What this drill tests
Business email compromise does not always begin with malware or a dramatic system outage. It may begin with a believable request to change bank details, send a wire, purchase gift cards, release payroll information, or bypass the normal approval process.
The FBI describes business email compromise as a crime in which criminals use spoofed addresses, spearphishing, malware, or compromised accounts to deceive businesses. The FBI recommends not clicking unsolicited messages that ask users to update or verify account information, and it advises victims to contact their financial institution immediately if a fraudulent transfer occurs.
This 25-minute drill tests the human and procedural controls around payment changes. It should use a fictional scenario and must not involve real funds, real credentials, or an actual vendor without prior approval.
Before the drill
Choose a facilitator and two participants:
- One person acts as the office manager or accounts-payable employee.
- One person acts as the owner, controller, or approving manager.
- The facilitator presents the scenario and records decisions.
Prepare a fictional email that says a known supplier has changed its bank account. Include enough detail to create a realistic decision, but do not copy a real vendor message or use a live payment system.
Decide in advance that the exercise will not grade writing style or technical expertise. It will evaluate whether the office follows an independent verification process.
Minute 0–5: Present the request
Give the employee this scenario:
“A regular supplier has emailed an updated invoice and requests that future payments be sent to a new account. The message says the change is urgent because the old account will close today. The sender address appears familiar, and the invoice uses the supplier’s normal branding.”
Ask the employee to state the first three actions they would take. Do not provide hints.
A strong first response should include pausing the payment, avoiding links or attachments until the message is reviewed, and using a trusted communication route to verify the request. Replying to the same email thread is not independent verification if the account may be compromised.
Minute 5–10: Test the verification path
Ask the participant:
- Which phone number or contact method would you use?
- Where did that contact information come from?
- Who is authorized to approve a bank-detail change?
- Is a second person required to approve the payment?
- What evidence would you retain?
The preferred contact method should come from a known vendor record, a previously validated contract, or another trusted source—not from the suspicious message.
The office should define its own approval threshold. For example, any bank-account change might require verbal confirmation with a known contact and written approval from a second employee. The exact procedure can vary, but it should be clear enough that an employee can follow it during a busy day.
Minute 10–15: Add pressure
Introduce a second fact: the sender says the shipment will be delayed unless payment is released within the hour. The employee is also told that the manager is traveling and cannot be reached through the usual channel.
Ask whether the process changes under pressure.
A mature process does not treat urgency as approval. The employee should have a safe escalation route, such as calling the owner through a known number, using a prearranged emergency contact method, or holding the transaction until an authorized person confirms it.
If the business has no backup approval route, record that as a continuity gap. The solution may be a small written procedure, not a new security product.
Minute 15–20: Test reporting
Ask the employee what happens after the request is identified as suspicious.
The answer should cover:
- Preserving the message and relevant headers or transaction details.
- Notifying the manager and IT or security provider.
- Checking whether any related account was accessed.
- Reviewing recent payment activity and mailbox rules where appropriate.
- Warning other employees who may receive similar requests.
- Recording the incident in the company’s internal log.
If money has already moved, the FBI advises contacting the financial institution immediately and requesting that it contact the receiving institution. The business should also report the matter to IC3. Timing matters, so the emergency contact card should contain the bank’s fraud number and the person authorized to make the call.
Minute 20–25: Score the result
Score each item as Yes, Partial, or No:
- The employee paused the payment.
- The employee did not rely on the suspicious email for verification.
- A trusted contact method was available.
- The approval requirement was understood.
- An escalation path existed when the manager was unavailable.
- The suspicious message could be preserved.
- IT or the security provider could be contacted.
- The bank’s fraud contact was easy to find.
- The incident could be documented.
- Staff knew when to notify leadership.
Do not treat a failed answer as an employee failure. The purpose is to expose process weaknesses before a real request arrives.
Improvements to make after the drill
Choose no more than three corrective actions. Examples include:
- Add an independent verification rule to the payment procedure.
- Require two-person approval for new payment destinations.
- Store bank and vendor fraud contacts in a secure, accessible location.
- Train employees not to approve changes from email alone.
- Create a five-minute incident contact card.
- Review mailbox forwarding rules after a suspected account compromise.
- Require vendors to use a documented change-notification process.
Assign an owner and deadline to each action. Schedule a retest within 60 to 90 days.
What this drill does not prove
A successful exercise does not prove that the business will prevent every fraudulent payment. It does not prove that an email account is uncompromised, that vendor records are accurate, or that the bank can reverse a transaction.
It does show whether the organization has a usable decision path under pressure. That is the practical objective: make it easy to pause, verify through a trusted channel, escalate without embarrassment, and report quickly when something goes wrong.
For a small Central Florida office, a 25-minute exercise can reveal more about payment resilience than a policy that employees have never practiced.

