Business email compromise (BEC)
In one sentence
A scam where an attacker uses a hacked or spoofed email account to trick someone into sending money or data.
In BEC, attackers impersonate an executive, vendor, or partner, often after quietly reading a compromised mailbox, to request a wire transfer, a change of bank details, or sensitive data. It relies on trust and urgency, not malware.
Why it's on your cyber insurance application
Business email compromise and funds-transfer fraud drive the majority of small-business cyber claims (58% per Coalition 2026).
How the Readiness Check scores it
The free Check asks the same question a carrier will. Here it is, why it's asked, and the fix if today's honest answer is no. The full application question list has the rest.
Email security
What protections sit in front of your business email?
Why carriers ask: Business email compromise drives more claims than ransomware. Carriers ask what filtering and anti-spoofing protections sit in front of your inbox.
If the answer is no: Move email to Microsoft 365 or Google Workspace if self-hosted; enable their anti-phishing protections and SPF/DKIM/DMARC.
Funds-transfer controls
Before changing bank details or sending an unusual payment, do you verify by phone using a known number?
Why carriers ask: Funds-transfer fraud is the single most common small-business loss type. A documented call-back verification procedure is cheap and prevents it, and some carriers require it for full FTF coverage.
If the answer is no: Institute the call-back rule today and tell every person who can move money. It's free and it prevents the most frequent claim type outright.
The written evidence carriers accept
A “yes” on the application needs a document behind it. In the Readiness Pack, those documents are:
Related terms
Would you pass this question today?
The free Readiness Check scores you across the ten control domains carriers probe, in five minutes, no email required for the score.