AI Governance Institute logo
AI Governance Institute

Intelligence for Compliance and GRC Teams

← All news

Business Email Compromise

Business email compromise involves fraudulent actors gaining unauthorized access to corporate email accounts to conduct financial fraud, espionage, or social engineering attacks. These breaches pose significant governance risks because attackers can impersonate executives to authorize unauthorized wire transfers, access sensitive data, or compromise downstream systems. For enterprises, defending against BEC requires coordinated controls spanning email authentication, access management, user training, and transaction verification procedures that fall under broader information security and compliance frameworks.

1 item