BEC Defense Package

Email Resilience Program — Defense in Depth for Mid-Market (50–500 seats)

$2.77B
FBI-reported BEC losses 2024
81%
of investigated incidents are BEC
70%
weekly attack probability <1K employees
79%
MFA bypassed via AiTM proxies
Methodology: BEC triage is context-dependent — the same email pattern means different things depending on tenant MFA posture and mail flow configuration. See Investigation Automation for the framework. BEC detection rules also demonstrate the Detection Engineering three-tier model: universal impersonation patterns at the baseline, tenant-specific mail flow rules at the profile tier.
Incident in progress? The response steps are on BEC Response. This page is how you get ready.
Defense in Depth Principle: No single control stops BEC. But if an attacker has to bypass your impersonation rules, then your origin-checking password manager, then your conditional access, then your behavioral AI, then your out-of-band verification — the economics don't work for them anymore. They move on.

Entry Point: BEC Maturity Assessment

Run CISA ScubaGear to produce an automated compliance report. Score each OODA loop (red/amber/green). Hand over the quick wins during the assessment — value delivered before the engagement is even scoped.
1–2 days Entry point / loss leader

Tools

  • CISA ScubaGear — PowerShell M365 compliance audit (Entra ID, Defender, Exchange Online)
  • Microsoft Secure Score — built-in posture dashboard at security.microsoft.com
  • Forwarding rule audit — immediate compromise detection (see PowerShell below)

Immediate Compromise Check

Get-Mailbox -ResultSize Unlimited | Get-InboxRule | Where-Object {
  $_.ForwardTo -or $_.ForwardAsAttachmentTo -or $_.RedirectTo
} | Select-Object MailboxOwnerId, Name, ForwardTo, RedirectTo

If this returns results — triage immediately. The mailbox may already be compromised.

Output

One-page maturity scorecard (red/amber/green per loop) + prioritized roadmap with effort/impact per recommendation. Action cards, not a 60-page report.

1 Containment — BEC Incident Readiness
Active incident: compromised mailbox, wire in flight, attacker in the inbox. Can you respond within 60 minutes?
Quick Wins (Day 0, Free)
  • Print bank fraud department phone numbers for every bank the company uses — tape to finance monitors
    5 minFree
  • Create #security-incidents channel in Teams/Slack — known place to raise alarms
    5 minFree
  • Document who can revoke sessions in Entra right now (if nobody knows, that's finding #1)
    15 minFree
  • Plant Canarytokens — fake "Wire Transfer Procedures.docx" in SharePoint. Compromised account touches it → instant alert
    30 minFree
  • Download O365 Investigation Tooling scripts — DumpDelegatesandForwardingRules.ps1 and RemediateBreachedAccount.ps1 ready to go
    15 minFree
Core Engagement (1 day)
  • BEC incident action cards (max 2 pages): compromised mailbox response, wire fraud response, session revocation
  • Pre-built PowerShell/Graph API lockdown scripts tested against the client's tenant
  • 2-hour tabletop: "CFO's mailbox is compromised, wire in flight"
Target State

Automated playbook: compromised mailbox detected → sessions revoked → forwarding rules purged → forensic export triggered → finance notified — within minutes, not hours.

2 Detection — See It When It Happens
Can you detect BEC when it arrives? Not just known-bad URLs, but social engineering with no payload.
Quick Wins (Day 0, Free)
  • Enable First Contact Safety Tip in Defender — warns on first-time senders (single checkbox, off by default)
    5 minFree
  • Enable external email warning banner via Exchange transport rule
    10 minFree
  • Turn on all three impersonation safety tips (user, domain, unusual characters) — off by default
    5 minFree
  • Deploy Check by CyberDrain — open-source browser extension detecting fake M365 login pages (AiTM proxy detection)
    1 hourFree / OSS
  • Block external auto-forwarding: New-TransportRule -Name "Block External Auto-Forward" -FromScope InOrganization -SentToScope NotInOrganization -MessageTypeMatches AutoForward
    10 minFree
  • Enable Outlook built-in Report button — users report phishing from any client, feeds into Defender
    10 minFree
Core Engagement (2–3 days)
  • Universal impersonation protection: register ALL employees' personal emails, freemail-only trigger, silent quarantine — not just VIPs
  • Add up to 350 protected users to Defender impersonation protection (executives, finance, board, key vendors)
  • Behavioral AI deployment: vendor selection + API integration (Abnormal, IRONSCALES free tier up to 500 mailboxes, Huntress)
  • Deploy Sublime Security (MIT license) — open-source email detection with 3,478-commit rule library
  • OAuth app consent audit + restrictive policy (block user consent for mail.read/mail.send)
  • Inbox rule monitoring: automated alerts on forwarding, auto-delete, and mark-as-read rules
  • Detection validation: controlled BEC simulations through the pipeline
Target State

BEC attempts generate alerts within minutes. Freemail impersonation silently quarantined — attacker gets no bounce, no rejection, burns time on a dead end. Compromised-account indicators trigger automated alerts. Zero unmonitored mailboxes.

3 Posture — Harden What You Already Own
Most mid-market orgs already pay for M365 Business Premium ($22/seat) which includes conditional access, Safe Links, Safe Attachments, and Entra P1. The gap is configuration, not licensing.
Quick Wins (Day 0, Free)
  • Enable Standard Preset Security Policy — single toggle that activates Safe Links, Safe Attachments, impersonation protection, phishing threshold 3, quarantine for phishing. The #1 most underused M365 feature.
    15 minFree (included in M365)
  • Enable Security Defaults in Entra if CA not configured (MFA for all + block legacy auth)
    30 minFree (every M365 tier)
  • Block legacy auth protocols (IMAP/POP3/SMTP basic auth) — 99% of password spray attacks use these
    15 minFree
  • Block device code flow in conditional access — rarely used legitimately, frequently used by attackers
    10 minFree
  • Force password manager adoption org-wide — autofill-only-on-correct-domain = free origin validation
    Policy decisionFree
  • Push Windows Hello for Business to all managed devices — device-bound passkey, zero hardware cost
    1 hourFree
  • Set phishing email threshold from 1 (default) to 3 or 4
    5 minFree
Core Engagement (2–3 days)
  • Conditional access deployment: device compliance, risk-based policies (impossible travel, anonymous IP, unfamiliar sign-in)
  • FIDO2/passkey rollout: phased by risk tier — finance + executives first (hardware keys ~€50/key), then general workforce (Windows Hello / synced passkeys)
  • Safe Links + Safe Attachments full configuration beyond preset defaults
  • DMARC enforcement path: SPF/DKIM audit → p=none → p=quarantine → p=reject with parsedmarc monitoring
  • DKIM signing enabled for all custom domains (off by default, requires 2 DNS CNAMEs)
  • Continuous Access Evaluation (CAE): token revocation on risk signal change
Target State

All authentication phishing-resistant (FIDO2/passkeys). No email access from unmanaged devices. DMARC at p=reject. AiTM proxy attacks structurally impossible — stolen session tokens useless from attacker's device.

4 Vulnerability Management — Stay Hardened
Controls configured once will drift. New employees, stale exceptions, accumulating OAuth grants. Continuous posture monitoring catches regression before attackers do.
Quick Wins (Day 0, Free)
  • Export MFA exception list — review it today. Most have stale exceptions from years ago
    15 minFree
  • Run Get-InboxRule across all mailboxes — find existing forwarding rules
    15 minFree
  • Audit admin OAuth consent grants:
    Get-MgServicePrincipal -All | Get-MgServicePrincipalOauth2PermissionGrant | Where-Object {$_.ConsentType -eq "AllPrincipals"}
    15 minFree
  • Review Entra sign-in logs for last 7 days — filter on "risky sign-ins"
    15 minFree
  • Check DMARC reports for last 30 days via parsedmarc
    30 minFree / OSS
  • Find dormant accounts: InactiveUsersLast90Days.ps1 from O365 Investigation Tooling
    10 minFree
  • Schedule monthly CISA ScubaGear re-scan to track drift
    15 minFree
Core Engagement (1 day + cadence)
  • Drift detection report template: automated monthly checks (employees without FIDO2, MFA exceptions, missing personal email registrations, new OAuth consents, new forwarding rules, CA policy changes, DMARC alignment failures)
  • Onboarding/offboarding integration: personal email registration as day-1 step, immediate revocation on departure
  • Quarterly posture review: re-run scorecard, compare to baseline, flag regression
Target State

No control degrades silently. Every new employee protected from day one. Every departure fully revoked. Drift caught within one review cycle.

5 Structural — Make BEC Architecturally Difficult
Move from "defended against BEC" to "BEC is structurally difficult regardless of social engineering sophistication."
Quick Wins (Day 0, Free)
  • Write the out-of-band verification rule: "Any payment request over €X requires a phone call to a number already on file — not the number in the email." Email it from the CEO to finance today.
    10 minFree
  • Add personal email registration to the IT onboarding checklist (spreadsheet is fine to start)
    10 minFree
  • Enable Microsoft Secure Score and assign improvement actions to owners
    30 minFree
Core Engagement (3–5 days)
  • Browser isolation architecture: email links render in sandboxed Chromium, credential pages blocked on uncategorized sites (Cloudflare, Zscaler, Menlo — vendor selection based on existing stack)
  • Content Disarm and Reconstruction (CDR): all inbound documents stripped of active content, rebuilt clean — zero-day proof by design (OPSWAT, Check Point SandBlast)
  • Out-of-band verification as formal policy: documented, trained, exception-audited — covers wire transfers, account changes, sensitive requests
  • Universal impersonation protection as permanent capability: personal email registration automated via identity provider, freemail trigger with silent quarantine
  • Board reporting template: quarterly email security posture — incidents blocked, controls active, drift status, investment vs. prevented loss
  • NIS2 Article 21 alignment: map all controls to requirements (incident handling, business continuity, supply chain, access control)
Target State

BEC is architecturally difficult. New attack variants hit structural barriers (isolation, CDR, device trust) regardless of sophistication. Compliance posture demonstrable to regulators.

Program Economics (200-seat reference)

Engagement Duration Investment
Assessment + quick wins handoff 1–2 days €1,250 – 2,500
1 Containment 1 day €1,250
2 Detection 2–3 days €2,500 – 3,750
3 Posture 2–3 days €2,500 – 3,750
4 Vulnerability Management 1 day + quarterly €1,250 + €5,000/yr
5 Structural 3–5 days €3,750 – 6,250
Full program 10–15 days €12,500 – 18,750 + retainer
ROI: One prevented BEC wire transfer (average €110K–€1.1M for SMBs) pays for the entire program. The assessment alone at €1,250–2,500 is the entry point.

Defense in Depth: Free Afternoon Deploy

13 controls deployable in a single afternoon with zero budget. Each individually imperfect. Stacked together, the attacker economics don't work anymore.
# Action Time Tool
1 Enable Standard Preset Security Policy 15 min M365 Defender portal
2 Run forwarding rule audit 15 min Exchange PowerShell
3 Block external auto-forwarding 10 min Exchange transport rule
4 Enable external email banner 10 min Exchange transport rule
5 Enable First Contact Safety Tip 5 min Defender anti-phishing
6 Block legacy auth + device code flow 30 min Entra Conditional Access
7 Run CISA ScubaGear assessment 1 hour ScubaGear
8 Deploy AiTM browser detection 1 hour Check by CyberDrain
9 Set up DMARC monitoring 2 hours parsedmarc
10 Plant canary documents in SharePoint 30 min Canarytokens
11 Deploy open-source email detection rules 2 hours Sublime Security
12 Push Windows Hello for Business 1 hour Intune / Group Policy
13 Send OOB verification rule to finance 10 min Email from CEO

Free / Open-Source Tools

Key PowerShell Commands

# Detect forwarding rules (BEC persistence)
Get-Mailbox -ResultSize Unlimited |
  Get-InboxRule | Where-Object {
    $_.ForwardTo -or $_.RedirectTo
  }

# Find SMTP forwarding
Get-Mailbox -ResultSize Unlimited |
  Where-Object {
    $_.ForwardingSMTPAddress -ne $null
  }

# Block external auto-forward
New-TransportRule `
  -Name "Block External Auto-Forward" `
  -FromScope InOrganization `
  -SentToScope NotInOrganization `
  -MessageTypeMatches AutoForward

# Audit OAuth consent grants
Get-MgServicePrincipal -All |
  Get-MgServicePrincipalOauth2PermissionGrant |
  Where-Object {
    $_.ConsentType -eq "AllPrincipals"
  }