Let's put a plan to your ambition
A practical business email compromise drill for small businesses that pay suppliers, manage invoices or change bank details.
It is Friday at 4:47 pm.
A supplier emails your accounts person. The message looks normal. Same logo. Same tone. Same email chain. They say their bank details have changed and ask you to update the next payment.
The invoice is due today.
What happens next?
It is Friday at 4:47 pm.
A supplier emails your accounts person. The message looks normal. Same logo. Same tone. Same email chain. They say their bank details have changed and ask you to update the next payment.
The invoice is due today.
What happens next?

Image Caption
The scam isn’t always obvious
Business email compromise doesn’t always look like a cartoon scam. It can be sitting inside a compromised mailbox, watching normal conversations, waiting for the right time to redirect a payment.
The email might come from the real account. It might use the same writing style. It might refer to a real invoice. It might land when everyone is tired and trying to clear the payment run.
That’s why the control can’t be "see if the email looks suspicious". Sometimes it won’t.
Business email compromise doesn’t always look like a cartoon scam. It can be sitting inside a compromised mailbox, watching normal conversations, waiting for the right time to redirect a payment.
The email might come from the real account. It might use the same writing style. It might refer to a real invoice. It might land when everyone is tired and trying to clear the payment run.
That’s why the control can’t be "see if the email looks suspicious". Sometimes it won’t.
The one bit of gold
Never verify changed payment details using the phone number or contact details contained in the message requesting the change.
Use a number already held in your accounting system, supplier file, signed agreement or earlier verified correspondence. If the only number you use came from the new email, the scammer may simply answer the phone.
Your minimum process
Every business that pays suppliers should have a bank-detail-change process.
At minimum:
Verify the change using previously known contact details.
Require a second person to approve the change.
Record who verified it, when and how.
Send a confirmation to the original known contact.
Turn on multi-factor authentication for email and accounting software.
Never verify changed payment details using the phone number or contact details contained in the message requesting the change.
Use a number already held in your accounting system, supplier file, signed agreement or earlier verified correspondence. If the only number you use came from the new email, the scammer may simply answer the phone.
Your minimum process
Every business that pays suppliers should have a bank-detail-change process.
At minimum:
Verify the change using previously known contact details.
Require a second person to approve the change.
Record who verified it, when and how.
Send a confirmation to the original known contact.
Turn on multi-factor authentication for email and accounting software.
Add technical controls
Process matters, but so does security. Multi-factor authentication, software updates and backups are the starting point. Email security, password managers, domain protection and staff training reduce the chance that someone can get inside the system in the first place.
The Cyber.gov.au Cyber Health Check is a useful five-minute starting point for businesses that don’t know where they stand.
Consider eInvoicing where it fits
eInvoicing isn’t a magic shield, but it can reduce reliance on emailed PDF invoices and manual data entry. Instead of invoices being emailed around as attachments, invoice data is exchanged through connected software over the network.
For businesses with large invoice volumes, recurring supplier risk or government customers, it’s worth reviewing whether your accounting software supports eInvoicing.
Process matters, but so does security. Multi-factor authentication, software updates and backups are the starting point. Email security, password managers, domain protection and staff training reduce the chance that someone can get inside the system in the first place.
The Cyber.gov.au Cyber Health Check is a useful five-minute starting point for businesses that don’t know where they stand.
Consider eInvoicing where it fits
eInvoicing isn’t a magic shield, but it can reduce reliance on emailed PDF invoices and manual data entry. Instead of invoices being emailed around as attachments, invoice data is exchanged through connected software over the network.
For businesses with large invoice volumes, recurring supplier risk or government customers, it’s worth reviewing whether your accounting software supports eInvoicing.
What to do this week
What to do this week
Create the bank change process, keep it simple and put it where the accounts team can see it.
Useful links
Website disclaimer note: This article provides general information only and does not take into account your circumstances. It is not a substitute for tax, legal, financial, employment, cyber security or other professional advice.
Create the bank change process, keep it simple and put it where the accounts team can see it.
Useful links
Website disclaimer note: This article provides general information only and does not take into account your circumstances. It is not a substitute for tax, legal, financial, employment, cyber security or other professional advice.
Share this post
Got questions?
Maybe it’s time for a
macchiato with Chris.

Got questions?Maybe it’s time for a macchiato with Chris.

Got questions?
Maybe it’s time for a
macchiato with Chris.

Ready to kick-start your
self-made journey?

© 2026 Denari Advisory. Liability limited by a Scheme approved under Professional Standards Legislation.
Strategy and Site by Touching Base
Ready to kick-start your self-made journey?

© 2026 Denari Advisory. Liability limited by a Scheme approved under Professional Standards Legislation.
Strategy and Site by Touching Base
Ready to kick-start your
self-made journey?

© 2026 Denari Advisory. Liability limited by a Scheme approved under Professional Standards Legislation.
Strategy and Site by Touching Base
