Business Email Compromise in 2026: A Defense Playbook for Indian Enterprises

  • Home
  • Business Email Compromise in 2026: A Defense Playbook for Indian Enterprises
Business Email Compromise in 2026: A Defense Playbook for Indian Enterprises
Business Email Compromise in 2026: A Defense Playbook for Indian Enterprises
Business Email Compromise in 2026: A Defense Playbook for Indian Enterprises
Business Email Compromise in 2026: A Defense Playbook for Indian Enterprises
Business Email Compromise in 2026: A Defense Playbook for Indian Enterprises

Business Email Compromise (BEC) has quietly become one of the most expensive cyber threats facing Indian enterprises in 2026. It rarely makes the headlines that ransomware does, yet a single well-timed fraudulent invoice or a spoofed “CEO” payment request can drain crores in minutes — with no malware, no breached firewall, and no obvious alarm. For finance, manufacturing, and services companies running lean security teams, BEC is the attack that slips through precisely because it targets people, not systems.

At PJ Networks, we see the same pattern across clients: the technical perimeter is reasonably hardened, but the email and identity layer is wide open. This playbook breaks down why BEC works, what changed in 2026, and the layered defense Indian enterprises can put in place — including the compliance obligations under the DPDP Act and CERT-In rules that now sit on top of the incident itself.

Why BEC works when firewalls don’t stop it

BEC is social engineering wearing a business suit. Instead of exploiting a software vulnerability, the attacker exploits trust, authority, and urgency. A typical chain looks like this:

  • Reconnaissance: The attacker studies your org chart on LinkedIn, identifies who approves payments, and learns your vendor names.
  • Access or impersonation: They either compromise a real mailbox (via a phishing page that harvests credentials) or register a look-alike domain that’s one character off your real one.
  • The ask: A finance executive receives an email — apparently from the MD or a known vendor — requesting an urgent wire transfer, a change of bank account details, or release of a “pending” invoice.
  • The payout: Because the request looks legitimate and carries authority, it gets actioned before anyone verifies out-of-band.

None of this trips a traditional firewall, because nothing malicious crosses the wire. That is exactly why email security, identity, and human process — not just network controls — decide whether BEC succeeds.

What changed in 2026: AI-crafted fraud

Two shifts have made BEC dramatically more effective this year. First, generative AI has eliminated the broken-English tell that once gave phishing away. Fraudulent emails now mirror your house style, sign-off, and even past thread context. Second, voice and video deepfakes have moved from novelty to operational tooling — a finance manager may receive a follow-up “call” that sounds convincingly like the person who supposedly sent the email.

The defensive takeaway is blunt: you can no longer train staff to “spot the fake” by looks alone. Verification has to become a process, enforced by technology, not a judgment call made under pressure.

A familiar scenario. A mid-sized manufacturer’s accounts team receives an email from a long-standing supplier: “We’ve changed banks — please update our account details for this month’s payment.” The thread history is real, the signature is perfect, the amount is routine. The only thing wrong is one letter in the reply-to domain. The payment of ₹42 lakh clears before anyone calls the supplier to confirm. The supplier never sees a rupee. This is not a hypothetical — variations of it land in Indian finance inboxes every week.

A layered defense playbook

1. Lock down email authentication (SPF, DKIM, DMARC)

Most successful impersonation attacks exploit domains that have no enforced DMARC policy. Publishing SPF and DKIM is only half the job — without a DMARC policy set to quarantine or reject, spoofed mail still lands in inboxes. We routinely find Indian enterprises stuck on p=none, which monitors but blocks nothing. Moving to enforcement is the single highest-leverage control against domain spoofing.

2. Deploy a secure email gateway

A modern secure email gateway such as FortiMail inspects inbound mail for impersonation patterns, look-alike domains, malicious links, and anomalous sender behavior — catching the messages that authentication alone won’t. Crucially, it also scans outbound mail, which helps contain a mailbox that has already been compromised.

3. Make identity the new perimeter (MFA + ZTNA)

BEC frequently begins with a stolen password. Phishing-resistant multi-factor authentication on every mailbox and admin account turns a harvested credential into a dead end. Pairing this with Zero Trust Network Access (ZTNA) ensures that even valid credentials only grant access to what a role genuinely needs — limiting how far an attacker can move if they do get in.

4. Build an out-of-band verification rule

The strongest single process control is also the cheapest: any change to bank details, or any payment above a defined threshold, must be verified through a second channel — a phone call to a known number, never the one in the email. Bake this into finance SOPs so it is mandatory, not optional.

5. Monitor continuously with a 24/7 SOC

BEC leaves subtle fingerprints: an impossible-travel login, a new inbox forwarding rule, a mailbox accessed from an unfamiliar geography at 3 a.m. A 24/7 Security Operations Centre correlates these signals and flags account takeover before the fraudulent payment goes out. For most Indian enterprises, a managed SOC is far more cost-effective than staffing this in-house around the clock.

The compliance layer: DPDP Act and CERT-In

A BEC incident in India is no longer just a financial loss — it is a regulatory event. If personal data is exposed in the compromise, the Digital Personal Data Protection (DPDP) Act obligations are triggered. Separately, CERT-In’s directions require reporting of cyber incidents within six hours of detection. That clock is unforgiving, and organizations without a prepared incident response plan routinely miss it. Your BEC response plan and your compliance reporting plan must be the same document, rehearsed in advance.

Five mistakes that leave the door open

In our assessments across Indian enterprises, the same gaps recur. If any of these describe your organization, BEC has a clear path in:

  • DMARC left on p=none: You’re monitoring spoofing but doing nothing to stop it.
  • MFA on “important” accounts only: Attackers target whichever mailbox is unprotected, not the one you’d expect.
  • No look-alike domain monitoring: A domain one character off yours can be registered in minutes and you’d never know.
  • Payment changes approved over email: If a bank-detail change never requires a phone call, the control simply doesn’t exist.
  • No after-hours monitoring: Account takeovers are timed for nights and weekends precisely because no one is watching.

A practical 30-day rollout

You don’t need a year-long program to materially reduce BEC risk. A focused 30-day sprint moves the needle:

  • Week 1: Audit your DMARC posture and move enforcement toward quarantine; enable MFA on all mailboxes and admin accounts.
  • Week 2: Deploy or tune a secure email gateway; register and monitor look-alike domains.
  • Week 3: Formalize the out-of-band payment verification SOP; run a targeted phishing simulation for finance and leadership.
  • Week 4: Stand up SOC monitoring for identity anomalies; write and rehearse a BEC incident response runbook aligned to the CERT-In six-hour window.

How PJ Networks helps

PJ Networks delivers this as an integrated managed service: FortiMail-based email security, FortiGate and ZTNA for identity-first access, and a 24/7 NOC/SOC that watches for account takeover the moment it begins. We help Indian enterprises move from a monitor-only posture to enforced controls — and we keep your incident response and CERT-In reporting rehearsed, so a bad day stays a manageable one.

If your finance team could action a convincing fraudulent payment request today without a mandatory second-channel check, BEC is an open risk worth closing now. Talk to PJ Networks about an email security and identity assessment for your organization.

Leave a Reply

Your email address will not be published. Required fields are marked *