Skip to main content
Annual Tabletop
Menu
Business Email Compromiseintro~45 min

Wire Fraud via BEC — The Auditor's Favorite SMB Scenario

A finance lead authorizes a $187K wire to a 'new vendor' after a CEO email thread that turns out to be a BEC. Run the response your SOC 2 / cyber-insurance underwriter wants documented.

Learning objectives

  • Walk the SOC 2 CC7.4 incident-response chain end-to-end.
  • Produce documented evidence of containment within 24 hours.
  • Map response decisions to FFIEC Information Security Booklet expectations.

Scenario brief

## Scenario context

Anchor scenario for regulated SMBs. Built around the response evidence SOC 2
and FFIEC examiners actually ask for.

Bring this scenario to your next exercise.