Your inbox gets more attention from criminals than you might think. Email is still the number one way hackers break into a business. They don’t need to hack your servers; they just need one person to click one bad link or trust one fake message from “the boss.”
This trick is called business email compromise, or BEC. It’s simple, but it has a big payoff for criminals. Unfortunately, it happens to UK businesses every single day.
What Business Email Compromise Actually Looks Like
Picture this: someone in your finance team gets an email. It looks like it’s from the CEO and has passed all email security services – same name, same tone, maybe even the same signature. The email asks for an urgent bank transfer or asks to change a supplier’s payment details. It feels rushed and important, so the transfer goes through.
Except it wasn’t the CEO. It was a scammer, and they had studied your company first.
This kind of attack often skips malware completely as there’s no virus to catch, just words. A well-written email, sent at the right moment, is designed to make someone act fast without thinking it through. That’s what makes it so hard to stop with normal antivirus software alone.
Recent research shows how common this has become. BEC attacks now make up a large share of all reported cyber incidents with average losses running into the tens of thousands of pounds per incident. Some businesses have lost hundreds of thousands in a single scam. Sadly, smaller companies are not spared either – criminals often see them as easier targets, because fewer checks are in place.
Why Small Businesses Get Targeted
Many small business owners think they’re too small to matter to a hacker. That belief is exactly what criminals count on.
Attackers don’t pick targets by size; they pick targets by opportunity. If your email has weak spam filters, no extra login checks, and staff who’ve never been shown what a scam email looks like, you’re an easy target. It doesn’t matter if you have five staff or five hundred.
Suppliers get copied too. A scammer might send a fake invoice that looks just like one from a company you already pay. This email may have the same logo, or a similar email address that’s just one letter off. If nobody checks closely, that invoice gets paid without question.
The cost of getting this wrong is rarely just the stolen money. There’s time lost sorting out the mess, the awkward call to your bank, plus the trust you have to rebuild with clients or suppliers who were also dragged into the scam.
The Building Blocks of Real Email Protection
Good email security is not just one single tool, but a few layers working together. If one layer misses something, another one catches it.
Spam and phishing filters. These sit in front of your inbox. They catch obvious scams before they even land. A strong filter blocks bad attachments, dodgy links, and known scam patterns automatically, before your team ever sees them.
Multi-factor authentication. People call this MFA for short. It means logging in takes more than just a password. Even if a scammer steals a password, they still can’t get in without a second step – usually a code sent to a phone. This one simple measure stops a huge number of account break-ins.
Domain authentication. This covers three technical settings called SPF, DKIM, and DMARC. Don’t worry about the names because what they do matters more: stopping criminals from sending emails that look like they came from your own company address. Without them, a scammer could send a message that appears to come from you, even though it didn’t.
Staff awareness training. Filters catch most scams, but not every single one. Your team needs to know the warning signs. Watch for urgent language. Watch for requests to change bank details. Watch for emails that push people to act fast, before they’ve had time to check.
Regular monitoring. Someone needs to watch for strange sign-ins, odd forwarding rules set up inside inboxes, or logins from unexpected countries. These are common signs that an account has already been broken into, even before any money moves.
A Quick Example of How Fast This Can Go Wrong
Say a scammer sends a fake invoice to your accounts team on a busy Friday afternoon. It looks like it’s from a supplier you’ve paid before, the amount is normal and nothing about it screams “scam.” Without a second check in place, the payment goes out before anyone thinks twice. By Monday, when the real supplier chases the unpaid invoice, the money is already long gone.
This exact pattern plays out across UK businesses every week. It rarely involves anything technically clever, it just relies on nobody stopping to check.
Why This Matters More Than Ever
Email threats keep changing because scammers write more convincing messages now. They time their emails better and some even study your company’s website or social media first, so their fake messages sound believable and personal.
At the same time, more of your business runs through email than ever before – invoices, contracts, HR requests, client conversations. If email security fails, the damage can spread across your whole business, not just one inbox.
There’s a knock-on effect many business owners don’t think about too. If your business gets hit through email, and it turns out basic protections weren’t in place, that can affect your insurance cover as well. Insurers now expect to see multi-factor authentication and staff training as standard practice.
How Cheeky Munkey can help you protect your inbox
A well-protected inbox shouldn’t feel complicated to the person using it. Staff should barely notice the security working behind the scenes. What they will notice is fewer suspicious emails reaching them, maybe a quick prompt for a login code now and then, and clear guidance on what to do if something still looks off.
Behind the scenes, this comes from proper setup. Filtering tuned to catch real threats, without blocking genuine emails by mistake. Authentication configured correctly across your whole domain. Monitoring that catches problems early, rather than after the money has already gone.
None of this needs to be complicated for your team to manage on their own – that’s the whole point of bringing in specialists.
This is exactly the kind of setup Cheeky Munkey builds for clients across St Albans and the wider UK. Our team looks at how your business actually uses email day to day, then we put the right layers of protection in place. These layers include filtering, MFA, and staff training that people actually remember, rather than forget within a week.
If you’d like a straightforward look at how secure your inbox really is, get in touch with the Cheeky Munkey team for a chat.
About The Author
Daniel Poulton
Daniel Poulton is an accomplished Technical Consultant with a strong background in cybersecurity, cloud technologies, and modern workplace solutions. His expertise spans incident response, SIEM management, Azure administration, cloud security, and IT infrastructure – skills developed through a progression of hands-on technical and security-focused roles.
In his current role, Daniel plays a key part in delivering secure, scalable, and future-ready technology environments. He is known for combining technical depth with a practical approach to designing and improving security-driven solutions. His work has contributed to teams achieving respected industry recognitions such as Microsoft Threat Protection and Cloud Security Advanced Specialisations.
Daniel’s career is underpinned by a clear mission: to help organisations strengthen their digital resilience through thoughtful design, smart tooling, and security that genuinely works for people.
Previous