Assess your business's vulnerability to Business Email Compromise (BEC) fraud. Free 10-question assessment with instant results and actionable recommendations.
Business Email Compromise is the single biggest fraud threat to Irish businesses. A Donegal business group lost over €1 million to a BEC attack. Nationally, Irish businesses lose millions every year to invoice fraud, CEO impersonation, and supplier spoofing.
The assessment evaluates your vulnerability to BEC attacks across email security, financial controls, staff awareness, and incident response. It takes less than 5 minutes and gives you an instant risk score with specific recommendations: your overall BEC risk level (Low / Moderate / High / Critical), which specific controls are missing or weak, and prioritised recommendations you can act on immediately.
The Controls the Assessment Covers
The 10 questions span six areas: email security, financial controls, people and training, detection, supply chain, and response.
- Multi-factor authentication on all email accounts, including shared mailboxes and admin accounts — the single most effective control against BEC
- A verbal verification process for all payment changes — calling back on a known number is the number one defence against invoice fraud and CEO fraud
- SPF, DKIM, and DMARC on your email domain — email authentication stops attackers spoofing your domain; SPF alone is not sufficient
- Blocking automatic email forwarding to external addresses — one of the first things attackers set up after compromising an account
- Staff training to recognise CEO fraud and impersonation attacks — BEC uses social engineering, not malware
- Dual authorisation for payments above a threshold — prevents a single compromised account authorising fraud
- Audit logging on email accounts with alerts for unusual login locations, forwarding rule changes, or bulk downloads
- Independent verification of supplier bank details before first or changed payments — supplier impersonation is the most common BEC variant in Ireland
- Disabling legacy email protocols (POP3, IMAP, basic authentication) — legacy protocols bypass MFA entirely
- A documented BEC response procedure with contacts — every minute of delay reduces the chance of recovering funds
How Scoring Works
Each of the 10 questions scores 0 to 3 points depending on how fully the control is implemented, for a maximum of 30. Your percentage maps to a risk level: 80% or above is Low BEC Risk, 60-79% Moderate, 40-59% High, and below 40% Critical. Results also break down your score by category, rating each area Strong, Needs Improvement, or Critical Gap.
What the Risk Levels Mean
Low BEC Risk
Strong defences against Business Email Compromise; your financial controls and email security are well above average for Irish SMEs. Maintain your controls and run BEC simulation exercises annually.
Moderate BEC Risk
Some good controls in place, but gaps remain that a determined attacker could exploit. Most BEC losses occur in businesses at this level. Payment verification and email authentication gaps can be fixed in days, not weeks.
High BEC Risk
Significant exposure — multiple controls that prevent the most common fraud scenarios are missing. An urgent review of your email security and financial controls is strongly recommended.
Critical BEC Risk
Highly vulnerable — without immediate action, a successful BEC attack is a matter of when, not if. The controls needed are straightforward and can be implemented quickly.
The BEC Threat in Ireland
Our team holds CISA, CISSP, and CISM certifications and has direct experience investigating BEC incidents with Irish businesses. Results include a downloadable PDF report and the option to book a free BEC review call.
- A Donegal business group lost over €1 million to a BEC attack
- BEC accounts for more financial losses than ransomware globally (FBI IC3 Report 2024)
- The average BEC loss for SMEs is €120,000 — often unrecoverable
- 91% of BEC attacks start with a compromised email account