← All posts

How To Prevent Email Account Takeover

September 16, 2026

A short, ranked list of controls that actually prevent email account takeover — and the ones that only look like they do.

Not all email security controls are equal. Ranked by how much account takeover risk they remove per dollar and hour spent:

1. Phishing-resistant MFA for the accounts that matter. Passkeys or hardware security keys for executives, finance, IT admins, and anyone who can change payment details. This is the only control that reliably defeats adversary-in-the-middle phishing, which is how modern takeovers bypass app-based MFA.

2. MFA everywhere else, with no standing exceptions. Every exclusion — service accounts, "the CEO hates it", a legacy scanner — is a documented way in.

3. Disable legacy authentication. Protocols that cannot present an MFA challenge quietly undo the control above.

4. Conditional access. Require compliant or managed devices for mail access, restrict risky sign-ins, and block countries you do not operate in.

5. Alert on persistence, not just on login. New forwarding rules, new OAuth consent grants, new MFA registrations, new delegation. These are high-signal and low-volume — the best alerts you will ever write.

6. Reduce privilege. Fewer global admins, no standing admin rights, and privileged access management for the accounts that keep them.

7. Watch for leaked credentials. Dark web credential monitoring closes the reuse route before someone else uses it.

8. Out-of-band payment verification. This does not prevent takeover, but it prevents the loss that makes takeover profitable. Cheapest control on the list.

9. Targeted training. Simulations aimed at the specific scenarios your business faces — invoice redirection, payroll change, executive urgency. Generic annual training moves the needle far less.

Notice what is not at the top: spam filters and email gateways. They matter, but BEC messages usually contain no malware and no link, so filtering is the wrong layer to depend on. Identity and process are where this is won.


Business email compromised right now? Call 1-844-LYRA-REC — our incident commanders answer live 24/7 and start containment on the first call. See our business email compromise response page for the first-hour checklist.

account takeoverpreventionMFAconditional access

24 / 7 Recovery

When the worst day hits, every minute matters.

Our breach team is standing by — call, email, or submit a request and we respond within minutes.