What is the most effective way to respond to a CEO Fraud business email compromise?
We recently had an incident where a staff member received an urgent email from the 'CEO' asking for a gift card purchase for a client. Luckily, they checked with us first. What are the best internal policies to ensure these Business Email Compromise (BEC) attempts are caught every time before money is lost?
2024-04-11 in Cyber Security by Nancy Wright
| 16757 Views
All answers to this question.
BEC is the most financially damaging form of social engineering. To stop it, you must implement a formal 'out-of-band' verification policy for any financial transaction or sensitive data request. If the 'CEO' emails, the employee must call or message them on a known, trusted channel to confirm. We also use email banners that clearly mark any message coming from outside the organization. This provides a visual cue that the 'CEO' name might be spoofed. Lastly, involve your finance team in security training so they understand the specific 'urgency' tactics used.
Answered 2024-05-30 by Margaret Young
Do these attackers usually use look-alike domains, or are they actually compromising the internal accounts of the executives to send these?
Answered 2024-06-02 by Paul Scott
-
Paul, they use both. Look-alike domains are common for external-to-internal attacks, but account takeover (ATO) is much harder to spot. That’s why MFA is critical for executive accounts. If the internal account is compromised, the only thing that saves you is a strict policy that no payments are made via email request alone.
Commented 2024-06-05 by Charles King
We found that showing real examples of BEC emails in our monthly newsletter keeps the threat top-of-mind for our administrative and finance staff.
Answered 2024-06-08 by Donna Green
-
I agree with Donna. Real-world examples are much more impactful than theoretical warnings. It makes the threat feel 'real' to the employees.
Commented 2024-06-10 by Nancy Wright
Write a Comment
Your email address will not be published. Required fields are marked (*)

