Why Business Email Compromise Belongs to Finance

Occasionally my clients ask me for a more thorough explanation of why I’m recommending a given control. In addition to a formal write-up, I’m also sharing a version of that research here.

In 2025, the FBI’s Internet Crime Complaint Center (IC3) recorded over three billion dollars in business email compromise (BEC) losses across 24,768 reported incidents. While security vendors keep selling AI-powered “cyber risk” solutions, employees are wiring money to fraudsters because someone they trust told them to in an email.

The latest proof comes from the Seventh Circuit, where a federal appeals court told a nonprofit insurance receiver (an entity that winds down insolvent insurers) that its $4 million loss from a compromised email account isn’t covered by its policy. The court’s reasoning had nothing to do with cybersecurity and everything to do with business controls.

What Happened at OSD

The Office of the Special Deputy Receiver (OSD), an Illinois non-profit that administers estates for insolvent insurance companies, held a Financial Institution Bond from Hartford Fire Insurance Company. Threat actors gained access to the Chief Financial Officer’s (CFO) email account through a spear phishing scheme, then impersonated the CFO and instructed other employees to wire funds for supposed new investments.

They even altered email settings so they could respond to follow-up questions from staff without raising suspicion. Over several weeks, OSD wired out nearly $7 million and recovered about $3 million, for a net loss of roughly $4 million. Earlier coverage of this incident focused on the technical controls to prevent identity compromise, but that misses the point.

How the Court Decided

When OSD filed a claim, Hartford denied it. The denial turned on two policy riders:

RiderWhat It CoveredWhy It Didn’t Apply
Rider 13Computer systems fraud (fraudulent entry/change of electronic data)Didn’t reach this loss; the fraud worked through email instructions to OSD staff, not a fraudulent entry or change of the computer system’s data
Rider 17Email-initiated transfer fraudOnly covered emails from customers, their authorized employees, or financial institutions acting on behalf of customers

The fraudulent emails from the CFO’s account didn’t meet Rider 17’s affirmative coverage criteria, so they fell into the rider’s exclusion clause, which barred losses from “fraudulent instruction sent to [OSD] through electronic mail” unless covered by the affirmative grant.

OSD argued the exclusion shouldn’t apply because the emails moved within the organization rather than arriving from outside. The Seventh Circuit disagreed. Writing for the panel, Circuit Judge Kirsch held that the exclusion looks at who received the email, not who sent it. The emails were sent to OSD employees, and for purposes of the rider, those employees are OSD. Exclusion applies, case dismissed.

Read the opinion and notice what’s missing. There’s no discussion of email filtering, identity protection, multi-factor authentication (MFA), security awareness training, or whether OSD maintained “reasonable” cybersecurity. The court never evaluated the technical sophistication of the attack or the adequacy of OSD’s security posture. It analyzed contract language, parsed the difference between affirmative coverage grants and exclusion clauses, and resolved the dispute on a motion to dismiss. The spear phishing was background; the legal question was purely about contract language.

The Real Failure Wasn’t Technical

This is the part that CISOs and senior security leaders should be focusing on. The loss didn’t happen because a firewall failed or an intrusion detection system missed an alert. It happened because employees authorized wire transfers based on email instructions without independent verification. No exploit moved the money; people did, following what they believed was a legitimate direction from their CFO.

The controls that would have prevented this loss aren’t cybersecurity controls. They’re financial controls:

  • Dual authorization on payments above a threshold stops the fraud when a second signatory picks up the phone to confirm
  • Callback verification using pre-existing phone numbers, never numbers supplied in the email itself, exposes the scheme on the first transfer
  • Regular review of payment approval procedures catches informal shortcuts that quietly become routine

These controls live in the finance department’s procedures manual.

Where Ownership Breaks Down

Labeling this a “cyber risk” creates a dangerous ownership gap, something I extensively discuss fixing in my book. According to Hyperproof’s 2024 IT Risk and Compliance Benchmark Report (a report I’d also contributed to), 70% of organizations managing risk in silos faced security incidents in the prior 24 months, a rate that dropped sharply among organizations with integrated risk management approaches.

The security team focuses on reducing email account compromise probability through filters, MFA, and training. Those are worth doing, but they’re upstream controls that reduce the odds of the trigger event, and they do nothing to limit the consequence once the trigger fires. Meanwhile, the finance team manages payment authorization and cash controls without considering what happens when an executive’s email identity is weaponized.

The $4 million falls in the gap between those two silos.

FunctionWhat They OwnWhat They Miss
Security (Chief Information Security Officer, CISO)Email filtering, MFA, endpoint protection, intrusion detectionPayment authorization procedures and verification protocols
Finance (CFO)Wire transfers, vendor banking changes, reconciliationWhat happens when an executive email identity is compromised
Executive LeadershipOverall risk appetite, insurance coverageThe gap between security controls and business processes

What Companies Should Actually Do

Start with the consequence, not the vector. Ask: “If our CFO’s email is compromised tomorrow, what prevents someone from wiring out $7 million?” That question leads to business controls. Asking “how do we stop phishing?” leads to filters that are necessary but insufficient when credentials are already stolen.

Map every so-called “cyber risk” to its business consequence. A compromised email account isn’t a security incident; it’s a potential fraudulent payment, a vendor impersonation, a banking detail change. Each of those outcomes has an owner in the business, and that owner needs to design controls for the scenario where the technical layer fails, because it will.

Make wire transfer authorization a shared accountability. The CISO owns email security, and the CFO owns payment authorization. The gap between those two responsibilities is where money disappears, and closing it requires both parties in the same room, designing controls together with clear thresholds for when a transaction requires verbal confirmation, dual approval, or delayed release.

Track business metrics, not technical ones:

  • Percentage of high-value transfers with dual approval
  • Number of vendor banking changes audited quarterly
  • Days to verify payment requests
  • Share of transactions above threshold that received the required verbal confirmation before release

These tell leadership whether the organization can survive a compromised email account. Vulnerability counts and patch rates don’t.

The Bottom Line

The Seventh Circuit didn’t care about the spear phishing. Hartford didn’t deny coverage because OSD’s cybersecurity was weak. The court cared about contract language, recipient identity, and the difference between an affirmative coverage grant and an exclusion clause.

Treat business email compromise the same way. Stop calling it a cyber risk and handing it to IT. That doesn’t mean IT walks away; it means finance owns the control that actually stops the loss, and the two functions build it together. The money moves through finance, the insurance responds to contract language, and the controls that matter are the ones nobody thinks to check until $4 million is gone.

Understand the stories that matter.

Every week, I break down the most important updates in cybersecurity, AI, law, and policy. Human-written, deeply analyzed.

I don’t spam! Read the privacy policy for more info.

Similar Posts