Business email compromise is dangerous for Indian teams because it blends normal business language with payment urgency, vendor trust and familiar inbox workflows.
The practical defence is a mix of MFA, domain authentication, payment-change verification, admin alerts, staff scripts and a written recovery plan.
Why this matters now
Many scams do not need malware. An attacker can use a lookalike domain, compromised vendor mailbox or forwarded email thread to redirect payments.
Small finance teams are especially exposed because approvals may happen through email, WhatsApp and phone calls rather than a formal procurement system.
Indian teams also need to consider how quickly operational details change. Staff roles, vendors, bank accounts, devices, apps, branch locations and customer channels can change faster than the website or policy document. A checklist that is not reviewed becomes stale, so every recommendation below includes an owner and evidence item.
Action checklist
- MFA: Require MFA for email, admin and recovery accounts.
- Payment rule: Confirm bank changes on a second channel.
- Domains: Check SPF, DKIM and DMARC records.
- Forwarding: Review hidden mailbox forwarding rules.
- Drills: Run a fake vendor-change exercise.
Implementation plan
First week
In the first week, identify who can approve payments, who can edit vendor bank details and who controls the email admin panel.
During the first week, keep the scope narrow and visible. A founder or manager should be able to open one document and see the status of every important item. If the team cannot explain who owns the task, the task is not ready for automation.
First month
Within a month, update finance SOPs, admin alerts and email authentication records. Teach staff how to pause urgent payment requests.
The first month should convert one-time cleanup into a repeatable habit. Create a calendar reminder, define the evidence to be saved and agree who signs off. This prevents the checklist from becoming a document that was created once and forgotten.
Quarterly review
Every quarter, test one vendor-change scenario and one mailbox compromise scenario.
A quarterly review should not only mark items as complete. It should ask whether the business model changed, whether a new vendor was added, whether a branch or remote team changed the process, and whether any customer complaint exposed a weak point.
Decision table
| Area | What to check | Owner | Evidence |
|---|---|---|---|
| Email admin | MFA and forwarding rules | IT owner | Settings export |
| Finance | Bank-change approval | Finance lead | Approval log |
| Domain | SPF, DKIM, DMARC | Developer | DNS screenshot |
| Recovery | Password reset and alerts | Founder | Drill notes |
Practical worksheet
Create a working sheet with five columns: owner, current status, evidence link, next action and review date. This makes the article usable by a founder, agency manager, finance lead or IT partner instead of leaving it as a reading exercise.
The worksheet should include only actions the team can prove. If an item is not complete, mark it as pending and add a date. A visible pending item is better than a control that everyone assumes exists but nobody can demonstrate.
For multi-location businesses, add one more column for branch or channel. A website form, a WhatsApp sales number, a marketplace listing and a physical counter can all need different handling even when the headline policy is the same.
What to measure
Track a small number of signals after the change. Useful signals include open exceptions, old accounts removed, evidence collected, failed checks, staff questions and customer complaints. Measurement should help the team improve the process, not create paperwork for its own sake.
For a young business, the most important metric is consistency. A weekly or monthly review that actually happens is more valuable than a complex dashboard that nobody opens.
Common mistakes
Do not rely on caller ID or email display name. Attackers can mimic both well enough to create pressure.
Do not let the same person request, approve and update vendor payment information without a second check.
A third mistake is outsourcing responsibility without requiring evidence. Agencies, freelancers, payment partners and IT vendors may perform important work, but the business still needs a record of what was configured and when it was last checked.
How IndiaPress readers can use this
Use this as a joint checklist for finance, operations and IT rather than leaving BEC as only a technical issue.
If a payment was sent to the wrong account, contact the bank and preserve all evidence immediately.
Teams can turn this article into a one-page internal SOP. Copy the checklist, remove anything irrelevant, add owner names and review it in the next weekly meeting. The goal is not perfection on day one; the goal is visible progress and fewer unknowns.
Practical note for Indian teams
The strongest control is cultural: staff must be allowed to slow down urgent requests without fear of blame.
Keep the first version simple enough for the smallest branch, store, agency desk or founder-led team to follow. Once the process works, add automation, dashboards and deeper controls. If the process fails on a busy day, simplify it before adding more software.
Teams should also keep ownership visible. A checklist without a named owner usually becomes a forgotten document. Add the ownerβs role, backup owner and the date when the item was last reviewed.
Finally, keep customer communication plain. If a change affects payments, support, privacy, security or service availability, staff should know how to explain it without jargon. Clear explanations reduce disputes and make the business look more reliable.


