Business Email Compromise Recovery Time Estimator

This estimator calculates a planning recovery time for a business email compromise incident by adding the major response phases: detection and triage, account containment, payment investigation, mailbox remediation, and business validation. A coordination factor can be used to reflect delays from handoffs, external banks, legal review, or parallel work.

The estimate helps incident response leaders set service targets, staffing expectations, and tabletop exercise benchmarks. It is a scenario model rather than a guaranteed restoration time, because banking response, evidence preservation, and identity compromise can materially change the timeline.

Scenario inputs

hr
hr
hr
hr
hr
%
Result
Estimated BEC recovery time
Base task time
Coordination overhead
Equivalent 8-hour workdays

1. Estimate detection and triage

Enter the time from alert or report to confirming that the event is a credible BEC incident.

2. Add containment time

Include disabling sessions, resetting credentials, securing mail rules, and blocking attacker access.

3. Estimate payment investigation

Include bank contact, transfer tracing, recall requests, and review of affected invoices or vendors.

4. Add remediation and validation

Estimate mailbox cleanup, endpoint checks, identity hardening, and confirmation that normal payment operations can resume.

5. Apply coordination overhead

Use a percentage for waiting, handoffs, approvals, external parties, and work that cannot proceed continuously.

6. Review total recovery time

Compare the estimate with incident response objectives and run alternate scenarios for nights, weekends, or cross-border banking delays.

Base task time = Detection + Containment + Investigation + Remediation + Validation
Coordination overhead hours = Base task time × Coordination overhead rate
Estimated recovery time = Base task time + Coordination overhead hours

Where:

  • Each phase: estimated labor-clock hours for that response activity
  • Coordination overhead rate: percentage added for handoffs, waiting, and dependencies

Assumptions: The model treats phase estimates as additive. If tasks reliably run in parallel, enter net elapsed time for those phases rather than total person-hours.

What the result means

The main result is a scenario estimate derived from the values entered and should be compared with alternative assumptions.

Use documented internal data where available and test conservative, expected, and severe cases.

Given:

  • Detection and triage: 2 hours
  • Account containment: 3 hours
  • Payment investigation: 8 hours
  • Mailbox remediation: 5 hours
  • Business validation: 4 hours
  • Coordination overhead: 20%

Calculation:
Base time = 2 + 3 + 8 + 5 + 4 = 22 hours. Overhead = 22 × 0.20 = 4.4 hours. Total = 22 + 4.4 = 26.4 hours.

Result:
26.4 hours, or 3.30 eight-hour workdays

Interpretation:
The scenario suggests a little more than three working days of elapsed recovery effort under the stated assumptions.

Is bank recovery time included?

Include expected bank contact and recall work in payment investigation. Long external waiting periods can be reflected through coordination overhead or by increasing that phase directly.

Should the inputs be person-hours or elapsed hours?

Use elapsed hours for the modeled recovery path. Adding person-hours from parallel teams would overstate the calendar time.

What marks the end of recovery?

Use a practical endpoint such as secured accounts, completed payment review, restored email operations, and validated business processes. Post-incident lessons learned can be tracked separately.

How should weekends affect the estimate?

Increase the affected phases or overhead if banks, vendors, legal teams, or administrators are unavailable outside business hours.

Why is this not a recovery time objective calculator?

This tool estimates likely recovery duration from task assumptions. A recovery time objective is a management target and may be shorter or longer than the estimate.