APPLICATIONS & OAUTHILLUSTRATIVE
SCOUTz product evidence supporting BEC Starts With a Login, Not Malware.

Ask people to picture a cyberattack and they picture malware. Something malicious lands on a machine, screens lock, a ransom note appears. That's the movie version, and it's why so much SMB security spending goes to endpoint tools and firewalls.

Meanwhile, the loss that insurance carriers fear most, the one behind the largest share of claims paid, involves no malware at all. Business email compromise is just someone logging in. With a real password, from a real browser, into a real mailbox. Nothing detonates. Nothing trips an antivirus. Someone who isn't your client's CFO is simply reading your client's CFO's email, patiently, sometimes for months.

Then comes the part that does the damage. The attacker learns the rhythms: who approves wires, what invoices look like, which vendor is due for payment. At the right moment they send the email, from the real account or a lookalike, nudging a payment to a new account number. The money moves voluntarily. No system was breached in the way a firewall understands breaching. A person was impersonated, convincingly, because the impersonator did their homework inside the actual mailbox.

For MSPs, the setup for this attack is visible in tenant configuration before it happens. There's a checklist, and the scan reads every item on it. Legacy authentication protocols still enabled, which let attackers bypass MFA entirely by using old sign-in methods. Mailbox forwarding rules pushing copies of mail to external addresses, the classic persistence move, sitting in plain sight in the rule list. Delegate permissions granting one account quiet access to another's inbox. Admin accounts, the crown jewels, running without MFA. Anomalous OAuth grants with mail-read permissions.

Every one of those is a configuration fact, not a probability. Either legacy auth is disabled or it isn't. Either that forwarding rule to a Gmail address exists or it doesn't. Which means the BEC conversation with a client doesn't have to be theoretical. It goes: here are the four conditions that enable the most expensive attack in small business, here's which ones are present in your tenant right now, here's the afternoon of work that closes them.

Fix the configuration first. Then train the humans, because verification habits around payment changes still matter enormously. But training people to resist a convincing email is hard, and disabling legacy auth is easy, so do the easy, high-leverage thing first.

The most expensive attack in the SMB world doesn't kick down the door. It logs in. Make sure your clients' doors require more than a password.