Skip to content

The Brutal Truth About Business Email Compromise – 6 Strategies to Defend Your Business

Business email compromise (BEC) is one of the most destructive cyber threats facing businesses today, and it’s more common than ever. By gaining the trust of employees by assuming the identity of a trusted figure, BEC scammers use manipulation to gain financial reward, or steal compromising information.

The challenge with BEC attacks lies in the great lengths the attackers go to in order to infiltrate their target businesses, often carrying out extensive research, and even preparatory attacks that give them info they can use to cause harm in the future. This targeted approach, combined with the industriousness of the attackers, means BEC scams can be particularly difficult to detect and thwart.

 

Here at Computing Dynamics, our mission is to help businesses in Oxford, Brackley, Buckingham, Northampton and the wider region benefit from secure, dependable, and high-performance IT. Our managed security services deliver the robust, multi-faceted protections today’s businesses need to deflect a wide range of cyber threats, ensuring sensitive data remains safe and uncompromised.

Countering cyber threats requires businesses to deploy measures that encompass people, processes and technology. This multi-layered approach is particularly important with sophisticated threats like BEC, which simply cannot be mitigated by a single tool on its own. To help you safeguard your business, here are six strategies to mitigate against BEC attacks that you can use in your business today.

 

Configure Your Network Security to Block Suspicious Emails

Your network security devices such as firewall appliances and Intrusion Detection Systems (IDS) can be leveraged to block suspicious inbound mail. Have your IT team or your IT support provider configure ‘rules’ that block emails containing domains that vary slightly from that of your email service. As we’ve discussed, email imitation is a key tactic of the BEC attacker.

For example, if your company domain is ‘redcompany.co.uk,’ configure rules to block the many slight variations that a hacker might use for their malicious purposes, such as red_company.co.uk, redcompany1.co.uk, _redcompany.co.uk, and so on. This defensive mechanism isn’t failsafe, but it just might prevent your business falling prey to the BEC scammers.

 

Use Colour Coding for Internal Mail

Coloured tags, categories or labels can be a great way to differentiate internal mail, or to highlight mail from senior execs within your business. Business email services have facilities that allow organisations to apply controls, including colour-coding, organisation-wide. Talk to your IT team, or IT support provider, about implementing this simple yet powerful visual protection.

In the unlikely event that you can’t apply colour-coding from the top down, encourage your employees to apply colour-based categorisation to important senders manually. In Outlook for example, this can be done easily, by right-clicking an email, and applying a categorisation rule.

Colour coding will allow employees to quickly discern legitimate requests, from the bogus ones, as a rogue email won’t feature the colour label that the user comes to expect.

 

Take Care When Using Social Media

It’s important to be guarded when using social media, both in a personal and professional capacity. Don’t post about your business’s internal matters ever, even if you’ve set your profile to private: social media accounts get hacked all the time. In the case of less sensitive information, such as work events or parties, be mindful of who you’re broadcasting this information to, and if in doubt, don’t. Even seemingly harmless information could be used by a BEC scammer to construct a convincing fake identity that they then use to harm your business.

Create a social media policy if you don’t already have one in place. This document should guide staff on safe and responsible use of social media, and prohibit the online sharing of private information about your business that could be used to launch a targeted attack, or information that could harm your reputation.

 

Implement Employee Awareness and Training

While a BEC attacker will impersonate someone at the senior level of an organisation, the target employee could be anyone, from HR administrators to finance managers. It’s therefore crucial that you train all staff on the dangers of BEC, familiarise them with the techniques BEC attacks feature and establish policies and protocols for executing financial transactions and changes to account information. Here are a few best practices you can use:

· Require Callbacks. Upon receiving a payment request, require that employees authenticate the request by calling the sender via your call directory. Stress the importance of NEVER using phone numbers or other contact information provided in emails.

· Urge Suspicion Around Strange Requests. Encourage staff to exercise vigilance when any request or query seems out of the ordinary. Prohibit the sending of account credentials via email, unless ID authentication can be carried out. Urge staff to be particularly cautious if the language used is email is designed to evoke fear, alarm or a sense of urgency, no matter who the sender appears to be.

· Encourage Email Header Inspection. As we mentioned previously, BEC criminals can easily change the “from” field of an email to make it appear credible. One way round this is to cross-check the sender against metadata contained in the email header, which will show the email’s true origin. The process for doing this depends on the Email service you use. Talk to your IT team if you’re unsure.

 

Use a Reputable Email Security Platform

Using a modern, reputable email security platform will help you mitigate against BEC attacks, and other forms of email-borne cyber threats, including malware and general phishing attacks. It’s worth noting that email security tools are not infallible, and should be used in conjunction with the other security measures listed in this guide. Some of the features and capabilities of email security tools that can help counter the BEC threat include:

Advanced Threat Protection

Email security platforms use advanced threat detection mechanisms that can block emails from known malicious sources, and items featuring attachments characteristic of malware. Some tools can even intercept mail containing language that’s consistent with social engineering and phishing attacks. Mail quarantining redirects suspicious items automatically, ensuring dubious items are prevented from reaching your employees’ inboxes.

Sender Authentication

Email security tools feature protocols (such as SPF, DKIM, and DMARC) designed to prevent email spoofing. Through thorough examination of the sender’s domain, sender authentication ensures each email originates from the legitimate, claimed source.

Multi-factor Authentication

Email security tools can present a route to implementing multi-factor authentication, which requires users to submit an additional form of ID (in addition to an account password) when signing into their email accounts. This can reduce the risk of BEC, by preventing your email accounts from falling into the wrong hands.

Protect Your Customers, Partners and Vendors

A BEC scammer could use your business’s email service to attack your partners, customers and vendors. You can protect them, by making it clear to them what you will, and will not, use email for. Let them know, for example, that you will never make a direct request for sensitive information (such as account passwords) by email, or that you will never issue payment requests outside of the sanctioned channels and authentication procedures. By setting out the boundaries of your use of email in something like an email policy document, you leave no room for doubt, and you’ll do your part in defending your customers, partners and vendors against BEC attacks.

 

Final Thoughts

Business Email Compromise is a pernicious, damaging cyber threat that requires a multi-pronged approach to combat. By engendering a culture of email security awareness, deploying effective security tools, establishing robust payment authentication protocols, and instructing staff on the safe use of social media, you’ll prevent your business from contributing to the worrying BEC attack statistics.

 

Don’t wait for disaster to strike. Secure your business with managed 360° protection

With cybercrime on the rise, leaving digital security to chance could spell disaster for your business. With managed security services from Computing Dynamics, your sensitive data will be robustly defended against a variety of online threats, thanks to 360° protections that cover every attack surface in your IT environment. We’ll proactively monitor, manage and maintain your environment against security risks, so that you can focus on running your business. Contact Computing Dynamics today, to book a meeting or have a friendly, no-obligation chat about your IT requirements. We’d love to hear from you.

Back To Top