Business Email Compromise Risk Exposure Estimator

This estimator translates business email compromise (BEC) exposure into an annualized dollar figure by combining the amount potentially transferable, the probability of an attempt, the chance that an attempt succeeds, and the share of funds likely to remain unrecovered. It is useful for finance, security, and risk teams evaluating payment controls, executive impersonation defenses, and vendor-change verification procedures.

The result provides a consistent scenario value for comparing control options and setting risk-reduction priorities. It is not a prediction of a specific fraud event; it is a structured estimate based on the assumptions entered.

Scenario inputs

USD
/yr
%
%
Result
Annualized BEC risk exposure
Expected successful events
Gross annual fraud exposure
Expected recovery offset

1. Define the exposed payment amount

Enter the typical maximum amount that could be sent or redirected in one credible BEC event.

2. Estimate yearly attempts

Use the number of realistic payment-change, invoice-redirection, or executive-impersonation attempts expected in a year.

3. Set the success assumption

Enter the percentage of credible attempts that could bypass current preventive controls.

4. Estimate unrecovered funds

Use the portion of a fraudulent transfer that would likely remain lost after bank recalls, insurance, or other recovery.

5. Review annualized exposure

Use the main result as a scenario value and compare it with the cost of stronger verification and monitoring controls.

Expected successful events = Attempts per year × Success rate
Gross exposure = Expected successful events × Funds exposed per event
Annualized risk exposure = Gross exposure × Unrecovered funds rate

Where:

  • Attempts per year: credible BEC attempts in one year
  • Success rate: percentage of attempts expected to cause a transfer
  • Funds exposed per event: dollars potentially transferred in one successful event
  • Unrecovered funds rate: percentage of transferred funds not recovered

Assumptions: Inputs represent an average planning scenario and do not include legal fees, downtime, notification costs, or reputational effects unless embedded in the per-event amount.

What the result means

The main result is a scenario estimate derived from the values entered and should be compared with alternative assumptions.

Use documented internal data where available and test conservative, expected, and severe cases.

Given:

  • Funds exposed per event: $250,000
  • Credible attempts per year: 4
  • Success rate: 8%
  • Unrecovered funds rate: 35%

Calculation:
Expected events = 4 × 0.08 = 0.32. Gross exposure = 0.32 × $250,000 = $80,000. Annualized exposure = $80,000 × 0.35 = $28,000.

Result:
$28,000 per year

Interpretation:
Under these assumptions, the organization carries an average annual BEC loss exposure of $28,000 from unrecovered transfers.

Why is the result annualized?

Annualization makes an infrequent, high-impact fraud scenario comparable with yearly budgets and control costs. It does not mean a loss will occur every year.

Should I use the largest possible payment?

Use a defensible scenario amount, such as a typical high-value payment that could realistically pass through the affected workflow. A separate stress test can use the maximum plausible amount.

How should insurance recoveries be handled?

Include expected insurance or bank recovery in the unrecovered funds rate rather than subtracting it twice. Use the net portion that would remain with the organization.

What if no BEC attempts have occurred yet?

Use threat intelligence, industry experience, or internal near-miss data to form a scenario assumption. Entering zero will correctly produce zero modeled exposure.

How is this different from an expected loss estimator?

This model focuses narrowly on transferable funds and recovery. A broader expected loss model may include investigation, legal, operational, and reputational costs.