Serving Central Coast, Newcastle & the Hunter Region, NSW

Contact us today 1300 270 412
Simple IT

11 September 2026

Email Compromise Prevention for Australian Businesses

Email Compromise Prevention for Australian Businesses

A supplier’s bank details change. The email looks genuine, the sender’s name is familiar and the invoice is due that afternoon. A staff member updates the details and pays it. Later, the real supplier calls to ask why their account is overdue.

This is the sort of situation email compromise prevention is designed to avoid. For small and medium-sized businesses, a compromised email account can lead to fraudulent payments, exposed client information, disrupted operations and a great deal of time spent rebuilding trust. The good news is that most incidents can be made far less likely with sensible controls and clear everyday processes.

What an email compromise looks like in a business

Email compromise is not always an obvious scam with poor spelling and an unusual sender address. Often, criminals gain access to a genuine staff mailbox after someone enters their password on a convincing fake Microsoft 365 sign-in page, reuses a password that has appeared in a breach, or approves a fraudulent sign-in request.

Once inside, they may quietly read messages to understand who the business deals with, how invoices are handled and who has authority to approve payments. They can then impersonate the account holder, send requests from the real mailbox, create inbox rules to hide replies, or use the account to target customers and suppliers.

This is why a basic spam filter alone is not enough. Filtering helps stop many malicious emails before staff see them, but it cannot fully protect a business when an attacker has access to a legitimate account or is impersonating a trusted contact.

The business impact is often operational, not just technical

The direct financial loss from a false payment gets attention, but it is only part of the picture. A compromised account may expose payroll information, customer records, quotes, legal documents or medical correspondence. Staff can lose access to email during the investigation, and clients may receive convincing messages from an account they trust.

For a practice manager, office manager or director, the priority is keeping the business moving while limiting harm. That requires technology, but also a process that people can follow when they are busy.

Email compromise prevention starts with identity protection

The most effective first step is to make it difficult for someone to sign in as one of your staff. Passwords still matter, but passwords on their own are no longer sufficient for business email.

Multi-factor authentication, often called MFA, requires a second form of verification after a password. This could be an approval in an authenticator app, a one-time code or, preferably for higher-risk accounts, a physical security key. If a criminal obtains a password, MFA can stop them from using it.

Not all MFA methods offer the same protection. Text message codes are better than no MFA, but they are more exposed to phone-number takeover and social engineering than app-based approvals or security keys. For most businesses using Microsoft 365, an authenticator app with number matching is a practical starting point.

MFA also needs to be applied consistently. Administrators, directors, finance staff and anyone with access to payroll, client records or shared mailboxes should not be exceptions. In fact, privileged accounts deserve tighter controls because they can affect the whole organisation.

Strong identity protection should also include:

  • unique passwords stored in a reputable password manager rather than reused across services;
  • removal of old accounts as soon as staff leave or change roles;
  • limits on overseas or unusual sign-ins where this suits the business;
  • regular checks of which staff have administrator access; and
  • separate administrator accounts for IT administration rather than using a normal day-to-day email account.

The right settings depend on how your team works. A construction business with staff travelling between sites, for example, needs a different access approach to a local accounting firm where everyone works from one or two offices. The goal is to reduce unnecessary access without making ordinary work frustrating.

Make payment changes a verified business process

Many email compromise incidents succeed because a fraudulent request is treated as routine. Technology can identify suspicious messages, but it cannot replace an independent check before money leaves the business.

Set a simple rule: bank account changes, unusual payment requests and changes to payroll details must be confirmed using a known phone number or another trusted contact method. Do not call the number included in the email requesting the change. Use the number held in your accounting system, supplier records or an existing contract.

This should apply even if the request comes from the managing director’s real email address. A compromised account can send messages that look completely normal. A short phone call may feel inconvenient, but it is far less disruptive than attempting to recover a payment sent to a criminal account.

For larger payments, consider a two-person approval process. One staff member enters the payment and another verifies the payee details and authorises it. This is particularly useful for businesses where one person manages accounts payable and is under pressure at month end.

Clear processes also protect staff. Rather than expecting someone to rely on instinct, give them permission to pause and verify. No employee should feel they will be criticised for delaying an urgent request that does not pass a basic check.

Train staff to recognise the signs, without blaming them

Security awareness works best when it is practical and repeated. A once-a-year presentation is easy to forget, especially when staff receive dozens or hundreds of emails each day.

Teach people to slow down when a message creates urgency, secrecy or pressure. Common examples include an executive asking for gift cards, a supplier requesting new banking details, a shared document requiring an immediate Microsoft 365 sign-in, or a customer asking for sensitive records to be sent again.

Staff should check the full sender address, not only the display name. They should also be cautious with unexpected attachments, QR codes and shared-document notifications. QR-code phishing has become more common because it moves the sign-in attempt from a managed computer to a personal mobile, where security checks may be weaker.

Training should be specific to the work your people do. Finance staff need realistic payment-change examples. Reception and administration staff may need guidance on handling requests for client information. Directors need to understand that their accounts are attractive targets and that urgent requests made in their name can carry extra weight.

The aim is not to turn every employee into a cybersecurity specialist. It is to make reporting a suspicious email normal, quick and judgement-free. Early reporting gives the business a chance to block a threat before someone else acts on it.

Configure Microsoft 365 and email security properly

Most businesses already have useful protection available in their email platform, but default settings may not match their risk level. A managed review should look beyond whether licences have been purchased and confirm that protections are actually enabled and monitored.

This usually includes anti-phishing and anti-malware policies, safe handling of attachments and links, external sender warnings, and controls that reduce impersonation attempts. Email authentication records - SPF, DKIM and DMARC - are also valuable. They help receiving mail systems confirm that messages claiming to be from your domain are legitimate, reducing the chance that criminals can spoof your business to customers or suppliers.

Shared mailboxes deserve attention too. It is common for accounts@, payroll@ or reception@ addresses to hold sensitive information and have several people with access. Review who needs access, remove former staff and avoid sharing a single password for a generic account.

Monitoring matters as much as configuration. Unusual sign-ins, new forwarding rules, unexpected mailbox delegation and changes to MFA settings can be early warning signs. A proactive IT provider can review these signals and act quickly, but the business should still know who to contact when something looks wrong.

Have a response plan before a mailbox is compromised

When an account is suspected of being compromised, speed matters. Staff should know to report it immediately rather than trying to quietly fix it themselves. The response normally involves resetting credentials, ending active sessions, reviewing sign-in activity, removing malicious inbox rules and checking whether emails, files or payment requests were sent.

If fraudulent bank details were acted on, contact the bank straight away. Recovery is not guaranteed, but prompt reporting gives the bank the best chance of tracing or freezing funds. Affected customers, suppliers or staff may also need clear, factual communication if their information or correspondence was involved.

Keep a short, accessible incident checklist with contact details for your IT support, bank and key decision-makers. Test the process occasionally. It is much easier to make sensible decisions when roles and escalation paths have already been agreed.

A practical place to begin

Start by reviewing the accounts that could cause the greatest disruption: directors, finance staff, payroll, Microsoft 365 administrators and shared finance mailboxes. Confirm that MFA is active, access is current and payment-change verification is documented. Then make sure staff know exactly how to report a suspicious message.

Email compromise prevention is not about making a small business operate like a bank. It is about putting a few reliable checks around the moments where trust, access and money meet. Those checks give your team the confidence to get on with their work while making it much harder for a convincing email to become a costly incident.

Book a free IT review with your local team

Talk to a local Central Coast IT team — no jargon, no obligation.