Skip to content
arrow_back
ISM-1740policyASD Information Security Manual (ISM)

Manage and Report Business Email Compromise

Employees should know about email fraud in banking and how to manage and report it.

record_voice_over

Plain language

Business email compromise is when a hacker tricks someone into sending money to a fraudulent account. If your staff don't know how to handle this, your organisation could lose thousands or even millions of dollars-and damage its reputation.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

June 2026

Control Stack last updated

18 June 2026

E8 maturity levels

N/A

Official control statement

Personnel dealing with banking details and payment requests are advised of what business email compromise is and how to manage and report it.
policyASD Information Security Manual (ISM)ISM-1740
priority_high

Why it matters

Failing to manage email scams can lead to financial loss and harm your company's trustworthiness with clients and partners.

settings

Operational notes

Regularly update and review payment processing guidelines with staff to ensure awareness of the latest phishing tactics used by scammers.

build

Implementation tips

  • Managers should educate their teams about what business email compromise looks like. Conduct regular training sessions using real-world examples and discuss common tricks that hackers use.
  • Finance officers should check with senders whenever they receive new payment instructions. They can do this by calling the person requesting the change using a known phone number to confirm the request.
  • Staff should report suspicious emails to the IT team immediately. Use a clear, simple process, such as forwarding the email to a specific 'security' email address.
  • Department heads should maintain a list of key contacts to verify payment requests. Ensure this list is updated quarterly with current phone numbers and email addresses.
  • HR should include guidelines on recognising and reporting email fraud in staff induction materials. This ensures new employees are aware from day one.
fact_check

Audit / evidence tips

  • Askthe email security policy document: Ensure it includes procedures for verifying payment requestsLook atspecific steps outlinedGoodpolicy will have clear instructions on how staff should verify payments
  • Askrecords of staff training sessions on email securityLook atattendance lists and training content. Good records will show regular training with high staff participation
  • Look atthe response and resolution timesGoodwill show timely actions taken after each report
  • Askto see the contact verification list used by finance teamsLook athow often it is updated and method of its distributionGoodlist is current and accessible to all relevant staff
  • AskHR's induction materials regarding email security. Check for content that explains fraud recognition and reporting clearly. Good materials cover practical examples and clear steps
link

Cross-framework mappings

How ISM-1740 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.

ISO 27001

ControlNotesDetails
handshakeSupports(1)expand_less
Annex A 6.8ISM-1740 requires personnel handling payment details to know what BEC is and how to report it through the organisation’s processes
linkRelated(1)expand_less
Annex A 6.3Annex A 6.3 requires an organisation-wide, role-appropriate security awareness and training program with regular updates to relevant poli...

These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.

See all Guidelines for personnel security controls, or browse the full ASD ISM library.

Mapping detail

Mapping

Direction

Controls