Business email compromise playbook drafts almost always get written in the week after an incident — after the fraudulent invoice has been paid, after somebody has spent a weekend reading audit logs, and after the finance director has asked the question nobody could answer at the time: who was supposed to decide that? Written then, the document is honest but expensive. Written before, it costs an afternoon.
This guide is about the document itself rather than the technology underneath it. A business email compromise playbook assumes the attack has already worked: a real mailbox, a real sender, a real conversation about a real invoice. What separates the businesses that lose a few hours from the ones that lose six figures is almost never a security product. It is whether five named people knew, in advance, what they were allowed to do without asking permission.
If you need the platform-side mechanics — session revocation, unified audit log exports, inbox rule forensics, OAuth grant review — our companion guide on the Microsoft 365 business email compromise response plan covers those clicks in detail, and a deliberately vendor-neutral business email compromise playbook does not repeat them.
What follows is a structure you can lift: the roles to name, the severity tiers to agree, the first-hour decisions that cannot wait for a meeting, the message templates to pre-write, the regulatory clock you are already on, and the rehearsal that turns all of it from a file into a reflex.
Table of contents
- What a business email compromise playbook actually has to do
- The five roles your business email compromise playbook must name
- Severity tiers your business email compromise playbook should define
- The first hour: containment decisions that cannot wait
- What your business email compromise playbook says about the money
- Business email compromise playbook communication templates
- Legal, regulatory and insurance obligations on the clock
- Rehearsing the business email compromise playbook before you need it
- Measuring whether your business email compromise playbook works
- Frequently asked questions about the business email compromise playbook
- References
What a business email compromise playbook actually has to do
It is a decision document, not a security manual
The most common failure is scope. Teams sit down to write a business email compromise playbook and produce a forty-page description of how email authentication works. Nobody reads it under stress. The document has exactly one job: to remove decisions from the moment of the incident and settle them in advance, in daylight, with the people who have the authority to settle them.
Everything that is not a decision belongs somewhere else. Configuration guidance belongs in your platform runbook. Awareness material belongs in training. The business email compromise playbook holds only the choices: who declares, who contains, who pays, who speaks, who notifies. If a page does not change what somebody does in the next ten minutes, it belongs in a different file.
The three failures it exists to prevent
Every expensive business email compromise incident traces back to one of three delays. The first is hesitation — nobody feels senior enough to block an account or stop a payment run, so an hour passes while someone is found. The second is destruction — a well-meaning administrator deletes the malicious inbox rule and resets the password before anyone exports the evidence, and the investigation never recovers. The third is silence — the bank is called after the close of the payment window, and money that was recoverable at minute forty is gone by hour six.
A good business email compromise playbook is measured against those three failures and nothing else. If it does not shorten hesitation, prevent destruction, and force early contact, it is decoration.
Why the platform runbook stays a separate document
Keep the business email compromise playbook vendor-neutral on purpose. Your business will change email platforms, acquire a company running something else, or inherit a subsidiary on a different tenant, and a playbook welded to one product’s admin console quietly expires. Roles, tiers, clocks and templates survive a platform migration. Screenshots do not.
The practical arrangement is two documents that reference each other: this one, which says the technical responder revokes all active sessions before resetting credentials, and a platform runbook that says exactly where that button lives today.
Who reads it, and in what state of mind
Assume the reader is not the author. Assume they are reading it on a phone, in a corridor, having been handed the incident by someone going into a meeting. That means numbered steps, named roles, real phone numbers, and no cross-references to appendices. A business email compromise playbook that requires two documents open at once has already failed its reader.
| Factor | Ad-hoc response | Written playbook |
|---|---|---|
| First containment action | Whenever someone senior is reachable | Inside 15 minutes, by pre-agreed authority |
| Authority to stop payments | Escalated upward, often twice | Delegated in advance to a named role |
| Evidence preserved | Partly, after cleanup has begun | Exported before any remediation |
| Regulatory clock | Noticed days later | Started and logged at declaration |
| Supplier and customer messaging | Improvised, inconsistent | Pre-approved template, one voice |
| Insurer position | Notification conditions often breached | Notified inside the policy window |
| Second incident | Same cost, same confusion | Cheaper — the path is already known |
The scale of the problem is what makes an afternoon of writing worthwhile. Reported losses to the FBI’s Internet Crime Complaint Center have sat near three billion dollars a year for four consecutive years, and those are only the incidents somebody reported.
The five roles your business email compromise playbook must name
The incident lead
One person runs the incident and is not also doing the technical work. Their job is sequence, time and record: what has been decided, what is outstanding, who is waiting on whom, and which step of the business email compromise playbook the business is currently on. In a small business this is often the operations manager rather than anyone from IT, and that is fine — the role needs authority and attention, not admin credentials.
The lead also owns declaration. Somebody has to say the words “this is now an incident”, because that sentence starts every clock in the document.
The finance authority
This is the role most business email compromise playbook drafts forget. You need one named person who can suspend outbound payments and bank-detail changes across the whole business without seeking approval, and a deputy for when they are on a plane. Without that delegation you will discover, at the worst possible moment, that stopping the payment run requires a director who is unreachable.
The technical responder
The responder contains the account and preserves the evidence, in that order, and does not clean anything until the lead confirms the export is done. On the platform side this means revoking active sessions rather than trusting a password reset, because a stolen session token survives a new password perfectly well.
The communications owner
One voice out. This role writes to staff, customers, suppliers and — if it comes to it — the press, using templates agreed long before today. The reason to name it is that in the absence of a named owner, four people send three different versions of events to the same supplier within an hour.
The legal and regulatory owner
Somebody tracks obligations: the regulatory notification clock, contractual notice periods you have already signed, and the insurer’s conditions. This is rarely a lawyer in a smaller business; it is usually whoever owns compliance and can read a policy schedule without panicking.
Name roles, not individuals
Write the business email compromise playbook in roles and keep a single contact appendix mapping roles to people, phone numbers and deputies. People leave; the document should not need a rewrite when they do. Review the appendix quarterly — it is the only part that rots.
| Role | Owns | Decides alone | Must not decide |
|---|---|---|---|
| Incident lead | Sequence, timeline, decision log | Declaration and severity tier | Technical remediation steps |
| Finance authority | Payments, bank contact, recall | Freezing payments and detail changes | Customer messaging |
| Technical responder | Containment and evidence | Session revocation, sign-in block | When to delete or clean up |
| Communications owner | All outbound messages | Sending pre-approved templates | Admitting liability or cause |
| Legal and regulatory owner | Clocks and obligations | Insurer and regulator notification | Containment timing |
Severity tiers your business email compromise playbook should define
Tier 3 — suspicious but unconfirmed
An impossible-travel alert, a user reporting a convincing phishing email, a supplier querying an invoice you did not send. Tier 3 is investigated by the technical responder within the working day and closed with a note. No declaration, no bank call, no meeting. Most of your volume lives here, and a business email compromise playbook that treats every Tier 3 as a crisis will be quietly abandoned within a quarter.
Tier 2 — confirmed compromise, no money moved
Someone else has been in the mailbox. There are inbox rules, a forwarding entry, or sign-ins that are not the user. No fraudulent payment has been made and no personal data is known to have left. Tier 2 declares the incident, starts the log, contains the account and preserves evidence — but it does not yet stop the business.
Tier 1 — money moved or data left
A payment has gone to an attacker-controlled account, or a mailbox containing personal data has been exfiltrated. Tier 1 pulls in the finance authority immediately, starts the bank recall, opens the regulatory assessment, and notifies the insurer. This is the tier the whole business email compromise playbook is built around, and it should be reachable in a single sentence from the front page.
Who is allowed to raise the tier
Anybody. Make it explicit that any employee can escalate to Tier 1 and that nobody will be criticised for over-escalating. Only the incident lead may lower a tier, and only with the reason written in the log. Asymmetric escalation rules are what keep bad news travelling fast.
The trap of a single tier
Three tiers is the sweet spot. One tier makes the business email compromise playbook exhausting; five makes people argue about classification while the money leaves. If you find yourself wanting a fourth, it is usually a sign that a Tier 2 trigger is drafted too loosely.
| Tier | Trigger | Leads | Response clock | External notification |
|---|---|---|---|---|
| Tier 3 | Suspicion, alert, user report | Technical responder | Same working day | None |
| Tier 2 | Confirmed mailbox access | Incident lead | Contain inside 1 hour | Insurer if policy requires |
| Tier 1 | Payment made or data exfiltrated | Incident lead plus finance authority | Immediate, out of hours included | Bank, police, insurer, regulator assessment |
The first hour: containment decisions that cannot wait
Decide before you clean
The single most valuable line in any business email compromise playbook is the instruction to preserve before you remediate. Inbox rules, sign-in records, forwarding configuration and message traces are the entire basis of the later question “did personal data leave?” — and an administrator tidying up in the first ten minutes can make that question permanently unanswerable. Export first, screenshot the rules, note the timestamps, then contain.
Lock the identity, not just the password
Resetting a password is the instinct and it is not enough on its own, which is why the business email compromise playbook spells out the order. Active sessions must be revoked, because a stolen token keeps working after the reset. Block sign-in for the account outright while you investigate, and treat any registered authentication method you do not recognise as attacker-controlled until proven otherwise.
Freeze the payment channel across the business
Not just the compromised mailbox. Suspend bank-detail changes and hold outbound payments business-wide until the finance authority is satisfied, because the mailbox you found may not be the only one and the invoice you know about may not be the only one. This is a blunt instrument and it is meant to be.
Preserve the evidence you are about to destroy
Take the exports the platform will not keep forever, and take them now. Sign-in logs, audit records, mailbox rules with creation timestamps, forwarding at every level it can be set, and connected application grants. Store them outside the affected environment — a compromised mailbox is a poor place to keep the evidence of its own compromise.
Start the decision log at minute zero
One running document: time, decision, who made it, why. Every business email compromise playbook should name the log’s location on page one, because it will be the difference between a defensible account and a reconstructed one when the insurer, the regulator or a customer’s lawyer asks in three months. Continuous monitoring tells you what happened to the system; the decision log tells you what happened in the room.
What your business email compromise playbook says about the money
Call the bank first, then everyone else
Recovery is a function of elapsed time and almost nothing else. The moment a fraudulent payment is confirmed, the finance authority calls the bank’s fraud line and asks explicitly for a recall or freeze on the receiving account — not an email, a phone call, with the payment reference to hand. Every hour the funds sit still is an hour they can be returned; once they are layered onward through mule accounts they are effectively gone.
This is why the business email compromise playbook carries the bank’s direct fraud number on its front page rather than in an appendix, and why the finance authority has a deputy.
Report to the authorities and your insurer
Report the fraud to the national reporting body and get a reference number, because your bank and your insurer will both ask for it. Notify the insurer the same day: most cyber and crime policies carry a notification condition measured in days, and quietly breaching it while you are busy is a common and expensive own goal.
Warn everybody in that mailbox
An attacker in a mailbox has read the conversations and knows who pays whom. Assume the suppliers and customers in that mailbox are being targeted right now with the same trick, in your name. The communications owner sends the pre-written warning to those contacts quickly, because your supplier paying a fraudulent invoice “from you” is your reputational problem whether or not it is your legal one.
Rebuild the payment change process afterwards
Almost every one of these incidents ends at the same root cause: bank details were changed on the strength of an email. The fix is a control, not a memo — verified callback to a number already on file, never a number in the email, plus dual authorisation for changes above a threshold. A business email compromise playbook that ends without changing this control has treated the symptom. Fold that into change management so it survives the departure of whoever currently remembers it.
Business email compromise playbook communication templates
Why pre-writing beats drafting under pressure
Templates are the part of the business email compromise playbook people are most grateful for. They exist so the communications owner is editing rather than composing at the point of maximum stress, and so that legal review happens once, in advance, instead of four times in an afternoon. Every template below is deliberately short, factual, and free of speculation about cause — the two failure modes in incident messaging are saying nothing for a day and saying too much in ten minutes.
The internal alert
The customer or supplier warning
The bank recall request
The holding statement
Keep one paragraph ready for the case where the incident becomes visible outside the business: what happened in one sentence, what you have done in one sentence, what you are asking people to do in one sentence, and when the next update comes. No cause, no blame, no numbers you have not confirmed.
What never goes into a template
Keep four things out of every business email compromise playbook template: attribution, an estimate of loss, a promise about data that has not been assessed, and an apology phrased as an admission of liability. Also keep customer templates free of technical detail — “unauthorised access to an email account” is accurate and sufficient, while naming your platform and configuration is an invitation.
Legal, regulatory and insurance obligations on the clock
The 72-hour clock and when it starts
Under UK GDPR a personal data breach that meets the risk threshold must be reported to the regulator without undue delay and within 72 hours of becoming aware of it. Awareness is the trap: the clock starts when you have a reasonable degree of certainty that a breach has occurred, not when the investigation finishes. The business email compromise playbook should say plainly that the legal and regulatory owner starts assessing at declaration, in parallel with containment rather than after it.
Deciding whether personal data actually left
A compromised mailbox is not automatically a reportable breach — but you have to be able to show your reasoning either way, which is what the preserved evidence is for. Message trace and audit records tell you what was accessed, forwarded and exported. Absent that evidence you cannot argue “no data left”, and the safe answer becomes the expensive one. Your data protection documentation should already define who makes this call.
The insurance conditions you may already be breaching
Read your cyber policy before the incident, not during it. Common conditions include notification within a fixed number of days, using the insurer’s own panel responders, and not admitting liability. Businesses regularly invalidate cover by appointing their usual IT partner to investigate before telling the insurer, which the business email compromise playbook can prevent with a single line.
Contractual notification you have already signed
Enterprise customers, processors and framework agreements frequently carry their own notification windows — sometimes 24 hours, tighter than the regulator’s. Nobody remembers this mid-incident. Keep a one-page list of contracts with security notification clauses attached to the playbook, and refresh it when a major contract is signed. Good IT governance is largely this: knowing what you have promised.
Keep the record you will be asked for
Regulators are less interested in the fact you had an incident than in whether you responded competently. The decision log, the evidence exports and the dated version of the business email compromise playbook you followed are the record. Keep them together, immutable, and outside the affected environment.
Rehearsing the business email compromise playbook before you need it
Read-through, tabletop, live simulation
There are three ways to rehearse a business email compromise playbook and they cost very different amounts. A read-through is an hour around a table checking the document still matches reality. A tabletop walks a scenario in real time, with each role saying what they would actually do. A live simulation actually places a test call to the bank’s fraud line and actually exports the logs. Start with the read-through; most businesses find enough broken assumptions there to fill a quarter.
The scenario that finds the most gaps
Use this one: the finance manager’s mailbox is compromised on a Friday afternoon; a supplier’s bank details were changed on Tuesday; a £40,000 payment left this morning; the finance director is on annual leave. It exercises delegation, out-of-hours contact, the bank clock and the supplier warning simultaneously, and it breaks most first-draft business email compromise playbook documents within twenty minutes.
Rehearse the finance path, not just the IT path
Most rehearsals over-index on technical containment because that is who runs them. The expensive failures are on the finance side — nobody knows the fraud line number, the payment freeze needs an unreachable authoriser, the bank asks for a reference nobody has. Insist that the finance authority is in the room, and time them.
Fix the playbook the same week
Rehearsals produce a list of gaps that decays fast. Assign each one an owner and a date before people leave the room, and re-issue the business email compromise playbook within the week, with a version number and date on the front page. A business email compromise playbook nobody has updated in three years is a liability, because people will follow it.
How often to rehearse
Annually as a floor, plus after any material change: a new finance system, a change of bank, a merger, a new email platform, or a real incident. Rehearsal is also the cheapest way to onboard a new incident lead, and it is where the general principles of good cybersecurity turn into muscle memory for the five people who will actually be woken up.
Measuring whether your business email compromise playbook works
Five capability areas worth scoring
Score each out of five, honestly, once a year: roles named and delegated; severity tiers agreed and used; communication templates written and legally reviewed; the finance and bank path rehearsed; evidence procedure documented and tested. The shape of the result matters more than the total — a business scoring well everywhere except the finance path is exactly the business that loses the money.
Time to containment as the headline metric
If you track one number, track elapsed minutes from first report to sessions revoked and payments frozen. It is measurable from the decision log, it is comparable across incidents, and it correlates with loss better than any other figure you can collect. Everything else in the business email compromise playbook exists to pull that number down.
Metrics that mislead
Count of phishing emails blocked, phishing simulation click rate and number of alerts triaged all look like security metrics and tell you almost nothing about whether the business email compromise playbook works. They measure the funnel, not the fire drill. A business with an excellent click rate and no named finance authority is still one convincing invoice away from a bad quarter.
Review after every real incident
Every genuine incident, including Tier 3s that turned out to be nothing, gets fifteen minutes of review: what did the playbook say, what did we actually do, and why were they different? The gap between the two is the real document. Most improvements to a mature business email compromise playbook come from this question rather than from any external framework.
Frequently asked questions about the business email compromise playbook
How long should the document be?
Six to ten pages, with the first page usable on its own. That front page of the business email compromise playbook carries the declaration sentence, the five roles with phone numbers, the three tiers, and the first-hour actions. Everything else is reference material for the people who have time to read it, which during Tier 1 is nobody.
Do we need one if our IT is outsourced?
More than ever, because the decisions the playbook covers are not your provider’s to make. Your managed IT services partner can revoke sessions and pull logs, but they cannot declare an incident on your behalf, freeze your payment run, notify your regulator or write to your customers. Agree the split in writing, including out-of-hours contact and response times, and rehearse it together at least once.
Does cyber insurance replace the playbook?
No, and the relationship runs the other way: your policy imposes obligations that only a business email compromise playbook will get met on time. Insurers increasingly ask about documented incident response and rehearsal at renewal, and can decline claims where notification conditions were missed. Treat the policy as an input to the document.
Who should own it in a business with no security team?
The operations or finance side, not IT. A business email compromise playbook is mostly about authority, money and communication, and it works best owned by someone whose day job already involves all three. IT owns the platform runbook it points at. Baseline security controls remain a separate workstream from response.
How is this different from a general incident response plan?
A general plan covers ransomware, outage and data loss at a level of abstraction that is useless for this specific attack, because the decisive actions here are financial and contractual rather than technical. The business email compromise playbook is deliberately narrow: one attack pattern, one hour, five roles, and a bank on the phone.
References
NCSC Incident Management Collection
NCSC Small Business Guidance: Response and Recovery
NCSC Phishing Attacks: Defending Your Organisation
NCSC Multi-Factor Authentication for Your Corporate Online Services
ICO Personal Data Breach Reporting
NIST SP 800-61 Rev. 3 Incident Response Recommendations and Considerations
FBI Internet Crime Complaint Center Annual Reports