MSG / MSG-03
Business email compromise risk reduction
Combining email, identity and business-process controls to reduce fraud that may contain no malicious attachment, including payment requests.

WHEN IT HELPS
A focused response
to a defined need.
Finance leadership or CISO; executive impersonation, mailbox compromise or bank-detail change requests.
SCOPE & OUTCOMES
What the engagement covers.
Scope
- Analyse fraud scenarios
- protect accounts
- impersonation alerts, mailbox-rule review and independent verification
Deliverables
- Approval workflows
- configured controls
- alert procedures and finance response guides
Acceptance evidence
A simulated fraudulent request is detected, rejected or independently verified under approved rules.
DELIVERY
How the work is structured.
Approach
Map domains and senders; select controls; test in pilot/observation mode; enable gradually; organise exceptions, alerts and support.
Prerequisites & responsibilities
Customer: email/DNS administrators, sending teams and sender approval. Provider: configuration and tests. For financial fraud, involve payment owners.
Scope factors
Mailboxes, domains, volume, connectors, third-party senders and operating scope. Proofpoint or other licenses, storage and recurring service are separate from the project.
Questions to clarify
Which requests trigger payment? Who can change a payee? Are sensitive mailboxes protected and monitored?
IMPORTANT BOUNDARIES
Email from a genuine account can be fraudulent; financial controls and incident investigation are distinct from filtering.
No solution blocks every fraud attempt. Overly strict policies can block legitimate messages; pilots, exceptions and business procedures remain essential.
IN PRACTICE
Illustrative situations.
These examples describe possible engagements and target outcomes. They are not customer references or achieved results.
Scenario 01
A fake supplier requests changed bank details. Project: combine email authentication with an independent callback process. Target outcome: prevent unverified changes; software alone does not approve payments.
Scenario 02
An executive mailbox is compromised and used for internal requests. Project: strengthen access, forwarding controls and reporting. Target outcome: improved visibility of suspicious behaviour; existing access is reviewed where compromise is suspected.
Technology and reference context
Email protection, MFA, identity logs and business verification procedures.
The final technology set is agreed during scoping, based on interoperability, licensing, access rights and operating requirements.
CONNECTED SERVICES
Build the next step.
These services can complement the engagement. They are not automatically included.
START A CONVERSATION
Make the scope clear.
We will clarify the objective, dependencies and responsibilities of this service before proposing delivery.
