1. Define the exposed payment amount
Enter the typical maximum amount that could be sent or redirected in one credible BEC event.
2. Estimate yearly attempts
Use the number of realistic payment-change, invoice-redirection, or executive-impersonation attempts expected in a year.
3. Set the success assumption
Enter the percentage of credible attempts that could bypass current preventive controls.
4. Estimate unrecovered funds
Use the portion of a fraudulent transfer that would likely remain lost after bank recalls, insurance, or other recovery.
5. Review annualized exposure
Use the main result as a scenario value and compare it with the cost of stronger verification and monitoring controls.