Stop! And think before you act on that email

How often do you stop and think “hey, is this email real?” Probably not a lot. If that’s the case, you need to become a little more suspicious to help prevent something called a Business Email Compromise (BEC) attack. Here’s what that is and how to protect your business.

15th June 2023

Stop! And think before you act on that email

How many times a day do you respond to an email without really thinking about its contents?

Maybe it’s a request for some information. Perhaps it’s asking you to pay an invoice. All mundane stuff. But no sooner than you’ve hit send, you’ve fallen victim to a Business Email Compromise (BEC) attack.

A BEC attack occurs when a cyber criminal gains access to your business email account and uses it to trick your employees, customers, or partners into sending them money or sensitive information. They do this by impersonating someone senior, and abusing their position of trust.

It might sound like something that only happens to big corporations, but that’s not the case. We see small businesses getting attacked, all of the time.

According to the FBI, small and medium-sized businesses are just as vulnerable to BEC attacks as larger ones. In fact, these attacks have cost businesses more than £20 billion over the past few years.

And Microsoft brings more bad news, with its recent findings showing that they’re getting both more destructive and harder to detect.

So, what can you do to protect your business from BEC attacks?

Here’s our advice:

  1. Train your employees: They are the first line of defence against BEC attacks. They need to know how to spot phishing emails, suspicious requests, and fake invoices. Train them regularly on cyber security best practice, like strong passwords, multi-factor authentication, and secure file sharing.
  2. Use advanced email security solutions: Basic email protections like antispam and antivirus software are no longer enough to block BEC attacks. You need more advanced solutions that use artificial intelligence and machine learning to detect and prevent these attacks in real-time. Look for email security providers that offer features like domain-based message authentication, reporting, and conformance (DMARC), sender policy framework (SPF), and DomainKeys Identified Mail (DKIM). Microsoft 365 supports this – but only if the features have been setup correctly.
  3. Set up transaction verification procedures: Before transferring funds or sensitive information, establish a verification process that confirms the authenticity of the request. This could include a phone call, video conference, or face-to-face meeting. Don’t rely on email alone to confirm these types of requests.
  4. Monitor your email traffic: Regularly monitor your email traffic for anomalies and unusual patterns. Look for signs like unknown senders, unusual login locations, changes to email settings or forwarding rules, and unexpected emails. Make sure you have a clear protocol in place for reporting and responding to any suspicious activity.
  5. Keep your software up to date: Ensure that you’re always running the latest version of your operating system, email software, and other software applications. These updates often include vital security patches that address known vulnerabilities.

BEC attacks are becoming more common and more sophisticated, but with the right awareness, training, and security solutions, you can protect your business.

Don’t wait until it’s too late – take action today to keep your business safe.

If you want to know more about how to protect your business from cyber threats, our team is always ready to help you. Book in a free consultation!

Any questions?

If you have any questions in relation to this blog post, contact us. We would be more than happy to help!

Subscribe to our newsletter

Here at Wight Computers Ltd we take your privacy very seriously, and will only use your personal information to communicate with you and provide the products and services you have requested from us.

You can unsubscribe or change your preferences at any time by clicking the link in the footer of our emails.

For more information, please read our Privacy Policy.

Share this blog

More Articles

Tom Smith and Andrew Nordbruch from Wight Computers at Expo 2023. Credit - Robin Crossley Photography

Wight Computers at Expo 2023

This week saw the return of the Isle of Wight Chamber of Commerce’s annual Business Expo, at a new venue, within the grounds of Ryde School. After taking a break last year, we were back exhibiting again with the theme “Secure The Office”.

Read more