Skip to content

Free for nonprofits, NGOs, think tanks, and institutes. Grant funded by James Scott, administered by the Embassy Row Project.

ArtOfTheHack home

Email Security

Preventing Business Email Compromise and Payment Diversion

Payment diversion succeeds because the request looks routine, and no single system holds enough evidence to judge it alone.

Audience
Nonprofit, Foundation
Cybersecurity topic
Identity Security, Data Protection, Incident Response
Reading time
3 minutes
Related capability
Suspicious Message Adjudication
Diagram showing email, identity, payment approval, and bank-change signals converging into a single governed verification decision node.

The most damaging email breach often begins with a message that appears entirely routine. A supplier requests a change in bank details. A senior executive asks for an urgent transfer. A program director sends a link to an updated grant document. Nothing in the message looks unusual enough to stop the process.

Business email compromise succeeds because it exploits institutional habits. Attackers study approval patterns, writing styles, reporting lines, payment schedules, and vendor relationships. They do not need to defeat every security control. They need to produce one believable request at the right time.

Email filtering alone cannot resolve the problem. The decision depends on evidence held across the identity provider, device platform, email system, finance records, vendor database, and approval workflow. A message may be authentic while the sender’s account is compromised. A bank change may be legitimate while the approval path is incomplete.

KRYOS-XS Hypercube can correlate these signals before a high-consequence action proceeds. It may detect that an executive’s account was accessed from a new device, that a mailbox rule was recently created, that the requested payment destination has never been used, and that the change falls outside the usual vendor process.

The response should remain proportionate. The system might hold the transaction, require voice verification, request approval from a second authority, restrict the email session, or revoke active tokens. It should not automatically accuse an employee or vendor of fraud when the evidence remains uncertain.

A governed decision record preserves what was known, which signals disagreed, who approved the response, and what happened afterward. That record supports internal review, insurance claims, donor assurance, and future policy improvement.

Payment protection is strongest when email security and financial authority are treated as one decision problem rather than two separate workflows.

Related Use Cases

Protect the Systems Your Mission Depends On.

Eligible nonprofit organizations may apply for grant-funded access to ArtOfTheHack cybersecurity services powered by KRYOS-XS Hypercube.