Entry Point: BEC Maturity Assessment
Tools
- CISA ScubaGear — PowerShell M365 compliance audit (Entra ID, Defender, Exchange Online)
- Microsoft Secure Score — built-in posture dashboard at
security.microsoft.com - Forwarding rule audit — immediate compromise detection (see PowerShell below)
Immediate Compromise Check
Get-Mailbox -ResultSize Unlimited | Get-InboxRule | Where-Object {
$_.ForwardTo -or $_.ForwardAsAttachmentTo -or $_.RedirectTo
} | Select-Object MailboxOwnerId, Name, ForwardTo, RedirectTo
If this returns results — triage immediately. The mailbox may already be compromised.
Output
One-page maturity scorecard (red/amber/green per loop) + prioritized roadmap with effort/impact per recommendation. Action cards, not a 60-page report.
- Print bank fraud department phone numbers for every bank the company uses — tape to finance monitors
- Create
#security-incidentschannel in Teams/Slack — known place to raise alarms - Document who can revoke sessions in Entra right now (if nobody knows, that's finding #1)
- Plant Canarytokens — fake "Wire Transfer Procedures.docx" in SharePoint. Compromised account touches it → instant alert
- Download O365 Investigation Tooling scripts —
DumpDelegatesandForwardingRules.ps1andRemediateBreachedAccount.ps1ready to go
- BEC incident action cards (max 2 pages): compromised mailbox response, wire fraud response, session revocation
- Pre-built PowerShell/Graph API lockdown scripts tested against the client's tenant
- 2-hour tabletop: "CFO's mailbox is compromised, wire in flight"
Automated playbook: compromised mailbox detected → sessions revoked → forwarding rules purged → forensic export triggered → finance notified — within minutes, not hours.
- Enable First Contact Safety Tip in Defender — warns on first-time senders (single checkbox, off by default)
- Enable external email warning banner via Exchange transport rule
- Turn on all three impersonation safety tips (user, domain, unusual characters) — off by default
- Deploy Check by CyberDrain — open-source browser extension detecting fake M365 login pages (AiTM proxy detection)
- Block external auto-forwarding:
New-TransportRule -Name "Block External Auto-Forward" -FromScope InOrganization -SentToScope NotInOrganization -MessageTypeMatches AutoForward - Enable Outlook built-in Report button — users report phishing from any client, feeds into Defender
- Universal impersonation protection: register ALL employees' personal emails, freemail-only trigger, silent quarantine — not just VIPs
- Add up to 350 protected users to Defender impersonation protection (executives, finance, board, key vendors)
- Behavioral AI deployment: vendor selection + API integration (Abnormal, IRONSCALES free tier up to 500 mailboxes, Huntress)
- Deploy Sublime Security (MIT license) — open-source email detection with 3,478-commit rule library
- OAuth app consent audit + restrictive policy (block user consent for
mail.read/mail.send) - Inbox rule monitoring: automated alerts on forwarding, auto-delete, and mark-as-read rules
- Detection validation: controlled BEC simulations through the pipeline
BEC attempts generate alerts within minutes. Freemail impersonation silently quarantined — attacker gets no bounce, no rejection, burns time on a dead end. Compromised-account indicators trigger automated alerts. Zero unmonitored mailboxes.
- Enable Standard Preset Security Policy — single toggle that activates Safe Links, Safe Attachments, impersonation protection, phishing threshold 3, quarantine for phishing. The #1 most underused M365 feature.
- Enable Security Defaults in Entra if CA not configured (MFA for all + block legacy auth)
- Block legacy auth protocols (IMAP/POP3/SMTP basic auth) — 99% of password spray attacks use these
- Block device code flow in conditional access — rarely used legitimately, frequently used by attackers
- Force password manager adoption org-wide — autofill-only-on-correct-domain = free origin validation
- Push Windows Hello for Business to all managed devices — device-bound passkey, zero hardware cost
- Set phishing email threshold from 1 (default) to 3 or 4
- Conditional access deployment: device compliance, risk-based policies (impossible travel, anonymous IP, unfamiliar sign-in)
- FIDO2/passkey rollout: phased by risk tier — finance + executives first (hardware keys ~€50/key), then general workforce (Windows Hello / synced passkeys)
- Safe Links + Safe Attachments full configuration beyond preset defaults
- DMARC enforcement path: SPF/DKIM audit → p=none → p=quarantine → p=reject with parsedmarc monitoring
- DKIM signing enabled for all custom domains (off by default, requires 2 DNS CNAMEs)
- Continuous Access Evaluation (CAE): token revocation on risk signal change
All authentication phishing-resistant (FIDO2/passkeys). No email access from unmanaged devices. DMARC at p=reject. AiTM proxy attacks structurally impossible — stolen session tokens useless from attacker's device.
- Export MFA exception list — review it today. Most have stale exceptions from years ago
- Run
Get-InboxRuleacross all mailboxes — find existing forwarding rules - Audit admin OAuth consent grants:
Get-MgServicePrincipal -All | Get-MgServicePrincipalOauth2PermissionGrant | Where-Object {$_.ConsentType -eq "AllPrincipals"} - Review Entra sign-in logs for last 7 days — filter on "risky sign-ins"
- Check DMARC reports for last 30 days via parsedmarc
- Find dormant accounts:
InactiveUsersLast90Days.ps1from O365 Investigation Tooling - Schedule monthly CISA ScubaGear re-scan to track drift
- Drift detection report template: automated monthly checks (employees without FIDO2, MFA exceptions, missing personal email registrations, new OAuth consents, new forwarding rules, CA policy changes, DMARC alignment failures)
- Onboarding/offboarding integration: personal email registration as day-1 step, immediate revocation on departure
- Quarterly posture review: re-run scorecard, compare to baseline, flag regression
No control degrades silently. Every new employee protected from day one. Every departure fully revoked. Drift caught within one review cycle.
- Write the out-of-band verification rule: "Any payment request over €X requires a phone call to a number already on file — not the number in the email." Email it from the CEO to finance today.
- Add personal email registration to the IT onboarding checklist (spreadsheet is fine to start)
- Enable Microsoft Secure Score and assign improvement actions to owners
- Browser isolation architecture: email links render in sandboxed Chromium, credential pages blocked on uncategorized sites (Cloudflare, Zscaler, Menlo — vendor selection based on existing stack)
- Content Disarm and Reconstruction (CDR): all inbound documents stripped of active content, rebuilt clean — zero-day proof by design (OPSWAT, Check Point SandBlast)
- Out-of-band verification as formal policy: documented, trained, exception-audited — covers wire transfers, account changes, sensitive requests
- Universal impersonation protection as permanent capability: personal email registration automated via identity provider, freemail trigger with silent quarantine
- Board reporting template: quarterly email security posture — incidents blocked, controls active, drift status, investment vs. prevented loss
- NIS2 Article 21 alignment: map all controls to requirements (incident handling, business continuity, supply chain, access control)
BEC is architecturally difficult. New attack variants hit structural barriers (isolation, CDR, device trust) regardless of sophistication. Compliance posture demonstrable to regulators.
Program Economics (200-seat reference)
| Engagement | Duration | Investment |
|---|---|---|
| Assessment + quick wins handoff | 1–2 days | €1,250 – 2,500 |
| 1 Containment | 1 day | €1,250 |
| 2 Detection | 2–3 days | €2,500 – 3,750 |
| 3 Posture | 2–3 days | €2,500 – 3,750 |
| 4 Vulnerability Management | 1 day + quarterly | €1,250 + €5,000/yr |
| 5 Structural | 3–5 days | €3,750 – 6,250 |
| Full program | 10–15 days | €12,500 – 18,750 + retainer |
Defense in Depth: Free Afternoon Deploy
| # | Action | Time | Tool |
|---|---|---|---|
| 1 | Enable Standard Preset Security Policy | 15 min | M365 Defender portal |
| 2 | Run forwarding rule audit | 15 min | Exchange PowerShell |
| 3 | Block external auto-forwarding | 10 min | Exchange transport rule |
| 4 | Enable external email banner | 10 min | Exchange transport rule |
| 5 | Enable First Contact Safety Tip | 5 min | Defender anti-phishing |
| 6 | Block legacy auth + device code flow | 30 min | Entra Conditional Access |
| 7 | Run CISA ScubaGear assessment | 1 hour | ScubaGear |
| 8 | Deploy AiTM browser detection | 1 hour | Check by CyberDrain |
| 9 | Set up DMARC monitoring | 2 hours | parsedmarc |
| 10 | Plant canary documents in SharePoint | 30 min | Canarytokens |
| 11 | Deploy open-source email detection rules | 2 hours | Sublime Security |
| 12 | Push Windows Hello for Business | 1 hour | Intune / Group Policy |
| 13 | Send OOB verification rule to finance | 10 min | Email from CEO |
Free / Open-Source Tools
- CISA ScubaGear — M365 tenant compliance audit
- parsedmarc — DMARC report parser + dashboards
- Sublime Security — Email detection platform (MIT)
- Check — M365 phishing page detector extension
- Canarytokens — Free tripwires / honeydocs
- O365 Investigation Tooling — IR scripts
- MXToolbox — SPF/DKIM/DMARC validation
Key PowerShell Commands
# Detect forwarding rules (BEC persistence)
Get-Mailbox -ResultSize Unlimited |
Get-InboxRule | Where-Object {
$_.ForwardTo -or $_.RedirectTo
}
# Find SMTP forwarding
Get-Mailbox -ResultSize Unlimited |
Where-Object {
$_.ForwardingSMTPAddress -ne $null
}
# Block external auto-forward
New-TransportRule `
-Name "Block External Auto-Forward" `
-FromScope InOrganization `
-SentToScope NotInOrganization `
-MessageTypeMatches AutoForward
# Audit OAuth consent grants
Get-MgServicePrincipal -All |
Get-MgServicePrincipalOauth2PermissionGrant |
Where-Object {
$_.ConsentType -eq "AllPrincipals"
}