Manage and Report Business Email Compromise
Employees should know about email fraud in banking and how to manage and report it.
Plain language
Business email compromise is when a hacker tricks someone into sending money to a fraudulent account. If your staff don't know how to handle this, your organisation could lose thousands or even millions of dollars-and damage its reputation.
Framework
ASD Information Security Manual (ISM)
Control effect
Preventative
Classifications
NC, OS, P, S, TS
ISM last updated
June 2026
Control Stack last updated
18 June 2026
E8 maturity levels
N/A
Guideline
Guidelines for personnel securityOfficial control statement
Personnel dealing with banking details and payment requests are advised of what business email compromise is and how to manage and report it.
Why it matters
Failing to manage email scams can lead to financial loss and harm your company's trustworthiness with clients and partners.
Operational notes
Regularly update and review payment processing guidelines with staff to ensure awareness of the latest phishing tactics used by scammers.
Implementation tips
- Managers should educate their teams about what business email compromise looks like. Conduct regular training sessions using real-world examples and discuss common tricks that hackers use.
- Finance officers should check with senders whenever they receive new payment instructions. They can do this by calling the person requesting the change using a known phone number to confirm the request.
- Staff should report suspicious emails to the IT team immediately. Use a clear, simple process, such as forwarding the email to a specific 'security' email address.
- Department heads should maintain a list of key contacts to verify payment requests. Ensure this list is updated quarterly with current phone numbers and email addresses.
- HR should include guidelines on recognising and reporting email fraud in staff induction materials. This ensures new employees are aware from day one.
Audit / evidence tips
- Askthe email security policy document: Ensure it includes procedures for verifying payment requestsLook atspecific steps outlinedGoodpolicy will have clear instructions on how staff should verify payments
- Askrecords of staff training sessions on email securityLook atattendance lists and training content. Good records will show regular training with high staff participation
- Look atthe response and resolution timesGoodwill show timely actions taken after each report
- Askto see the contact verification list used by finance teamsLook athow often it is updated and method of its distributionGoodlist is current and accessible to all relevant staff
- AskHR's induction materials regarding email security. Check for content that explains fraud recognition and reporting clearly. Good materials cover practical examples and clear steps
Cross-framework mappings
How ISM-1740 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.
ISO 27001
| Control | Notes | Details |
|---|---|---|
handshakeSupports(1)expand_less | ||
| Annex A 6.8 | ISM-1740 requires personnel handling payment details to know what BEC is and how to report it through the organisation’s processes | |
linkRelated(1)expand_less | ||
| Annex A 6.3 | Annex A 6.3 requires an organisation-wide, role-appropriate security awareness and training program with regular updates to relevant poli... | |
These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.
Related ASD ISM controls in Personnel security
See all Guidelines for personnel security controls, or browse the full ASD ISM library.