← All posts

A BEC Incident Response Playbook for Small Security Teams

September 16, 2026

Detect, contain, investigate, notify, recover. A practical business email compromise playbook you can run with a two-person IT team.

Most BEC damage comes from hesitation, not from a lack of tooling. A one-page playbook agreed to in advance removes the hesitation. Here is the structure we use.

Triggers

Define what starts the playbook: a reported suspicious sign-in, a forwarding rule nobody created, a vendor claiming your bank details changed, an impossible-travel alert, or finance flagging a changed payment instruction. Any one of them, not a consensus of several.

Roles

Name in advance the incident commander, the identity administrator with permission to revoke sessions at 2am, the finance contact who can call the bank, the legal or counsel contact, and the person who calls the insurance carrier. Include phone numbers, because email is the compromised channel.

Contain — first 60 minutes

Reset credentials, revoke sessions and tokens, remove malicious rules and grants, purge unknown MFA methods, and block the attacker's infrastructure. Freeze any pending payments touched by that mailbox.

Preserve

Export sign-in logs, audit logs, message trace, and the rule definitions before remediation. Snapshot the mailbox. Note timestamps in UTC. Assume every artifact will be read by someone else months later.

Investigate

Establish the initial access method, the dwell time, every account touched, whether files or shared drives were reached, and whether any payment or payroll data was altered.

Notify

Bank first if money moved. Then carrier or broker — most policies require prompt notice and many require pre-approval of vendors. Then counsel, who owns the regulatory notification decision. See cyber insurance requirements after an email breach.

Recover and verify

Restore normal access, close the entry path tenant-wide, add detections for the technique used, and write a short after-action with three concrete changes. Then tabletop it once a quarter so the runbook is not read for the first time during an incident.

If you would rather not staff a 2am rotation to make this work, that is what our 24/7 SOC is for.


Business email compromised right now? Call 1-844-LYRA-REC — our incident commanders answer live 24/7 and start containment on the first call. See our business email compromise response page for the first-hour checklist.

BEC incident responseplaybookIRtabletop

24 / 7 Recovery

When the worst day hits, every minute matters.

Our breach team is standing by — call, email, or submit a request and we respond within minutes.