick your staff into sending money to fraudulent bank accounts. Once you understand how hackers get into your email in the first place, you realize that a single missed red flag can cost your business hundreds of thousands of dollars. From October 2013 through December 2023, global BEC exposed losses totaled $55,499,915,582 across 305,033 incidents reported in all 50 states and 186 countries.

To stop business email compromise, you need three layers of defense. You must implement money controls to catch fraudulent transfers, email controls to block malicious messages, and people controls to train your staff. This checklist provides the concrete steps business owners and finance managers need to secure their operations against these devastating attacks.

Money Controls

The most reliable way to survive a BEC attempt is to stop the money from leaving your bank. Hackers will eventually get a convincing email into an inbox. Your financial processes must catch what your email filters miss. Work through these controls in order.

  1. Verify every payment change outside of email. If a vendor emails you to change their ACH details or wire routing instructions, confirm the request outside of the email channel. This is known as out-of-band payment verification. Call the vendor at a known, trusted phone number that you already have on file. Do not call the phone number listed in the email requesting the change, as hackers frequently provide their own phone numbers to intercept your verification call.
  2. Set up dual approval wire transfer controls with your bank. No single employee should have the power to authorize and release a large wire transfer. Contact your bank to establish specific dollar thresholds that require two separate individuals to approve the transaction. One person initiates the transfer in the banking portal, and a second executive must log in separately to approve and release the funds.
  3. Make vendor bank change callbacks a hard company policy. Any change to payment routing requires a verbal conversation. Hackers often compromise a legitimate vendor’s email account and send invoices with updated payment instructions from the actual vendor’s email address. A strict callback policy ensures that even if the email comes from a trusted partner, the payment change is verified verbally before any money moves.

Email Controls: Preventing Business Email Compromise

Technology stops the bulk of BEC attacks before they reach your finance team. You need strict limits on how email accounts can be accessed and what those accounts are allowed to send. Put these in place in this order.

  1. Require MFA for email security on every account. Multi-factor authentication is mandatory. Start with your finance department and executives, but roll it out to every user in your organization. If a hacker steals a password, MFA blocks them from logging into the account. Without MFA, criminals can easily log in, read your financial correspondence, and learn exactly how your business operates before launching an attack.
  2. Configure email authentication SPF DKIM DMARC. These three protocols work together to prove that an email actually came from your domain, and they stop hackers from spoofing your company email addresses. When you enforce DMARC policies, receiving servers will automatically reject messages that pretend to be from your company but originate from unauthorized servers. This protects your clients and your internal staff from spoofed messages.
  3. Set up email gateway security rules. Configure your email system to flag messages originating from outside the organization, and warn users about reply-to mismatches. A common tactic is for an email to display your CEO’s name, but the actual reply-to address routes to an external webmail account. Gateway rules can highlight these discrepancies in bright banners at the top of the message.|
  4. Audit mailbox rules and forwarding regularly. Once hackers gain access to an inbox, they often create hidden rules to forward incoming invoices to themselves or move your replies directly to the trash folder. This allows them to communicate with your vendors without the actual account owner noticing. Audit your Microsoft or Google email environments on a schedule to catch and remove unauthorized forwarding rules.

People Controls

Your employees are the final barrier. General cybersecurity awareness is helpful, but business email compromise training must be specific to the people handling money and sensitive data. Focus the training on these steps.

  1. Run targeted training for finance and HR. Teach your team how to detect BEC attack attempts by focusing on the specific scenarios they will face. The FBI’s Internet Crime Complaint Center identifies five main scenarios for this fraud. Prepare your team for CEO fraud where an executive asks for a wire transfer, and vendor supplier email compromise where invoice details are swapped. Train them on attorney impersonation, data theft where HR is tricked into sending W-2 forms, and account compromise, where a hacked employee mailbox is used to send fraudulent payment requests to that employee’s own vendor contacts. You can read more about how these specific attacks function in our guide detailing CEO fraud and wire scams explained.
  2. Teach staff the specific business email compromise red flags. These include urgent requests from executives who are supposedly unavailable by phone, sudden changes to payment instructions right before a weekend or holiday, and requests for secrecy regarding a transaction.
  3. Explain business email compromise vs phishing. Make sure your team understands the difference. Generic phishing casts a wide net hoping someone clicks a bad link to steal a password. BEC is highly targeted social engineering designed to steal money directly. Hackers will spend weeks reading emails to mimic the exact tone and formatting your executives use.

What to Have Ready BEFORE an Incident

Even with perfect BEC attack prevention, you must plan for failure. If a fraudulent wire transfer goes out, your recovery window is incredibly tight, and speed is your only advantage once funds leave your account. You need an incident response plan that outlines exactly who to call. The timeline below maps the recovery clock to the actions that matter.

Recovery windowWhat to doWhy the clock matters
ImmediatelyContact your financial institution and request a wire recallOnce a wire transfer is accepted and the funds are credited to the beneficiary’s account, commercial law makes it extremely difficult to reverse, and the receiving bank is under no automatic obligation to return the funds.
ImmediatelyReport the crime to IC3.govThe IC3 Recovery Asset Team works directly with financial institutions to freeze funds for BEC victims. While you request the recall from your originating bank, the RAT forwards transaction details to the recipient bank to request the account be frozen.
Approximately 24 to 72 hours from when the wire was sentKeep pressure on both banks; this is the practical recovery windowThe faster you act, the better your odds of recovering the funds, since criminals typically move money out of the receiving account quickly.
Within 72 hours, international wires onlyAsk about the international Financial Fraud Kill Chainit can only be activated if the wire transfer is $50,000 or greater and a SWIFT recall notice has already been initiated.

The freeze process works when it starts fast.

In 2024, the Recovery Asset Team initiated the Financial Fraud Kill Chain on 3,020 incidents, resulting in $469.1 million frozen in domestic cases and an overall 66 percent success rate.

Review our step-by-step guide on wire transfer fraud recovery so your team knows exactly how to react when minutes matter.

See Where You Stand

You can use the free self-assessment to evaluate your current defenses. Free 2-minute BEC Exposure Check: 9 quick questions on how your business moves money, see your exposure level and the gaps to fix. No sign-up to see your result. free wire fraud risk assessment

Frequently Asked Questions

How can business email compromise be prevented?

Preventing business email compromise requires a combination of strict financial controls, hardened email security, and targeted employee training. You must require out of band verbal verification for any changes to payment instructions. You also need to enforce multi-factor authentication on all email accounts and train your finance team to recognize the specific social engineering tactics hackers use.

What is a red flag for a business email compromise?

Common red flags include sudden changes to wire routing instructions or ACH payment details. You should also watch for urgent requests from executives who claim they cannot be reached by phone. Another major warning sign is an email that appears to come from a known contact but has a mismatched reply to address routing to an external webmail provider.

How common is business email compromise?

Business email compromise is incredibly common and highly destructive. In 2024 alone, the FBI Internet Crime Complaint Center received 21,442 BEC complaints resulting in adjusted losses of 2.77 billion dollars. It remains one of the most financially damaging internet crimes affecting businesses globally.

Who is usually targeted in a BEC attack?

Hackers specifically target employees who have the authority to move money or access sensitive data. This typically includes finance managers, accounts payable staff, human resources personnel, and senior executives. Real estate professionals and title companies are also frequent targets due to the large wire transfers involved in property closings.

Is business email compromise phishing?

Business email compromise often starts with a phishing attack to steal email credentials, but it is much more targeted than generic phishing. While standard phishing tries to trick users into downloading malware or giving up passwords, BEC is a long term financial con. Hackers use the compromised email account to study business relationships and eventually manipulate staff into sending money to fraudulent accounts.

Secure Your Business Communications

LeadingIT is a Chicagoland managed it and cybersecurity provider that has helped Illinois businesses since 2010. We serve roughly 200 organizations and over 2,500 users from our offices in Woodstock and Manteno. LeadingIT hardens email with MFA and DMARC enforcement, trains staff against wire fraud social engineering, and builds the payment verification and incident response processes that stop BEC.

If you want to protect your financial assets from email fraud, explore LeadingIT’s managed cybersecurity services (done-for-you path). You can also contact us directly or book a call to schedule a conversation. To speak with our team immediately, call 815-788-6041.


Stephen Taylor is the founder and driving force behind LeadingIT, a Chicagoland-based IT and cloud services company, where he focuses on delivering practical, client-first technology solutions for businesses. A Microsoft Certified professional and author of Technology Should Just Work, he combines hands-on expertise with a passion for making IT simple, transparent, and effective. Read more about the author.

Let Us Be Your Guide In Cybersecurity Protections
And IT Support With Our All-Inclusive Model.