Business email compromise is still the expensive one
In Canada this is still the claim that hurts: a changed bank detail, a rushed payment, a quiet mailbox rule.
ITSIGN Administrator · April 23, 2025 · 2 min read
Someone sits in a mailbox for two weeks. They learn who pays whom. They send one invoice from a lookalike, or from the real mailbox with a new rule that hides the replies.
Finance is busy. The amount is familiar. The wire goes.
The control that works
No new bank detail without a voice call on a number you already had. Dual control above a threshold. MFA on every mailbox that can move money.
We train the people with security awareness and lock the tenant with cloud and Microsoft 365 management.
Related reading
Email retention, PIPEDA, and the mailbox you never deleted
Keeping everything forever is not a strategy. It is a larger breach waiting for a number.
2 min read
When the phish comes from a vendor you trust
Their tenant, your payment. Callback still wins. So does knowing who is allowed to change details.
2 min read
Turn off IMAP and POP before someone else uses them
Legacy protocols skip modern MFA. They are still on in tenants that were migrated in a hurry.
2 min read
Want this applied to your environment?
A short conversation, an honest assessment of your current setup, and a clear proposal. No obligation and no pressure.
