How Long Does It Take To Recover From BEC?
September 16, 2026
Containment in hours, forensics in days, notification in weeks, and the financial tail in months. A realistic timeline for business email compromise.
Leadership always asks for a date. Here is the honest breakdown, based on the incidents we run.
Hours 0–4: containment
Credential reset, session and token revocation, persistence removal, payment freeze, and the first bank call. A single mailbox with good administrative access is genuinely a few hours of work.
Day 1–3: scoping
Log export and analysis, determining initial access and dwell time, and identifying every account touched. If mailbox auditing was already enabled, this is fast. If it was not, this phase stretches and the conclusions get more conservative — which costs money later.
Day 2–10: cleanup and hardening
Tenant-wide rule and grant audits, MFA improvements, conditional access changes, disabling legacy authentication, and warning counterparties. Users are working normally through this phase.
Week 2–8: notification, if required
Data review, individual identification, drafting, and regulator filings. Counsel-driven, and the longest phase when a mailbox held a lot of personal information.
Month 1–12: the financial and legal tail
Insurance claim adjustment, potential fund recovery, any law enforcement follow-up, and in larger matters, litigation. Wire recovery itself is decided in the first 24 to 72 hours, even though the paperwork lasts far longer.
What shortens all of it
- Mailbox and unified audit logging already enabled
- Administrative access available at 2am without a change request
- A named incident commander and a written playbook
- Carrier and counsel contacts on a phone list, not in the compromised mailbox
- Responders who have done this before
The gap between a prepared company and an unprepared one is not one of tooling. It is roughly a week of elapsed time and often an order of magnitude in cost.
Business email compromised right now? Call 1-844-LYRA-REC — our incident commanders answer live 24/7 and start containment on the first call. See our business email compromise response page for the first-hour checklist.