Business Email Compromise · Detection & response

BEC is not an email problem. It is an identity problem.

Modern business email compromise does not break in. It logs in — with a stolen session, a consented application, or a credential that passed multi-factor authentication legitimately. Email filtering never sees it, because by the time the fraud is sent the attacker is a valid user. Cyberneza scopes the identity controls; Huntress-backed identity threat detection watches for the behaviour that follows.

Why the usual controls miss it

Three defences that are all working correctly.

The email gateway

Filtering inspects mail arriving from outside. The fraudulent message in a BEC incident is sent from a legitimate internal mailbox, through the normal path, often inside an existing thread. There is nothing malformed to catch.

Multi-factor authentication

Adversary-in-the-middle phishing waits for the user to complete MFA and steals the resulting session. The control performed exactly as designed. The attacker simply inherited what it produced.

The password reset

Resetting the password is the standard response and on its own it is insufficient — an active session, a consented OAuth application, or a forwarding rule all survive it. Containment means revoking the session and auditing what was granted.

What the service covers

Detect the takeover, not the message.

Identity threat detection

Continuous monitoring for suspicious sign-in behaviour, session anomalies, mailbox rule manipulation, and unexpected application consent across supported Microsoft 365 and Google Workspace environments.

Identity security →

Managed response

Where a takeover is confirmed, the response is to disable the account and revoke the session — the two actions that actually end the attacker’s access — supported by an investigated incident report rather than a raw alert.

The human layer

Wire-fraud red flags, verification habits for payment changes, and phishing resilience. BEC succeeds on a plausible request to a person, so training is part of the control set rather than an adjacent nicety.

Security awareness →

Configuration hardening

Cyberneza reviews conditional access, legacy authentication, application consent policy, administrative roles, mailbox forwarding restrictions and the auditing that has to be switched on before any of it is visible.

A verification process

The control that stops the loss is procedural: no change to payment details on the strength of an email, ever, without out-of-band confirmation to a number already on file. We help write it and make it stick.

Evidence for assurance

Identity monitoring, logging and awareness records support control expectations under SOC 2, ISO 27001 and NIST SP 800-171, and cyber insurers increasingly ask about BEC controls specifically.

Cyber insurance readiness →

Reported detail

What Huntress publishes about BEC.

Huntress reports a 3-minute mean time to respond on identity incidents, across more than 9 million identities monitored. In its 2026 Cyber Threat Report, drawn from 2025 activity, 19% of identity threats involved mailbox manipulation and persistence — which the report describes as a signature of business email compromise — and over 35% came from suspicious logins from risky locations, malicious networks or anonymising VPNs.

Sources: Huntress BEC use-case datasheet and the Huntress 2026 Cyber Threat Report. Figures are Huntress’s measurements, not Cyberneza’s. Cyberneza is an authorized Huntress reseller. Our read on the report →

Why it is worth the attention

The loss is immediate and often uninsured.

BEC does not encrypt anything, take a system offline, or announce itself. It moves money, and it is usually discovered when a supplier asks why they have not been paid — days or weeks later, by which point recovery depends on how quickly the receiving bank can be reached.

It is also the incident class most likely to be argued over at claim time, because policies distinguish between a computer-fraud loss and one where an employee authorized the payment. Whether your controls made that authorization reasonable is a question best answered before the claim, not during it.

Want to know whether you would see a takeover?

We can review your identity configuration, auditing, and payment-verification process, and scope monitoring around what the review finds.

Supported identity platforms, features, response actions and licensing depend on the selected Huntress service and current product availability.