Home / Case Studies / OYA Business Email Compromise
Case Study · Financial Services · Business Email Compromise

OYA Financial Services strengthened BEC controls across email, identity and payment-risk workflows

OYA Financial Services depends on email, Microsoft 365, finance workflows, supplier communication, settlement activity and executive approval pathways every day. That operating model creates a specific cyber risk: business email compromise. In financial services, attackers do not need to bring down systems to cause damage — a convincing payment-change request, supplier impersonation, compromised mailbox or executive-style instruction can create financial exposure before anyone realises an attack is underway.

Inlight IT strengthened OYA Financial Services' BEC controls by focusing on the full risk path: Microsoft 365 security, identity protection, email authentication, mailbox risk, anti-impersonation settings and payment-verification discipline.

INBOUND MAILVERIFICATIONPAYMENT PAYMENT VERIFICATION IMPERSONATION BLOCKEDAUTHENTICATEDPAYMENT WORKFLOW OYA / FINANCIAL SERVICES / EMAIL & PAYMENT SECURITY VERIFY BEFORE YOU PAY
Engagement at a glance

OYA Financial Services — business email compromise risk reduction

Strengthened BEC controls across email, identity and payment-risk workflows.

Client
OYA Financial Services
Industry
Financial services
Environment
Email- and Microsoft 365-dependent finance workflows with high-value transactions and multiple external parties
Starting point
The work began with Inlight IT's response to a business email compromise event in the environment
Engagement type
BEC risk reduction across Microsoft 365 security, identity, email authentication, mailbox risk and payment-process controls
Approach
Technical and operational controls addressed together, without slowing ordinary business
Outcome
A stronger BEC prevention posture — impersonation harder, compromise more visible, payment-change fraud harder to execute
Key project stats

One event became a stronger prevention posture

5
points on the attack path

Sender, mailbox, identity, user decision and payment process — the review followed the path an attacker would use.

2
layers addressed together

The technical controls that make impersonation and mailbox compromise harder, and the operational controls that stop a fraudulent request becoming a financial loss.

1
convincing email is all it takes

Often the attack is a convincing email that looks like a legitimate supplier request, executive instruction, settlement update or payment-detail change.

0
payment changes actioned from email alone

Payment-verification discipline means a high-risk payment-change request cannot be actioned from email alone.

Operating context

Business email compromise is effective because it blends into normal commercial activity

The attacker does not always need malware, cyber attack or a system outage. Often the attack is a convincing email that looks like a legitimate supplier request, executive instruction, settlement update or payment-detail change.

For OYA Financial Services the risk profile was shaped by how financial services actually works: high-value transactions, multiple external parties, time-sensitive settlements and heavy reliance on email.

Inlight IT's approach reduced exposure on both sides — the technical controls that make impersonation and mailbox compromise harder, and the operational controls that stop a fraudulent request becoming a financial loss.

Why this work mattered

Financial services gives attackers the ingredients BEC needs: money, urgency, trust and multiple parties

The work began with Inlight IT's response to a business email compromise event in the OYA Financial Services environment, and expanded into hardening Microsoft 365 controls, identity, mailbox visibility and payment-process discipline so a similar event would be detected earlier and contained faster.

01

The work began with a real event

Inlight IT responded to a business email compromise event in the environment, then expanded the work into hardening controls so a similar event would be detected earlier and contained faster.

02

Many legitimate requests arrive by email

The environment includes internal teams, external advisers, brokers, custodians, lawyers, suppliers, settlement agents and clients — a communication pattern where many legitimate payment and document requests arrive by email.

03

The risk profile was shaped by how financial services works

High-value transactions, multiple external parties, time-sensitive settlements and heavy reliance on email shaped the exposure.

04

Controls could not slow ordinary business

The controls had to reduce fraud risk without slowing legitimate payment and document flow.

05

Both sides of the risk had to be addressed

The technical controls that make impersonation and mailbox compromise harder, and the operational controls that stop a fraudulent request becoming a financial loss.

What Inlight IT delivered

BEC risk reduction across Microsoft 365, identity, email authentication and payment-process controls

Inlight IT addressed the technical and operational layers together — making impersonation harder, account compromise less likely, mailbox misuse more visible and payment-change fraud harder to execute.

01

Reducing spoofing and lookalike sender risk

Email authentication and sender controls to make spoofing and lookalike domains harder.

Included
Email authenticationSender controlsSpoofing reductionLookalike domain riskInbound sender checks
02

Making executive and supplier impersonation harder to miss

Anti-impersonation settings targeting the executive- and supplier-style requests BEC relies on.

Included
Anti-impersonation controlsExecutive-style instructionsSupplier impersonationSettlement-update requestsPayment-detail changes
03

Reducing the chance of mailbox compromise

Identity protection, MFA posture and Conditional Access to make account compromise less likely.

Included
Identity protectionMFA postureConditional AccessAccount compromise riskMicrosoft 365 security
04

Improving visibility into post-compromise behaviour

Better visibility into the mailbox behaviours attackers use after gaining access.

Included
Mailbox risk visibilityPost-compromise behaviourSuspicious mailbox activityEarlier detectionFaster containment
05

Stopping the attack at the point money would move

Payment-verification discipline so a payment-change request cannot be actioned from email alone.

Included
Payment-verification disciplinePayment-change controlsHigh-risk payment changesFraud-risk reductionLegitimate flow preserved
Delivery approach

The review followed the path an attacker would use, from inbound sender to the moment money would move

Select a stage to trace the attack path from inbound sender to the moment money would move.

Market context

Business email compromise blends into normal commercial activity

In financial services, attackers do not need to bring down systems to cause damage — a convincing payment-change request, supplier impersonation, compromised mailbox or executive-style instruction can create financial exposure before anyone realises an attack is underway. A BEC control review is strongest when it traces the actual attack path rather than reviewing isolated settings, from the inbound sender through to the moment a payment would move.

1

Often the attack is one convincing email that looks like a legitimate supplier request, executive instruction, settlement update or payment-detail change.

5

The review traced five points where BEC can be stopped: sender, mailbox, identity, user decision and payment process.

2

Exposure reduced on both sides — the technical layer and the operational controls that stop a fraudulent request becoming a financial loss.

0

High-risk payment changes cannot be actioned from email alone under the payment-verification discipline.

OYA Financial Services engagementInlight IT incident response and review record
What changed for the client

A stronger BEC prevention posture across email, identity and payment-risk workflows

The engagement left impersonation harder, compromise more visible and payment-change fraud harder to execute — without slowing legitimate payment and document flow.

O·01

Impersonation made harder

Spoofing, lookalike senders and executive/supplier impersonation are harder to land.

O·02

Account compromise less useful

Identity controls reduce the value of a compromised account.

O·03

Mailbox misuse more visible

Suspicious post-compromise mailbox behaviour is easier to detect.

O·04

Payment-change fraud harder to execute

High-risk payment changes cannot be actioned from email alone.

O·05

Faster detection and containment

A similar event would now be detected earlier and contained faster.

O·06

Controls without slowing legitimate workflows

Fraud risk reduced without slowing legitimate payment and document flow.

Net position

The value was not any single setting. It was reducing BEC on both sides — the technical layer and the commercial process — so a fraudulent request is harder to land and harder to turn into a financial loss.

Project outcomes

BEC is reduced on both sides — the technical layer and the commercial process

Outcome 01

Sender controls

Spoofing and lookalike risk reduced.

Outcome 02

Anti-impersonation

Executive and supplier impersonation harder to miss.

Outcome 03

Identity hardening

MFA and Conditional Access reduce compromise.

Outcome 04

Mailbox visibility

Attacker behaviour after access made visible.

Outcome 05

Payment verification

Money cannot move on email alone.

Outcome 06

Earlier detection

A repeat event detected and contained faster.

Technology and service scope

The work connected email security, identity and payment-verification discipline

Email security

6
  • Email authentication
  • Sender controls
  • Anti-impersonation controls
  • Lookalike domain risk
  • Spoofing reduction
  • Microsoft 365 security

Identity and access

6
  • Identity protection
  • MFA posture
  • Conditional Access
  • Account compromise reduction
  • Executive approval pathways
  • Identity hardening

Detection and response

6
  • Mailbox risk visibility
  • Post-compromise behaviour
  • Earlier detection
  • Faster containment
  • Incident response
  • Cyber resilience posture

Payment-process controls

6
  • Payment-verification discipline
  • Payment-change requests
  • Supplier communication
  • Settlement activity
  • High-value transactions
  • Fraud-risk reduction
Practical next step

Are your payment-change and email security controls strong enough for BEC risk?

We review where email and payment workflows are exposed, then reduce the risk.

Reduce your BEC risk