Skip to main content

Business email compromise (BEC) playbook 

This playbook has technical guidance for responding to a business email compromise incident. It is not a standalone resource: use it alongside your incident management plan to make sure it works for your school.

Containment

Prioritise accounts and systems that hold or can access financial or personal data.

Verify that any accounts with key privileges are secure and have not been compromised. You can do this by having your technical team or service provider audit account access and verifying only the legitimate user has access to their account.