Back to blog
7 Proven Ways to Prevent Business Email Compromise in the UK

7 Proven Ways to Prevent Business Email Compromise in the UK

3 September 2026

What is business email compromise?

Business Email Compromise (often called BEC or BEC fraud) is a sophisticated cybercrime where criminals impersonate a trusted email sender to trick employees into transferring money or revealing sensitive information. Unlike obvious spam or phishing emails, BEC scams are highly targeted and use social engineering; manipulating human trust to fool recipients.

In the UK, BEC attacks are a growing headache for businesses of all sizes from start-ups to large enterprises. The National Cyber Security Centre (NCSC) reports that in 2023 alone, UK organisations lost millions of pounds due to BEC scams. Action Fraud recorded over 1,200 reports of CEO fraud and related email scams last year, reflecting the increasing danger.

Even small and medium-sized enterprises (SMEs) are at risk because cybercriminals believe these businesses often have fewer security controls in place, making them easier targets for business email compromise.

Common Types of Business Email Compromise Attacks

BEC fraud takes several forms, often designed to exploit typical business processes.

CEO Fraud

In CEO fraud, scammers impersonate a senior executive (often the CEO or finance director) and send an urgent email to a finance or accounts team member asking for a payment or confidential information. The email looks authentic and creates pressure to act quickly.

Vendor or Supplier Fraud

Here, criminals hack or mimic email accounts of trusted suppliers or vendors. The attacker instructs the victim to send payments to new bank accounts controlled by the fraudster.

Account Compromise

In this attack, hackers gain access to an actual employee's email account and use it to send requests internally, making detection extremely difficult.

How Do BEC Scams Work? An Anonymised UK Business Case Study

Case Study: A Close Call at a UK Manufacturing Firm

Problem: In early 2023, a mid-sized manufacturing company in Manchester nearly lost £75,000 when their finance officer received an email appearing to come from the company's managing director requesting an urgent overseas payment.

What happened: The email used the correct tone and details, creating urgency by citing a new supplier contract. The finance team almost transferred funds before noticing that the email address was slightly off; using ".co" instead of ".co.uk". Another staff member alerted management just in time.

The outcome: The payment was halted and Action Fraud was informed. The company then implemented multi-factor authentication and a double-approval process for all payments.

The lesson: Vigilance, staff training, and verifying requests via phone calls or in-person discussions are crucial defences against BEC.

A typosquatting cyber attack uses a fraudulent website address that closely resembles a legitimate domain, often by changing, removing, or adding a single letter. Attackers may copy the genuine website’s branding, login page, email design, and language, making everything appear authentic. However, the website is controlled by criminals and may be used to steal passwords, payment details, or sensitive business information. Always check domain names carefully before clicking links or entering personal information.

Recognising the Warning Signs of a Business Email Compromise Attack

BEC emails are often neatly crafted without obvious errors, making them hard to spot. However, watch out for:

  • Urgent payment requests that demand immediate action without normal procedures.
  • Emails from addresses that appear genuine but have subtle changes (e.g., j.smith@company.co versus j.smith@company.co.uk).
  • Requests for payments to new or unusual bank accounts.
  • Messages that come outside typical hours or from unusual locations.
  • Emails lacking attachments or links but still asking for sensitive info or funds.

If you notice these, pause and verify before acting.

Business Email Compromise Prevention Checklist

Why BEC Costs UK Businesses Millions Every Year

BEC fraud is not just a nuisance; it causes serious financial damage. According to the NCSC's 2023 report:

  • UK businesses faced losses exceeding £45 million from BEC scams.
  • On average, affected firms lost around £30,000 per incident.
  • Over 60% of reported cases targeted SMEs with limited cybersecurity resources.

These costs include lost funds, investigation expenses, legal fees, and reputational harm.

How to Protect Your UK Business from Business Email Compromise

1. Train and Raise Awareness Among Staff

The best defence is an informed team. Run regular training covering BEC scams, phishing, and social engineering techniques. Use real examples like the case study to highlight risks.

2. Always Verify Payment and Information Requests

Establish a clear company policy requiring employees to confirm all payment instructions or requests for sensitive data through a second channel; such as a phone call to a known contact.

3. Implement Strong Email Security Measures

  • Enable Multi-Factor Authentication (MFA) on all email accounts to require multiple proofs of identity.
  • Regularly update and enforce strong, unique passwords.
  • Keep software and anti-virus programs up to date.

4. Adopt Email Authentication Protocols (SPF, DKIM, DMARC)

These technical tools help prevent scammers from spoofing your company's email domain.

 

Email Authentication

Together, they greatly reduce fraudulent emails appearing to come from your business. Your IT team or email provider (such as Microsoft Office 365, Google Workspace, or hosted providers like Mimecast) can typically configure these within your email administration settings.

 

5. Use Email Filtering Tools

Invest in email security gateways or filters that scan for suspicious senders, unusual content, or unknown attachments.

6. Strengthen Financial Controls

Require multi-person approval for payments, especially transfers to new or international accounts.

7. Consider Cyber Insurance

Many UK insurers offer cyber fraud protection policies to help cover financial losses from BEC and related cybercrimes.

BEC and UK Compliance: What You Need to Know

Business Email Compromise can also have compliance implications:

  • Under the EU General Data Protection Regulation (GDPR), if an attack leads to a data breach involving personal data, firms must notify the Information Commissioner's Office (ICO) within 72 hours.
  • The Network and Information Systems (NIS) Regulations require operators of essential services and digital providers to report significant cyber incidents promptly.

Implementing proactive measures such as staff training, MFA, and technical controls demonstrates to regulators that you take cybersecurity seriously.

What To Do If Your Business Falls Victim to BEC Fraud

  1. Report to Action Fraud immediately: Visit actionfraud.police.uk.
  2. Notify your bank: Alert them to stop or reverse fraudulent transactions.
  3. Contact the National Cyber Security Centre: Access their incident response guidance at ncsc.gov.uk.
  4. Inform the ICO: If personal data breach is suspected, notify the Information Commissioner's Office.
  5. Review and strengthen your defences: Conduct a thorough internal investigation and enhance policies accordingly.

Frequently Asked Questions about Business Email Compromise (BEC)

Q1: What is the difference between BEC and phishing?

A1: While both are email scams, phishing often involves mass emails with malicious links or attachments. BEC is targeted and impersonates trusted contacts to trick specific individuals into transferring money or information.

Q2: Can small UK businesses be targeted by BEC?

A2: Yes. In fact, SMEs are frequently targeted due to often weaker security defences.

Q3: How long does a BEC investigation take?

A3: Investigations vary but typically take weeks or even months, depending on the complexity and cooperation from financial institutions.

Q4: What is multi-factor authentication and why does it help?

A4: MFA requires users to provide two or more verification methods before accessing accounts, making it harder for criminals to gain control of email accounts.

Q5: Are there UK-specific cyber fraud protection certifications?

A5: Yes. The Cyber Essentials scheme is a government-backed certification demonstrating that basic cybersecurity controls are in place.

Q6: Can email filtering prevent all BEC attacks?

A6: No single solution is foolproof, but effective email filtering greatly reduces the risk by blocking suspicious messages.

Q7: What are the consequences of failing to report a BEC-related data breach?

A7: Non-compliance with GDPR can lead to significant fines and reputational damage.

Summary and Next Steps: Protect Your UK Business Today!

Business Email Compromise is a costly and increasing cyber threat to UK businesses. However, with practical steps such as staff training, verification processes, strong email security including SPF, DKIM, DMARC protocols, and compliance awareness, your business can significantly reduce risk.

Start by reviewing your payment authorisation procedures, enable MFA on all accounts, and educate your team on spotting BEC scams. For tailored guidance, visit the National Cyber Security Centre's small business cybersecurity toolkit at ncsc.gov.uk/collection/small-business.

Want to strengthen your overall cybersecurity posture? Check out our comprehensive cybersecurity training for SMEs for broader strategies to protect your business across all areas.

Stay alert. Stay secure.

Cybersecurity Awareness Training

Need Expert Guidance?

Is your business vulnerable to BEC fraud? Unsure where to start with email security? 

At Optimise Cyber we help businesses to secure their staff against cyberthreats. Contact us for more information. 

 

More from the blog

Public WiFi Safety: Essential Guide for Business Professionals
Post

Public WiFi Safety: Essential Guide for Business Professionals

Learn how to stay safe on public WiFi. Discover risks, 7 essential tips, VPN guidance, and how businesses can protect employees. Practical & actionable.

27 August 2026Read more
Two-Factor Authentication: Enable 2FA for Stronger Security
Post

Two-Factor Authentication: Enable 2FA for Stronger Security

Discover the power of two-factor authentication (2FA) to protect your online accounts. Learn easy ways to enable 2FA and keep your personal data safe.

24 August 2026Read more
Impersonation Fraud at the Office
Post

Impersonation Fraud at the Office

Learn how impersonation fraud threatens modern workplaces. Discover common tactics, red flags, and proven strategies to protect your team from identity fraud and deepfakes.

19 August 2026Read more