The email gateway
Filtering inspects mail arriving from outside. The fraudulent message in a BEC incident is sent from a legitimate internal mailbox, through the normal path, often inside an existing thread. There is nothing malformed to catch.
Modern business email compromise does not break in. It logs in — with a stolen session, a consented application, or a credential that passed multi-factor authentication legitimately. Email filtering never sees it, because by the time the fraud is sent the attacker is a valid user. Cyberneza scopes the identity controls; Huntress-backed identity threat detection watches for the behaviour that follows.
Filtering inspects mail arriving from outside. The fraudulent message in a BEC incident is sent from a legitimate internal mailbox, through the normal path, often inside an existing thread. There is nothing malformed to catch.
Adversary-in-the-middle phishing waits for the user to complete MFA and steals the resulting session. The control performed exactly as designed. The attacker simply inherited what it produced.
Resetting the password is the standard response and on its own it is insufficient — an active session, a consented OAuth application, or a forwarding rule all survive it. Containment means revoking the session and auditing what was granted.
Continuous monitoring for suspicious sign-in behaviour, session anomalies, mailbox rule manipulation, and unexpected application consent across supported Microsoft 365 and Google Workspace environments.
Where a takeover is confirmed, the response is to disable the account and revoke the session — the two actions that actually end the attacker’s access — supported by an investigated incident report rather than a raw alert.
Wire-fraud red flags, verification habits for payment changes, and phishing resilience. BEC succeeds on a plausible request to a person, so training is part of the control set rather than an adjacent nicety.
Cyberneza reviews conditional access, legacy authentication, application consent policy, administrative roles, mailbox forwarding restrictions and the auditing that has to be switched on before any of it is visible.
The control that stops the loss is procedural: no change to payment details on the strength of an email, ever, without out-of-band confirmation to a number already on file. We help write it and make it stick.
Identity monitoring, logging and awareness records support control expectations under SOC 2, ISO 27001 and NIST SP 800-171, and cyber insurers increasingly ask about BEC controls specifically.
Huntress reports a 3-minute mean time to respond on identity incidents, across more than 9 million identities monitored. In its 2026 Cyber Threat Report, drawn from 2025 activity, 19% of identity threats involved mailbox manipulation and persistence — which the report describes as a signature of business email compromise — and over 35% came from suspicious logins from risky locations, malicious networks or anonymising VPNs.
Sources: Huntress BEC use-case datasheet and the Huntress 2026 Cyber Threat Report. Figures are Huntress’s measurements, not Cyberneza’s. Cyberneza is an authorized Huntress reseller. Our read on the report →
BEC does not encrypt anything, take a system offline, or announce itself. It moves money, and it is usually discovered when a supplier asks why they have not been paid — days or weeks later, by which point recovery depends on how quickly the receiving bank can be reached.
It is also the incident class most likely to be argued over at claim time, because policies distinguish between a computer-fraud loss and one where an employee authorized the payment. Whether your controls made that authorization reasonable is a question best answered before the claim, not during it.
We can review your identity configuration, auditing, and payment-verification process, and scope monitoring around what the review finds.
Supported identity platforms, features, response actions and licensing depend on the selected Huntress service and current product availability.