Business email compromise does not require malware, a zero day, or much skill. It requires one valid login and one person willing to act on an urgent email. That is why the defenses that work are a mix of identity controls and payment process, not a better spam filter alone.
1. Phishing-resistant multi-factor authentication
Text message codes stop casual attacks and fall to real-time phishing kits that relay the code while the user is still typing it. Number matching, authenticator apps, and hardware keys are the meaningful upgrade. Roll it out per account, including shared and service mailboxes, which is where the gaps always hide.
2. Conditional access
Decide who can sign in from where, on what kind of device, and under what risk score. Blocking legacy authentication protocols alone removes a large share of successful mailbox takeovers, because those protocols bypass multi-factor entirely. This is the core of a zero trust approach.
3. A payment verification rule nobody can skip
Any change to banking details gets verified by phone, using a number already on file, never a number in the email. Write it down, make it mandatory, and make it apply to executives too. Most successful fraud depends on one person deciding the rule does not apply this time because the request looks urgent.
4. Mail authentication and filtering
SPF, DKIM, and an enforced DMARC policy stop attackers from sending as your domain. Advanced filtering catches lookalike domains, display name impersonation, and credential harvesting pages before delivery. See email security and spam filtering.
5. Alerting on the attacker playbook
Alert on new forwarding rules, new OAuth consents, impossible travel sign-ins, and mass mailbox searches. Those four signals catch most compromises within hours instead of weeks, and hours is the difference between an incident and a loss.
6. Endpoint control and training
Default-deny application control stops credential stealers and remote access tools from running at all, and ongoing cyber awareness training keeps staff able to spot a lookalike login page. Technology narrows the attack surface, people close the last gap.
If you are past prevention and dealing with an active compromise, start with what to do when your business email is compromised and call 864-224-0008.

