Skip to content
arrow_back
search
ISM-1740 policy ASD Information Security Manual (ISM)

Training on Business Email Compromise for Payment Handling

Staff learn about email scams that change payment details and how to report them.

record_voice_over

Plain language

This control is about training staff who handle payments to recognise email scams that change payment details. It's crucial because if scammers trick your staff into sending money to a fraudulent account, your business could lose a significant amount of money, damaging both your finances and reputation.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Feb 2022

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Personnel dealing with banking details and payment requests are advised of what business email compromise is, how to manage such situations and how to report it.
policy ASD Information Security Manual (ISM) ISM-1740
priority_high

Why it matters

Failure to train staff on business email compromise can lead to misdirected payments, financial loss and reputational damage.

settings

Operational notes

Provide regular BEC-focused training for staff handling banking details, and require immediate reporting of suspicious payment-change emails.

Mapping detail

Mapping

Direction

Controls