How to reduce business email compromise risk with staff training

Reduce business email compromise risk in 2026 with staff training: call-back rules, three BEC simulations, and a 30-day plan you can measure.

Business email compromise (BEC) is still one of the costliest fraud types on record in 2026, and the fastest way to cut exposure is to train the people who move money — not only the people who read security policy.

Key takeaways

Why this matters

Best-in-class email filters still miss well-written BEC messages because those messages often come from a compromised supplier inbox or a lookalike domain, not from a bulk spam list. The last control is the person who approves the payment.

In 2026, organisations that treat BEC as a pure technology problem keep paying for it. Organisations that treat it as a behaviour problem — and train accordingly — stop wires before they leave. Pair security awareness training with the exact actions your staff take when money moves, and you finally have something to measure.

Verizon’s 2026 Data Breach Investigations Report found the human element involved in 62% of breaches. That is the number that justifies a focused BEC training sprint, not a generic annual video.

What you will need

The steps

1. Map who can actually move money

Do not start with a site-wide video. Export every role that can approve a payment, change a beneficiary, or release a payroll file. That list is your primary cohort for the first 30 days. Everyone else gets general awareness later.

Expected outcome: a named roster of 15–80 people in most mid-size firms, not a full company email list.

Common mistake: training everyone at the same depth, so finance sits through content written for sales and never practises the call-back.

2. Publish one verification rule before training starts

Write a single non-negotiable rule: any request to change supplier bank details, pay a new vendor, or send an urgent wire must be verified on a phone call to a number already in your vendor or internal directory — never to a number in the email. Put the rule on one page. Have the CFO sign it.

Without that rule, training is optional advice. With it, training has a clear pass/fail.

Common mistake: allowing exceptions for the CEO — which is exactly the pretext attackers use.

3. Run a 10–12 minute BEC lesson for the money-mover group

Keep it under 12 minutes. Cover three patterns only: (1) fake executive urgency, (2) supplier bank-detail change, (3) payroll redirect. End with the call-back script staff should read out loud once. Story-driven modules beat slide decks here — people remember the scam they almost fell for.

Cyber Aware’s short, story-led lessons fit this window: one pattern, one quiz, done the same day.

Expected outcome: 100% of the money-mover cohort completes the lesson within five business days.

Common mistake: a 45-minute annual module that people multitask through and never apply to a live invoice.

4. Send three escalating BEC simulations across 30 days

Schedule three sends, seven to ten days apart:

  1. Day 3–5: low-pressure supplier invoice with a slight domain lookalike.
  2. Day 12–15: bank-detail change from a known vendor, sent mid-morning on a busy AP day.
  3. Day 22–25: urgent wire request spoofing an executive, time-boxed to under two hours.

Anyone who fails should land in short remediation automatically — not a public shaming email. Anyone who reports should get a short congratulations note so the behaviour sticks.

Expected outcome: click rate falls across the three sends; report rate rises above 20% by send three.

Common mistake: one hard spear-phish on day one that tanks trust and produces no learning curve.

5. Score call-back compliance, not vanity completion

After each simulation week, sample five live payment changes or wires and check whether the call-back was logged. Pair that with simulation report rate and training completion. A human risk reporting view that rolls overdue training, quiz fails, and phishing fails into one score per learner makes the QBR conversation numerical instead of anecdotal.

Expected outcome: a one-page monthly scorecard the CFO will actually open.

Common mistake: celebrating 95% training completion while zero call-backs were logged on real bank changes.

6. Close the loop with managers and one process fix

In week five, brief each money-mover manager on who reported, who needed remediation, and one process change (for example: dual approval above a fixed dollar threshold). Add dual control where a single person still releases wires alone. Re-run the hardest template 60 days later on the same cohort.

Expected outcome: one permanent process fix plus a dated re-test on the calendar for 2026.

Common mistake: ending at the training certificate and never touching the payment workflow.

Troubleshooting

Finance refuses the call-back rule because it slows deals. Have the CFO sponsor restate the rule in writing and attach a single real industry loss figure from the IC3 report. Speed without verification is how the $3.05 billion happens.

Click rates stay flat after two simulations. Templates are too obvious or too similar. Move send three to a real internal project name drawn from public information only, and send it during a real AP window.

Staff report the simulation to IT as a real incident and panic. Brief managers 48 hours before send one. Frame the programme as skill practice, not a gotcha test.

Help desk blocks your simulation domain. Whitelist sending domains and IPs with email security before campaign one. Blank data burns a full week of your 30-day window.

Executives insist they are exempt. Put them in send three. Attackers target them by name. Exemption is the vulnerability.

You have no baseline. Treat send one as baseline even if the click rate looks bad. 20–35% on a first BEC-style send is common and is a starting line, not a failing grade.

Tools and resources

What to do next

Once the 30-day sprint clears your report-rate and call-back targets, widen training beyond money-movers and add a light monthly BEC template into the standing simulation cadence. Do not jump from a 30-person cohort to a full-company blast in one send.

FAQ

What is the fastest way to reduce business email compromise risk with staff training in 2026? Train money-movers first, publish a verbal call-back rule, then run three escalating BEC simulations in 30 days while tracking report rate and real call-back completion.

How much did business email compromise cost in 2025? The FBI IC3 2025 Annual Report recorded $3.05 billion in BEC losses across 24,768 complaints.

Who should receive BEC training first? Finance, payroll, procurement, executive assistants, and anyone who can approve or release a wire. Broaden later.

How often should BEC simulations run? Three sends in the first 30 days, then a standing monthly or bi-monthly BEC-style template inside your wider phishing programme.

Is a call-back on a number from the email enough? No. Call a number already stored in the vendor master or internal directory. Numbers inside the email are part of the scam.

Does email security make BEC training unnecessary? No. Filters miss vendor-compromise and lookalike-domain messages that contain no malware. The payment approver remains the control.

What report rate should we target by day 30? Aim above 20% reporting on the third simulation, with click rate trending down across the three sends.

Can small teams run this without a full security department? Yes. A signed one-page rule, three templates, and short lessons are enough to start in 2026.

One last thing

The quiet failure mode in BEC programmes is measuring training completion and ignoring whether anyone actually picked up the phone on a live bank-detail change. If the call-back log is empty, the certificate folder is theatre. Put five real payment changes next to the simulation scores every month — that single habit separates programmes that cut loss from programmes that only cut audit findings.

Related guides

Ready to deploy

Same playbook.
Your brand.

Cyber Aware's Human Risk Score works the same way for every MSP partner - under your brand, on your cadence.