A Business Email Compromise Response Plan Leaders Can Use

A first-response framework for suspicious mailbox activity, payment changes, identity containment, evidence, communication, and coordinated recovery.
Protect the business process
If payment or banking information may have changed, contact the appropriate financial institution through a known channel and follow the organization’s approved escalation process. Do not rely on contact details from the suspicious message.
Contain identity carefully
Reset credentials, revoke sessions, review authentication methods, mailbox rules, forwarding, application consent, and related accounts as appropriate. Preserve evidence before it is overwritten.
Determine scope
Review sign-ins, sent items, deleted items, rules, file access, account changes, and communications with customers or vendors. Coordinate with security, legal, insurance, leadership, and law enforcement as appropriate.
Recover and learn
Correct fraudulent instructions, notify affected parties through verified channels, monitor for follow-on activity, and fix the process weakness. This guide is not legal or incident-response advice for every situation.
Business email compromise response checklist
- Escalate payment risk immediately
- Use known contact channels
- Contain sessions and access
- Preserve and review evidence
- Coordinate recovery and lessons learned
How AMD Technology helps with email compromise response
AMD Technology can help clarify requirements, evaluate options, coordinate providers and projects, and support an appropriate next step. Recommendations should reflect the organization’s actual environment, priorities, budget, contracts, and risk profile.
Share
Get Insights Delivered to Your Inbox
Practical technology advice for growing businesses - straight to your inbox. No spam, unsubscribe anytime.
