Business email compromise playbook drafts almost always get written in the week after an incident — after the fraudulent invoice has been paid, after somebody has spent a weekend reading audit logs, and after the finance director has asked the question nobody could answer at the time: who was supposed to decide that? Written then, the document is honest but expensive. Written before, it costs an afternoon.

This guide is about the document itself rather than the technology underneath it. A business email compromise playbook assumes the attack has already worked: a real mailbox, a real sender, a real conversation about a real invoice. What separates the businesses that lose a few hours from the ones that lose six figures is almost never a security product. It is whether five named people knew, in advance, what they were allowed to do without asking permission.

If you need the platform-side mechanics — session revocation, unified audit log exports, inbox rule forensics, OAuth grant review — our companion guide on the Microsoft 365 business email compromise response plan covers those clicks in detail, and a deliberately vendor-neutral business email compromise playbook does not repeat them.

What follows is a structure you can lift: the roles to name, the severity tiers to agree, the first-hour decisions that cannot wait for a meeting, the message templates to pre-write, the regulatory clock you are already on, and the rehearsal that turns all of it from a file into a reflex.

What a business email compromise playbook actually has to do

business email compromise playbook b interlocking role ring

It is a decision document, not a security manual

The most common failure is scope. Teams sit down to write a business email compromise playbook and produce a forty-page description of how email authentication works. Nobody reads it under stress. The document has exactly one job: to remove decisions from the moment of the incident and settle them in advance, in daylight, with the people who have the authority to settle them.

Everything that is not a decision belongs somewhere else. Configuration guidance belongs in your platform runbook. Awareness material belongs in training. The business email compromise playbook holds only the choices: who declares, who contains, who pays, who speaks, who notifies. If a page does not change what somebody does in the next ten minutes, it belongs in a different file.

The three failures it exists to prevent

Every expensive business email compromise incident traces back to one of three delays. The first is hesitation — nobody feels senior enough to block an account or stop a payment run, so an hour passes while someone is found. The second is destruction — a well-meaning administrator deletes the malicious inbox rule and resets the password before anyone exports the evidence, and the investigation never recovers. The third is silence — the bank is called after the close of the payment window, and money that was recoverable at minute forty is gone by hour six.

A good business email compromise playbook is measured against those three failures and nothing else. If it does not shorten hesitation, prevent destruction, and force early contact, it is decoration.

Why the platform runbook stays a separate document

Keep the business email compromise playbook vendor-neutral on purpose. Your business will change email platforms, acquire a company running something else, or inherit a subsidiary on a different tenant, and a playbook welded to one product’s admin console quietly expires. Roles, tiers, clocks and templates survive a platform migration. Screenshots do not.

The practical arrangement is two documents that reference each other: this one, which says the technical responder revokes all active sessions before resetting credentials, and a platform runbook that says exactly where that button lives today.

Who reads it, and in what state of mind

Assume the reader is not the author. Assume they are reading it on a phone, in a corridor, having been handed the incident by someone going into a meeting. That means numbered steps, named roles, real phone numbers, and no cross-references to appendices. A business email compromise playbook that requires two documents open at once has already failed its reader.

FactorAd-hoc responseWritten playbook
First containment actionWhenever someone senior is reachableInside 15 minutes, by pre-agreed authority
Authority to stop paymentsEscalated upward, often twiceDelegated in advance to a named role
Evidence preservedPartly, after cleanup has begunExported before any remediation
Regulatory clockNoticed days laterStarted and logged at declaration
Supplier and customer messagingImprovised, inconsistentPre-approved template, one voice
Insurer positionNotification conditions often breachedNotified inside the policy window
Second incidentSame cost, same confusionCheaper — the path is already known

The scale of the problem is what makes an afternoon of writing worthwhile. Reported losses to the FBI’s Internet Crime Complaint Center have sat near three billion dollars a year for four consecutive years, and those are only the incidents somebody reported.

Reported BEC losses to the FBI IC3 (US$ billions)
2021 $2.40bn
2022 $2.74bn
2023 $2.95bn
2024 $2.77bn

The five roles your business email compromise playbook must name

business email compromise playbook c ascending severity steps

The incident lead

One person runs the incident and is not also doing the technical work. Their job is sequence, time and record: what has been decided, what is outstanding, who is waiting on whom, and which step of the business email compromise playbook the business is currently on. In a small business this is often the operations manager rather than anyone from IT, and that is fine — the role needs authority and attention, not admin credentials.

The lead also owns declaration. Somebody has to say the words “this is now an incident”, because that sentence starts every clock in the document.

The finance authority

This is the role most business email compromise playbook drafts forget. You need one named person who can suspend outbound payments and bank-detail changes across the whole business without seeking approval, and a deputy for when they are on a plane. Without that delegation you will discover, at the worst possible moment, that stopping the payment run requires a director who is unreachable.

The technical responder

The responder contains the account and preserves the evidence, in that order, and does not clean anything until the lead confirms the export is done. On the platform side this means revoking active sessions rather than trusting a password reset, because a stolen session token survives a new password perfectly well.

The communications owner

One voice out. This role writes to staff, customers, suppliers and — if it comes to it — the press, using templates agreed long before today. The reason to name it is that in the absence of a named owner, four people send three different versions of events to the same supplier within an hour.

The legal and regulatory owner

Somebody tracks obligations: the regulatory notification clock, contractual notice periods you have already signed, and the insurer’s conditions. This is rarely a lawyer in a smaller business; it is usually whoever owns compliance and can read a policy schedule without panicking.

Name roles, not individuals

Write the business email compromise playbook in roles and keep a single contact appendix mapping roles to people, phone numbers and deputies. People leave; the document should not need a rewrite when they do. Review the appendix quarterly — it is the only part that rots.

RoleOwnsDecides aloneMust not decide
Incident leadSequence, timeline, decision logDeclaration and severity tierTechnical remediation steps
Finance authorityPayments, bank contact, recallFreezing payments and detail changesCustomer messaging
Technical responderContainment and evidenceSession revocation, sign-in blockWhen to delete or clean up
Communications ownerAll outbound messagesSending pre-approved templatesAdmitting liability or cause
Legal and regulatory ownerClocks and obligationsInsurer and regulator notificationContainment timing

Severity tiers your business email compromise playbook should define

business email compromise playbook d sealed envelope plinth

Tier 3 — suspicious but unconfirmed

An impossible-travel alert, a user reporting a convincing phishing email, a supplier querying an invoice you did not send. Tier 3 is investigated by the technical responder within the working day and closed with a note. No declaration, no bank call, no meeting. Most of your volume lives here, and a business email compromise playbook that treats every Tier 3 as a crisis will be quietly abandoned within a quarter.

Tier 2 — confirmed compromise, no money moved

Someone else has been in the mailbox. There are inbox rules, a forwarding entry, or sign-ins that are not the user. No fraudulent payment has been made and no personal data is known to have left. Tier 2 declares the incident, starts the log, contains the account and preserves evidence — but it does not yet stop the business.

Tier 1 — money moved or data left

A payment has gone to an attacker-controlled account, or a mailbox containing personal data has been exfiltrated. Tier 1 pulls in the finance authority immediately, starts the bank recall, opens the regulatory assessment, and notifies the insurer. This is the tier the whole business email compromise playbook is built around, and it should be reachable in a single sentence from the front page.

Who is allowed to raise the tier

Anybody. Make it explicit that any employee can escalate to Tier 1 and that nobody will be criticised for over-escalating. Only the incident lead may lower a tier, and only with the reason written in the log. Asymmetric escalation rules are what keep bad news travelling fast.

The trap of a single tier

Three tiers is the sweet spot. One tier makes the business email compromise playbook exhausting; five makes people argue about classification while the money leaves. If you find yourself wanting a fourth, it is usually a sign that a Tier 2 trigger is drafted too loosely.

TierTriggerLeadsResponse clockExternal notification
Tier 3Suspicion, alert, user reportTechnical responderSame working dayNone
Tier 2Confirmed mailbox accessIncident leadContain inside 1 hourInsurer if policy requires
Tier 1Payment made or data exfiltratedIncident lead plus finance authorityImmediate, out of hours includedBank, police, insurer, regulator assessment

The first hour: containment decisions that cannot wait

business email compromise playbook e looping recall arrow

Decide before you clean

The single most valuable line in any business email compromise playbook is the instruction to preserve before you remediate. Inbox rules, sign-in records, forwarding configuration and message traces are the entire basis of the later question “did personal data leave?” — and an administrator tidying up in the first ten minutes can make that question permanently unanswerable. Export first, screenshot the rules, note the timestamps, then contain.

Lock the identity, not just the password

Resetting a password is the instinct and it is not enough on its own, which is why the business email compromise playbook spells out the order. Active sessions must be revoked, because a stolen token keeps working after the reset. Block sign-in for the account outright while you investigate, and treat any registered authentication method you do not recognise as attacker-controlled until proven otherwise.

Freeze the payment channel across the business

Not just the compromised mailbox. Suspend bank-detail changes and hold outbound payments business-wide until the finance authority is satisfied, because the mailbox you found may not be the only one and the invoice you know about may not be the only one. This is a blunt instrument and it is meant to be.

Preserve the evidence you are about to destroy

Take the exports the platform will not keep forever, and take them now. Sign-in logs, audit records, mailbox rules with creation timestamps, forwarding at every level it can be set, and connected application grants. Store them outside the affected environment — a compromised mailbox is a poor place to keep the evidence of its own compromise.

Start the decision log at minute zero

One running document: time, decision, who made it, why. Every business email compromise playbook should name the log’s location on page one, because it will be the difference between a defensible account and a reconstructed one when the insurer, the regulator or a customer’s lawyer asks in three months. Continuous monitoring tells you what happened to the system; the decision log tells you what happened in the room.

Target response clock — minutes from declaration to action complete
Declare and name the incident lead 5 min
Evidence exported and stored off-platform 15 min
Sessions revoked and sign-in blocked 20 min
Payments and bank-detail changes frozen 30 min
Bank recall request raised 45 min

What your business email compromise playbook says about the money

business email compromise playbook f upright rehearsal pieces

Call the bank first, then everyone else

Recovery is a function of elapsed time and almost nothing else. The moment a fraudulent payment is confirmed, the finance authority calls the bank’s fraud line and asks explicitly for a recall or freeze on the receiving account — not an email, a phone call, with the payment reference to hand. Every hour the funds sit still is an hour they can be returned; once they are layered onward through mule accounts they are effectively gone.

This is why the business email compromise playbook carries the bank’s direct fraud number on its front page rather than in an appendix, and why the finance authority has a deputy.

Report to the authorities and your insurer

Report the fraud to the national reporting body and get a reference number, because your bank and your insurer will both ask for it. Notify the insurer the same day: most cyber and crime policies carry a notification condition measured in days, and quietly breaching it while you are busy is a common and expensive own goal.

Warn everybody in that mailbox

An attacker in a mailbox has read the conversations and knows who pays whom. Assume the suppliers and customers in that mailbox are being targeted right now with the same trick, in your name. The communications owner sends the pre-written warning to those contacts quickly, because your supplier paying a fraudulent invoice “from you” is your reputational problem whether or not it is your legal one.

Rebuild the payment change process afterwards

Almost every one of these incidents ends at the same root cause: bank details were changed on the strength of an email. The fix is a control, not a memo — verified callback to a number already on file, never a number in the email, plus dual authorisation for changes above a threshold. A business email compromise playbook that ends without changing this control has treated the symptom. Fold that into change management so it survives the departure of whoever currently remembers it.

Business email compromise playbook communication templates

Why pre-writing beats drafting under pressure

Templates are the part of the business email compromise playbook people are most grateful for. They exist so the communications owner is editing rather than composing at the point of maximum stress, and so that legal review happens once, in advance, instead of four times in an afternoon. Every template below is deliberately short, factual, and free of speculation about cause — the two failure modes in incident messaging are saying nothing for a day and saying too much in ten minutes.

The internal alert

Template — internal alert to all staff
We are dealing with a confirmed email security incident affecting one mailbox. Until further notice: do not action any request to change bank details, and do not process any payment request received by email today without verbal confirmation on a number you already hold. Forward anything that looks unusual to the incident lead and do not reply to it. We will update everyone by [time]. Contact [role] with questions.

The customer or supplier warning

Template — warning to suppliers and customers in the affected mailbox
We are contacting you as a precaution. We have identified unauthorised access to one of our email accounts, and correspondence with you may have been visible. We have contained the account. Please treat any recent request from us to change payment details as suspect, and verify any payment instruction with us by telephone on [number] before acting. We are not aware of any impact to your data at this stage and will update you if that changes.

The bank recall request

Template — details to have ready on the call
Our reference [x]. A payment of [amount] was made on [date/time] from account [ours] to [sort code / account number], reference [payment reference]. We believe this payment was induced by fraud following unauthorised access to our email. We are requesting an immediate recall and a freeze on the receiving account. Our fraud report reference is [x]. The contact for this incident is [name, role, direct number].

The holding statement

Keep one paragraph ready for the case where the incident becomes visible outside the business: what happened in one sentence, what you have done in one sentence, what you are asking people to do in one sentence, and when the next update comes. No cause, no blame, no numbers you have not confirmed.

What never goes into a template

Keep four things out of every business email compromise playbook template: attribution, an estimate of loss, a promise about data that has not been assessed, and an apology phrased as an admission of liability. Also keep customer templates free of technical detail — “unauthorised access to an email account” is accurate and sufficient, while naming your platform and configuration is an invitation.

The 72-hour clock and when it starts

Under UK GDPR a personal data breach that meets the risk threshold must be reported to the regulator without undue delay and within 72 hours of becoming aware of it. Awareness is the trap: the clock starts when you have a reasonable degree of certainty that a breach has occurred, not when the investigation finishes. The business email compromise playbook should say plainly that the legal and regulatory owner starts assessing at declaration, in parallel with containment rather than after it.

Deciding whether personal data actually left

A compromised mailbox is not automatically a reportable breach — but you have to be able to show your reasoning either way, which is what the preserved evidence is for. Message trace and audit records tell you what was accessed, forwarded and exported. Absent that evidence you cannot argue “no data left”, and the safe answer becomes the expensive one. Your data protection documentation should already define who makes this call.

The insurance conditions you may already be breaching

Read your cyber policy before the incident, not during it. Common conditions include notification within a fixed number of days, using the insurer’s own panel responders, and not admitting liability. Businesses regularly invalidate cover by appointing their usual IT partner to investigate before telling the insurer, which the business email compromise playbook can prevent with a single line.

Contractual notification you have already signed

Enterprise customers, processors and framework agreements frequently carry their own notification windows — sometimes 24 hours, tighter than the regulator’s. Nobody remembers this mid-incident. Keep a one-page list of contracts with security notification clauses attached to the playbook, and refresh it when a major contract is signed. Good IT governance is largely this: knowing what you have promised.

Keep the record you will be asked for

Regulators are less interested in the fact you had an incident than in whether you responded competently. The decision log, the evidence exports and the dated version of the business email compromise playbook you followed are the record. Keep them together, immutable, and outside the affected environment.

Rehearsing the business email compromise playbook before you need it

Read-through, tabletop, live simulation

There are three ways to rehearse a business email compromise playbook and they cost very different amounts. A read-through is an hour around a table checking the document still matches reality. A tabletop walks a scenario in real time, with each role saying what they would actually do. A live simulation actually places a test call to the bank’s fraud line and actually exports the logs. Start with the read-through; most businesses find enough broken assumptions there to fill a quarter.

The scenario that finds the most gaps

Use this one: the finance manager’s mailbox is compromised on a Friday afternoon; a supplier’s bank details were changed on Tuesday; a £40,000 payment left this morning; the finance director is on annual leave. It exercises delegation, out-of-hours contact, the bank clock and the supplier warning simultaneously, and it breaks most first-draft business email compromise playbook documents within twenty minutes.

Rehearse the finance path, not just the IT path

Most rehearsals over-index on technical containment because that is who runs them. The expensive failures are on the finance side — nobody knows the fraud line number, the payment freeze needs an unreachable authoriser, the bank asks for a reference nobody has. Insist that the finance authority is in the room, and time them.

Fix the playbook the same week

Rehearsals produce a list of gaps that decays fast. Assign each one an owner and a date before people leave the room, and re-issue the business email compromise playbook within the week, with a version number and date on the front page. A business email compromise playbook nobody has updated in three years is a liability, because people will follow it.

How often to rehearse

Annually as a floor, plus after any material change: a new finance system, a change of bank, a merger, a new email platform, or a real incident. Rehearsal is also the cheapest way to onboard a new incident lead, and it is where the general principles of good cybersecurity turn into muscle memory for the five people who will actually be woken up.

Measuring whether your business email compromise playbook works

Five capability areas worth scoring

Score each out of five, honestly, once a year: roles named and delegated; severity tiers agreed and used; communication templates written and legally reviewed; the finance and bank path rehearsed; evidence procedure documented and tested. The shape of the result matters more than the total — a business scoring well everywhere except the finance path is exactly the business that loses the money.

Time to containment as the headline metric

If you track one number, track elapsed minutes from first report to sessions revoked and payments frozen. It is measurable from the decision log, it is comparable across incidents, and it correlates with loss better than any other figure you can collect. Everything else in the business email compromise playbook exists to pull that number down.

Metrics that mislead

Count of phishing emails blocked, phishing simulation click rate and number of alerts triaged all look like security metrics and tell you almost nothing about whether the business email compromise playbook works. They measure the funnel, not the fire drill. A business with an excellent click rate and no named finance authority is still one convincing invoice away from a bad quarter.

Review after every real incident

Every genuine incident, including Tier 3s that turned out to be nothing, gets fifteen minutes of review: what did the playbook say, what did we actually do, and why were they different? The gap between the two is the real document. Most improvements to a mature business email compromise playbook come from this question rather than from any external framework.

Worked example — capability self-score out of 5 for a 60-person firm
Roles named and delegated 4 / 5
Severity tiers agreed and used 3 / 5
Evidence procedure documented 3 / 5
Templates written and reviewed 2 / 5
Finance and bank path rehearsed 1 / 5

Frequently asked questions about the business email compromise playbook

How long should the document be?

Six to ten pages, with the first page usable on its own. That front page of the business email compromise playbook carries the declaration sentence, the five roles with phone numbers, the three tiers, and the first-hour actions. Everything else is reference material for the people who have time to read it, which during Tier 1 is nobody.

Do we need one if our IT is outsourced?

More than ever, because the decisions the playbook covers are not your provider’s to make. Your managed IT services partner can revoke sessions and pull logs, but they cannot declare an incident on your behalf, freeze your payment run, notify your regulator or write to your customers. Agree the split in writing, including out-of-hours contact and response times, and rehearse it together at least once.

Does cyber insurance replace the playbook?

No, and the relationship runs the other way: your policy imposes obligations that only a business email compromise playbook will get met on time. Insurers increasingly ask about documented incident response and rehearsal at renewal, and can decline claims where notification conditions were missed. Treat the policy as an input to the document.

Who should own it in a business with no security team?

The operations or finance side, not IT. A business email compromise playbook is mostly about authority, money and communication, and it works best owned by someone whose day job already involves all three. IT owns the platform runbook it points at. Baseline security controls remain a separate workstream from response.

How is this different from a general incident response plan?

A general plan covers ransomware, outage and data loss at a level of abstraction that is useless for this specific attack, because the decisive actions here are financial and contractual rather than technical. The business email compromise playbook is deliberately narrow: one attack pattern, one hour, five roles, and a bank on the phone.

References