Phishing, Social Engineering and Business Email Compromise
Business email compromise and social engineering attacks succeed by exploiting trust and urgency rather than technical vulnerabilities, which means the most effective defence is a well-trained,...
Business email compromise and social engineering attacks succeed by exploiting trust and urgency rather than technical vulnerabilities, which means the most effective defence is a well-trained, appropriately sceptical member of staff, not just a spam filter.
Recognising common pretexts
Attackers often impersonate a trusted figure — a senior executive, a known supplier, an IT support contact — using a plausible pretext designed to lower the recipient's guard before making an unusual request.
Spotting manufactured urgency
A sense of urgency, pressure to bypass normal steps, or a request framed as too sensitive or time-critical for the usual process are all common manipulation tactics designed to short-circuit careful thinking.
Verifying requests through a separate channel
Verifying an unusual request — especially one involving a payment or sensitive information — through a separate, independently sourced communication channel is one of the single most effective defences available.
Payment controls and reporting suspected attempts
Strong payment controls, including mandatory verification for new or changed bank details, prevent a successful social engineering attempt from actually resulting in a financial loss, and reporting attempts — successful or not — helps the wider organisation stay alert.
Worked Example
Worked example: An employee in accounts payable receives an email, apparently from a known supplier, requesting that future payments be sent to a newly provided bank account due to an 'internal reorganisation'. Processing this change without verification would be a serious risk, since business email compromise attacks frequently use exactly this pretext. The correct response is to verify the change directly with the supplier using previously known, independently sourced contact details, not the details provided in the email itself.
Key Takeaways
- Social engineering exploits trust and urgency rather than technical vulnerabilities.
- Common pretexts include impersonating trusted figures like executives or known suppliers.
- Verifying unusual requests through a separate, independently sourced channel is highly effective.
- Strong payment controls and prompt reporting both reduce the actual impact of an attempt.
Common Pitfalls to Avoid
A common pitfall is assuming a well-written, professional-looking email can't be an attack, when in reality sophisticated attempts increasingly avoid obvious spelling or formatting errors. Another is skipping verification of an urgent request under time pressure, which is precisely the outcome the attacker is engineering.
Building This Into Team Practice
A single training session rarely changes behaviour on its own. For all staff, "Phishing, Social Engineering and Business Email Compromise" works best when it's reinforced through short, regular refreshers rather than treated as a one-off module — especially since the underlying subject matter (pretexts, urgency, verification, payment controls, and reporting) tends to evolve as new typologies, products and regulatory expectations emerge. Teams that set aside time to discuss real, anonymised cases from their own environment alongside the course content consistently retain the material better than those who complete it in isolation. Managers can reinforce this further by referencing the course's own scenarios in team meetings and by making it clear that raising a genuine concern is treated as good practice, not an inconvenience.
Why This Belongs in a Structured CPD Programme
Financial crime and conduct rules don't stand still, and neither should training. Embedding this course within a wider, structured CPD programme — rather than delivering it as an isolated annual requirement — gives all staff the chance to build genuine capability over time: to be able to detect manipulation across email, voice, messaging and payment workflows, and to keep that capability current as the environment around them changes. Learnsignal designs its compliance library so that individual courses like this one connect naturally into a broader learning pathway, letting firms track completion, refresh knowledge on a sensible cycle, and evidence a genuinely proportionate training programme rather than a box-ticking exercise.
How This Fits Into a Broader Compliance Programme
This course applies the general cyber hygiene principles covered elsewhere in this cluster to the specific, high-stakes scenario of business email compromise, where the financial and reputational consequences of a successful attack can be severe.
Frequently Asked Questions
How can I tell a legitimate urgent request from a manufactured one?
Genuine urgent requests can usually still tolerate a quick independent verification step — if a request specifically discourages verification, that's itself a significant warning sign.
What if I've already acted on a suspicious request before realising?
Report it immediately regardless of embarrassment — prompt reporting gives the firm the best chance to limit the damage, and delay only makes things worse.
Why do attackers often target accounts payable or finance staff specifically?
Because these roles have direct access to payment processes, making them a high-value target for attacks designed to result in a fraudulent payment.
How long does the "Phishing, Social Engineering and Business Email Compromise" course take to complete?
This is an interactive foundational course designed for a minimum of 30 minutes, with the exact length depending on the pace of the individual learner and how much of the practice and assessment content they engage with — some learners will comfortably spend longer working through the scenarios in detail.
This connects to information security and cyber hygiene and ransomware and cyber incident response. Learnsignal's CPD-accredited compliance courses cover social engineering defence in depth.
This page was last updated:
Learnsignal Education Team
Expert Tutor at Learnsignal
Qualified professional with years of experience in teaching and helping students achieve their accounting qualifications.
View all posts by Learnsignal Education Team

