OYA Financial Services strengthened BEC controls across email, identity and payment-risk workflows
OYA Financial Services depends on email, Microsoft 365, finance workflows, supplier communication, settlement activity and executive approval pathways every day. That operating model creates a specific cyber risk: business email compromise. In financial services, attackers do not need to bring down systems to cause damage — a convincing payment-change request, supplier impersonation, compromised mailbox or executive-style instruction can create financial exposure before anyone realises an attack is underway.
Inlight IT strengthened OYA Financial Services' BEC controls by focusing on the full risk path: Microsoft 365 security, identity protection, email authentication, mailbox risk, anti-impersonation settings and payment-verification discipline.
- Client
- OYA Financial Services
- Industry
- Financial services
- Environment
- Email- and Microsoft 365-dependent finance workflows with high-value transactions and multiple external parties
- Starting point
- The work began with Inlight IT's response to a business email compromise event in the environment
- Engagement type
- BEC risk reduction across Microsoft 365 security, identity, email authentication, mailbox risk and payment-process controls
- Approach
- Technical and operational controls addressed together, without slowing ordinary business
- Outcome
- A stronger BEC prevention posture — impersonation harder, compromise more visible, payment-change fraud harder to execute
OYA Financial Services — business email compromise risk reduction
Strengthened BEC controls across email, identity and payment-risk workflows.
One event became a stronger prevention posture
Sender, mailbox, identity, user decision and payment process — the review followed the path an attacker would use.
The technical controls that make impersonation and mailbox compromise harder, and the operational controls that stop a fraudulent request becoming a financial loss.
Often the attack is a convincing email that looks like a legitimate supplier request, executive instruction, settlement update or payment-detail change.
Payment-verification discipline means a high-risk payment-change request cannot be actioned from email alone.
Business email compromise is effective because it blends into normal commercial activity
The attacker does not always need malware, cyber attack or a system outage. Often the attack is a convincing email that looks like a legitimate supplier request, executive instruction, settlement update or payment-detail change.
For OYA Financial Services the risk profile was shaped by how financial services actually works: high-value transactions, multiple external parties, time-sensitive settlements and heavy reliance on email.
Inlight IT's approach reduced exposure on both sides — the technical controls that make impersonation and mailbox compromise harder, and the operational controls that stop a fraudulent request becoming a financial loss.
Financial services gives attackers the ingredients BEC needs: money, urgency, trust and multiple parties
The work began with Inlight IT's response to a business email compromise event in the OYA Financial Services environment, and expanded into hardening Microsoft 365 controls, identity, mailbox visibility and payment-process discipline so a similar event would be detected earlier and contained faster.
The work began with a real event
Inlight IT responded to a business email compromise event in the environment, then expanded the work into hardening controls so a similar event would be detected earlier and contained faster.
Many legitimate requests arrive by email
The environment includes internal teams, external advisers, brokers, custodians, lawyers, suppliers, settlement agents and clients — a communication pattern where many legitimate payment and document requests arrive by email.
The risk profile was shaped by how financial services works
High-value transactions, multiple external parties, time-sensitive settlements and heavy reliance on email shaped the exposure.
Controls could not slow ordinary business
The controls had to reduce fraud risk without slowing legitimate payment and document flow.
Both sides of the risk had to be addressed
The technical controls that make impersonation and mailbox compromise harder, and the operational controls that stop a fraudulent request becoming a financial loss.
BEC risk reduction across Microsoft 365, identity, email authentication and payment-process controls
Inlight IT addressed the technical and operational layers together — making impersonation harder, account compromise less likely, mailbox misuse more visible and payment-change fraud harder to execute.
01Reducing spoofing and lookalike sender risk
Email authentication and sender controls to make spoofing and lookalike domains harder.
02Making executive and supplier impersonation harder to miss
Anti-impersonation settings targeting the executive- and supplier-style requests BEC relies on.
03Reducing the chance of mailbox compromise
Identity protection, MFA posture and Conditional Access to make account compromise less likely.
04Improving visibility into post-compromise behaviour
Better visibility into the mailbox behaviours attackers use after gaining access.
05Stopping the attack at the point money would move
Payment-verification discipline so a payment-change request cannot be actioned from email alone.
The review followed the path an attacker would use, from inbound sender to the moment money would move
Select a stage to trace the attack path from inbound sender to the moment money would move.
Business email compromise blends into normal commercial activity
In financial services, attackers do not need to bring down systems to cause damage — a convincing payment-change request, supplier impersonation, compromised mailbox or executive-style instruction can create financial exposure before anyone realises an attack is underway. A BEC control review is strongest when it traces the actual attack path rather than reviewing isolated settings, from the inbound sender through to the moment a payment would move.
Often the attack is one convincing email that looks like a legitimate supplier request, executive instruction, settlement update or payment-detail change.
The review traced five points where BEC can be stopped: sender, mailbox, identity, user decision and payment process.
Exposure reduced on both sides — the technical layer and the operational controls that stop a fraudulent request becoming a financial loss.
High-risk payment changes cannot be actioned from email alone under the payment-verification discipline.
A stronger BEC prevention posture across email, identity and payment-risk workflows
The engagement left impersonation harder, compromise more visible and payment-change fraud harder to execute — without slowing legitimate payment and document flow.
Impersonation made harder
Spoofing, lookalike senders and executive/supplier impersonation are harder to land.
Account compromise less useful
Identity controls reduce the value of a compromised account.
Mailbox misuse more visible
Suspicious post-compromise mailbox behaviour is easier to detect.
Payment-change fraud harder to execute
High-risk payment changes cannot be actioned from email alone.
Faster detection and containment
A similar event would now be detected earlier and contained faster.
Controls without slowing legitimate workflows
Fraud risk reduced without slowing legitimate payment and document flow.
The value was not any single setting. It was reducing BEC on both sides — the technical layer and the commercial process — so a fraudulent request is harder to land and harder to turn into a financial loss.
BEC is reduced on both sides — the technical layer and the commercial process
Sender controls
Spoofing and lookalike risk reduced.
Anti-impersonation
Executive and supplier impersonation harder to miss.
Identity hardening
MFA and Conditional Access reduce compromise.
Mailbox visibility
Attacker behaviour after access made visible.
Payment verification
Money cannot move on email alone.
Earlier detection
A repeat event detected and contained faster.
The work connected email security, identity and payment-verification discipline
Email security
6- Email authentication
- Sender controls
- Anti-impersonation controls
- Lookalike domain risk
- Spoofing reduction
- Microsoft 365 security
Identity and access
6- Identity protection
- MFA posture
- Conditional Access
- Account compromise reduction
- Executive approval pathways
- Identity hardening
Detection and response
6- Mailbox risk visibility
- Post-compromise behaviour
- Earlier detection
- Faster containment
- Incident response
- Cyber resilience posture
Payment-process controls
6- Payment-verification discipline
- Payment-change requests
- Supplier communication
- Settlement activity
- High-value transactions
- Fraud-risk reduction
Are your payment-change and email security controls strong enough for BEC risk?
We review where email and payment workflows are exposed, then reduce the risk.
Reduce your BEC risk