A BEC Incident Response Playbook for Small Security Teams
September 16, 2026
Detect, contain, investigate, notify, recover. A practical business email compromise playbook you can run with a two-person IT team.
Most BEC damage comes from hesitation, not from a lack of tooling. A one-page playbook agreed to in advance removes the hesitation. Here is the structure we use.
Triggers
Define what starts the playbook: a reported suspicious sign-in, a forwarding rule nobody created, a vendor claiming your bank details changed, an impossible-travel alert, or finance flagging a changed payment instruction. Any one of them, not a consensus of several.
Roles
Name in advance the incident commander, the identity administrator with permission to revoke sessions at 2am, the finance contact who can call the bank, the legal or counsel contact, and the person who calls the insurance carrier. Include phone numbers, because email is the compromised channel.
Contain — first 60 minutes
Reset credentials, revoke sessions and tokens, remove malicious rules and grants, purge unknown MFA methods, and block the attacker's infrastructure. Freeze any pending payments touched by that mailbox.
Preserve
Export sign-in logs, audit logs, message trace, and the rule definitions before remediation. Snapshot the mailbox. Note timestamps in UTC. Assume every artifact will be read by someone else months later.
Investigate
Establish the initial access method, the dwell time, every account touched, whether files or shared drives were reached, and whether any payment or payroll data was altered.
Notify
Bank first if money moved. Then carrier or broker — most policies require prompt notice and many require pre-approval of vendors. Then counsel, who owns the regulatory notification decision. See cyber insurance requirements after an email breach.
Recover and verify
Restore normal access, close the entry path tenant-wide, add detections for the technique used, and write a short after-action with three concrete changes. Then tabletop it once a quarter so the runbook is not read for the first time during an incident.
If you would rather not staff a 2am rotation to make this work, that is what our 24/7 SOC is for.
Business email compromised right now? Call 1-844-LYRA-REC — our incident commanders answer live 24/7 and start containment on the first call. See our business email compromise response page for the first-hour checklist.