The Protocol CollectiveAll guides

Guide

Controls against wire fraud and business email compromise

Business email compromise turns a routine payment into a loss by hijacking trust rather than systems. An attacker impersonates an executive, a supplier, or a lawyer, often from a real but compromised mailbox, and asks for a wire or a change of bank details. The request looks normal because it usually is normal in every respect except who sent it. Once a wire settles, recovery is difficult and time-sensitive, which is why prevention carries almost all the weight.

Verification that resists impersonation

The core control is out-of-band verification. Any new payee, or any change to existing bank details, must be confirmed by calling a number already on file, never a number supplied in the request itself. High-value or unusual payments should require dual approval by two people, with the second reviewer checking the payee against records rather than the email thread. Staff need to know that urgency and secrecy are the two most common pressure tactics, and that a genuine executive expects verification rather than resenting it.

Detection and fast recovery

Layered defences reduce exposure: email authentication to cut spoofing, flags on external senders, alerts on inbox rules that auto-forward or hide messages, and monitoring for lookalike domains registered against your name. When a fraudulent wire does go out, speed decides the outcome. A documented playbook should name who contacts the sending bank to request a recall, who notifies law enforcement so a financial-fraud kill chain can be attempted, and the deadlines that apply. Every hour lost lowers the odds of getting funds back.

Controls you own

The wire fraud and business email compromise control set is available as an owned, single-file, regulator-mapped dashboard from The Protocol Collective. You pay once, own it outright, receive updates for life, and it is built from public frameworks. It brings verification steps, approval thresholds, detection signals, and the recovery playbook into one structured reference, so the response is decided before an attacker tests it, not during.

Explore The Protocol Collective

General information about compliance and program structure, not regulatory, legal, tax or financial advice, and no promise of any examination or audit outcome. Built from public frameworks.