MonorsMonors
Cybersecurity13 min read

Business Email Compromise Prevention for Toronto Small Businesses: 12 Controls for 2026

Business email compromise succeeds when a believable message meets a weak business process. The strongest defence combines secure accounts and domains with a rule that no urgent email can quietly change where money goes.

By Monors Editorial Team · Reviewed and updated July 30, 2026

In this guide

Key takeaways

  • Treat every request to change payment instructions, payroll deposits, account recovery, or sensitive-data delivery as a controlled business event—not an ordinary email.
  • Require independent verification through a known phone number or approved system before changing financial details or releasing a high-risk payment.
  • Protect email with phishing-resistant multifactor authentication where practical, least privilege, SPF, DKIM, DMARC, anti-phishing policies, logging, and tested alerts.
  • If fraud or account compromise is suspected, contact the financial institution immediately, contain the account, preserve evidence, and report quickly.

The email arrives at 3:42 p.m. on a busy Thursday. A familiar supplier says its banking information has changed and asks that tomorrow’s payment go to a new account. The signature looks right. The thread includes a real invoice. The tone sounds like the person your bookkeeper knows. Nothing in the message asks anyone to click a strange attachment.

That is why business email compromise is so effective. The attacker may spoof a trusted address, compromise a real mailbox, study an existing conversation, register a lookalike domain, or impersonate an executive. The objective is often not malware. It is persuading a legitimate employee to send money or sensitive information to the wrong place.

The risk is current in Canada. On May 13, 2026, the Canadian Anti-Fraud Centre reported helping recover approximately CAD $3.5 million connected to payment-redirection fraud targeting a Quebec business. Criminals impersonated legitimate contacts and manipulated email communications to provide fraudulent instructions for two wire transfers. Fast reporting helped financial institutions and investigators coordinate the recovery.

Toronto and Ontario small businesses do not need an enterprise security operations centre to reduce this risk. They need secure identities and email, a payment process that an email alone cannot change, employees who know what to verify, and a response plan that begins in minutes rather than days.

What is business email compromise?

Business email compromise, commonly shortened to BEC, is fraud that uses a trusted business identity or relationship to persuade someone to transfer funds, change payment instructions, disclose data, or grant access. Microsoft describes BEC as using forged trusted senders—such as financial officers, customers, or partners—to trick recipients into approving payments, moving funds, or revealing customer data.

The sender may not be forged at all. If an attacker signs in to a supplier’s or employee’s real mailbox, they can read conversations, wait for a payment opportunity, create hidden forwarding or inbox rules, and reply from the legitimate account. A correct display name, address, signature, or thread history is therefore not proof that a request is safe.

BEC patternWhat the message may sayWhat the attacker wants
Supplier payment change“Our bank details have changed. Use this account for the outstanding invoice.”Redirect a legitimate payment
Executive impersonation“I am in a confidential meeting. Send this wire or buy gift cards now.”Exploit authority and urgency
Payroll diversion“Please update my direct-deposit account before payroll closes.”Redirect an employee’s pay
Customer or lawyer impersonation“Use the attached instructions to complete the transaction today.”Intercept a high-value transaction
Sensitive-data request“Send the employee tax files or customer list for review.”Steal personal or business information
Account recovery or MFA request“I lost my phone. Reset my password and add this new authentication method.”Take control of an identity

Why business email compromise gets past normal caution

BEC attacks are designed around business context. Criminals collect names, roles, suppliers, travel plans, project announcements, and reporting relationships from company websites, social media, data breaches, and compromised mailboxes. They time the request around a real invoice, closing date, executive absence, or busy accounting period.

The Canadian Centre for Cyber Security’s July 2026 social-engineering guidance says threat actors impersonate trusted people and use publicly available information to make messages credible. The request may arrive by email, phone, text, collaboration tool, social media, or a QR code. A process that verifies only through a reply to the same conversation can therefore be defeated.

1. Map the workflows that can move money, data, or access

Start with business operations. List every workflow where one message can lead to a financial transfer, banking-detail change, payroll update, customer refund, gift-card purchase, tax-document release, password reset, new MFA method, or administrator access.

  • Who can request the action?
  • Who enters or changes the information?
  • Who approves it, and at what amount or risk threshold?
  • Which system records the request and approval?
  • What independent evidence confirms the requester’s identity?
  • What happens if the normal approver is unavailable?

This exercise often exposes a larger problem: the company has a payment policy in someone’s memory rather than in a documented workflow. Fixing that process can prevent more fraud than another warning banner alone.

2. Require independent verification for financial changes

A request to change payment instructions must be verified outside the message that requested the change. Call the supplier or employee using a phone number already stored in the approved vendor, payroll, or customer record—not a number in the email, attachment, new website, or signature.

For higher-risk changes, require a second authorized employee to review the original record, verification result, beneficiary name, institution, account details, amount, and effective date. Make the same rule apply to executives so employees are never punished for slowing down an urgent request.

3. Use two-person approval and meaningful limits

Separate the ability to create or change a payee from the ability to approve payment. Use banking controls, accounting-system roles, payment limits, callback services, and dual authorization where available. A second approval is useful only if the reviewer sees the relevant evidence and is expected to challenge the request.

  • New payees and changed bank details require independent verification.
  • High-value or unusual payments require two authorized people.
  • The requester, data-entry user, and final approver are separated where staffing allows.
  • Daily and per-transaction limits reflect normal business activity.
  • Bank alerts go to more than one trusted person.
  • Exceptions are documented rather than approved through an informal chat.

4. Protect email identities with strong authentication

Require multifactor authentication for every email account, with priority for administrators, executives, finance, payroll, human resources, customer service, and anyone who can reset another user. Where supported, prefer phishing-resistant methods such as passkeys or hardware security keys for high-risk users.

Traditional push or one-time-code MFA is much better than a password alone, but adversary-in-the-middle phishing can capture a live session. The Canadian Centre for Cyber Security continues to observe these campaigns connected to BEC and recommends phishing-resistant MFA to reduce that exposure.

  • Disable legacy authentication and unused email protocols where business applications allow.
  • Use separate administrator accounts and least-privilege roles.
  • Review registered authentication methods and remove old phones, app passwords, and unknown devices.
  • Protect password-reset and help-desk procedures against executive impersonation.
  • Revoke sessions promptly when employment ends or compromise is suspected.
  • Do not share mailboxes through shared passwords; use delegated access with individual identities.

5. Configure SPF, DKIM, and DMARC for every business domain

Email authentication makes it harder for attackers to send messages that directly spoof a company’s domain. SPF identifies permitted sending sources. DKIM adds a cryptographic signature. DMARC checks alignment with the visible From domain, tells receiving systems how to handle failures, and can provide reports.

Microsoft’s July 2026 guidance is explicit that SPF alone is not sufficient; SPF, DKIM, and DMARC must work together for effective authentication. Inventory every legitimate sender first—including Microsoft 365, website forms, CRM, accounting, marketing, ticketing, payroll, scanners, and third-party platforms. Start DMARC with reporting and controlled monitoring, remediate legitimate failures, then move toward quarantine or reject based on evidence.

6. Tune anti-phishing and impersonation protection

Microsoft 365 cloud mailboxes include baseline protections, while Microsoft Defender for Office 365 adds capabilities according to plan. Defender for Office 365 Plan 1 is designed to protect email and collaboration from zero-day malware, phishing, and BEC; Plan 2 adds investigation, hunting, automation, and simulation capabilities.

Protect high-value users and trusted domains with impersonation settings where licensing supports them. Review anti-phishing, anti-spam, Safe Links, Safe Attachments, quarantine, user reporting, and external-sender behaviour. Avoid broad allow lists and mail-flow rules that bypass filtering; a convenient exception can create a permanent blind spot.

7. Detect mailbox persistence and suspicious changes

Attackers who gain mailbox access may create forwarding, inbox rules, app consent, new authentication methods, or delegated access so they can continue reading messages or hide replies. They may move messages to RSS, Notes, Junk, or Deleted Items to keep the legitimate user unaware.

  • Alert on new external forwarding and suspicious inbox rules.
  • Review risky or unusual sign-ins and impossible or unexpected travel patterns in context.
  • Monitor added MFA methods, app consent, role assignment, connector, transport-rule, and delegate changes.
  • Investigate unexpected deletion, missing replies, unfamiliar sent messages, or unexplained account lockouts.
  • Send security alerts to a monitored path that does not depend only on the affected mailbox.
  • Retain audit evidence for the period required by the business, contracts, and incident plan.

8. Maintain trusted vendor and employee records

Keep approved contact and payment information in a controlled accounting, vendor-management, or payroll record. Limit who can change it, record previous values, and require evidence and approval. An employee should not build the verification channel from information supplied in the suspicious request.

Tell suppliers and employees how changes are accepted. If a supplier knows your organization always confirms bank changes through a known contact and dual approval, an attacker has less room to create urgency or shame an employee into bypassing the process.

9. Reduce public information that helps impersonation

Marketing and recruitment require some public information, but not every reporting relationship, travel date, finance contact, direct email address, supplier, contract award, or employee birthday needs to be published. Review the company website and social profiles through an attacker’s eyes.

Do not rely on secrecy as the main control; much of this information can still be discovered. Use the review to remove unnecessary detail and to create additional verification around roles that are easy to identify and impersonate.

10. Train employees around real business decisions

Generic advice to “look for bad grammar” is outdated and unfair to employees. Modern messages can be polished, timely, and sent from a genuine account. Training should focus on risky requests, approved verification channels, and the authority to pause.

  • New or changed banking and payroll details
  • Urgent secrecy or pressure from an executive
  • Unexpected gift cards, wires, refunds, or cryptocurrency
  • Requests for tax, payroll, customer, credential, or MFA information
  • Login pages reached through email, QR codes, shared documents, or unfamiliar collaboration invites
  • A familiar person using a different number, domain, tone, or process

Run short exercises with finance, payroll, reception, executives, and IT support. Measure whether employees report suspicious requests and follow the verification procedure—not simply whether they click a simulated link.

11. Protect devices and business applications

Email security cannot compensate for an infected or unmanaged endpoint. Keep operating systems, browsers, Office applications, password managers, accounting software, and security tools supported and updated. Use endpoint protection, disk encryption, screen locking, secure mobile access, and device-management policies appropriate to the organization.

Finance and administrative users should not have local administrator privileges for daily work. Restrict browser extensions and unapproved remote-access tools, and review whether sensitive payments can be initiated from unmanaged or personally owned devices.

12. Prepare a BEC response plan before money moves

Speed matters. The organization should know whom to call at its bank, insurer, managed IT provider, Microsoft 365 administrator, legal or privacy advisor, and local police. Store the contacts somewhere available even if email is unavailable or untrusted.

PriorityImmediate actionWhy it matters
FinancialCall the financial institution through a known number and request recall, hold, or fraud escalationFunds can move rapidly through other accounts
IdentityBlock or contain affected accounts, reset credentials, revoke sessions, and inspect MFA methods and app consentA password change alone may not end active access
MailboxReview forwarding, inbox rules, delegates, connectors, sent/deleted items, and message traceAttackers often hide communication and maintain access
EvidencePreserve emails, headers, screenshots, transaction records, audit logs, phone numbers, and timelinesInvestigation and recovery depend on accurate evidence
ReportingNotify local police and report through Canada’s Report Cybercrime and Fraud systemFast reporting can support coordinated recovery and disruption
BusinessWarn affected partners through a trusted channel and review related payments or data exposureThe compromise may span multiple organizations

Microsoft’s current compromised-account guidance includes resetting credentials, revoking active sessions, reviewing registered MFA devices, checking application consent and roles, and inspecting mailbox settings. Adapt the technical procedure to your identity environment and preserve evidence before making changes when it is safe to do so.

A five-minute payment-change checklist

  1. Stop: do not use the reply button, link, attachment, or phone number in the request to verify it.
  2. Compare: review the approved vendor or employee record and previous payment history.
  3. Call: contact the known person using a trusted number already on file.
  4. Confirm: verify the reason, beneficiary, institution, account change, amount, and effective date without reading all new details first.
  5. Approve: obtain the required second-person authorization and record who verified what, when, and through which channel.
  6. Notify: alert the supplier through the established process and monitor the first payment to the changed account.

A practical 30-day BEC prevention plan

WeekFocusDeliverable
Week 1Map payment, payroll, data-release, and account-recovery workflowsRisky actions, owners, verification paths, and approval thresholds
Week 2Review Microsoft 365 identity, forwarding, authentication, and email policiesPrioritized technical remediation list
Week 3Inventory sending services and deploy or improve SPF, DKIM, and DMARC monitoringDocumented email sources and authentication plan
Week 4Test one realistic supplier-change scenario and one compromised-account responseCorrected procedure, contact list, and evidence checklist

When to involve a cybersecurity or managed IT provider

Professional help is useful when Microsoft 365 settings have grown without ownership, the organization lacks phishing-resistant MFA, email authentication is incomplete, multiple third parties send as the domain, external forwarding is unmanaged, audit alerts are not monitored, or no one can lead a compromised-account response.

A practical cybersecurity assessment should review both technology and the business process. The deliverable should include identity and email findings, SPF/DKIM/DMARC status, high-risk users, forwarding and app-consent controls, financial verification steps, incident contacts, prioritized fixes, and evidence that critical controls were tested.

The bottom line

Business email compromise is not only an email-filter problem. A perfect-looking message can arrive from a real account. The decisive control is a business process that requires trusted, independent verification before money, data, or access changes hands.

For Toronto and Ontario businesses, the right starting point is simple: document who can change payment details, secure the accounts involved, authenticate the company domain, monitor for attacker persistence, and rehearse the first hour of response. Those steps make an urgent message much less likely to become an irreversible loss.

Related Monors services

Common questions

Frequently asked questions

What is the difference between phishing and business email compromise?

Phishing broadly tries to steal credentials, deliver malware, or persuade a victim to act. Business email compromise is a targeted form of social engineering that impersonates or uses a trusted business identity to redirect payments, obtain sensitive information, or gain access. BEC may contain no malicious link or attachment.

Can multifactor authentication stop business email compromise?

MFA greatly reduces account-takeover risk, especially when phishing-resistant methods are used, but it cannot stop every BEC scenario. Attackers can spoof domains, compromise a supplier, steal active sessions, or persuade an employee without accessing your mailbox. Combine MFA with email authentication, monitoring, and payment-verification controls.

How should a Toronto business verify new banking details?

Call a known supplier or employee contact using the approved number already stored in your accounting, payroll, or vendor record. Do not use contact information supplied in the change request. Verify the change, record the result, and require a second authorized approval for higher-risk payments.

Do SPF, DKIM, and DMARC prevent all email impersonation?

No. They help receiving systems authenticate use of your domain and reduce direct spoofing, but attackers can use lookalike domains, display-name impersonation, compromised accounts, or other channels. They are essential layers, not substitutes for identity security and business verification.

What should we do first after a fraudulent transfer?

Contact the financial institution immediately through a trusted number and request its fraud, recall, or hold process. Then contain suspected accounts, preserve evidence, notify affected parties through trusted channels, contact local police, and report through Canada’s Report Cybercrime and Fraud system. Do not wait for a complete internal investigation before contacting the bank.

How can Monors help prevent business email compromise in Toronto?

Monors can review Microsoft 365 identity and email controls, configure stronger authentication and email protection, assess SPF, DKIM, and DMARC, monitor risky changes, document payment-verification procedures, and build a practical incident-response plan for Toronto and Ontario businesses.

Primary sources

This guide was reviewed against the following primary and authoritative references. Source links are provided so you can verify the guidance and check for updates.

Ready when you are

Protect your business before the next urgent payment email

Monors helps Toronto and Ontario small businesses strengthen Microsoft 365, authenticate email domains, review payment workflows, and prepare a response plan for account compromise and invoice fraud. Request a business email security assessment.