Scenarios

Running a business email compromise tabletop exercise that forces the wire-transfer decision

Editorial illustration for the article "Running a business email compromise tabletop exercise that forces the wire-transfer decision".

Business email compromise is among the most prevalent and costly cyberattacks organizations face, and it rarely announces itself with malware or a system outage. It arrives as a plausible email, a compromised or spoofed account, and a request that looks routine until money leaves the building. Palo Alto Networks reports that its Unit 42 incident response team found BEC incidents represented nearly a third of the cases it investigated in 2022, and that the FBI Internet Crime Complaint Center estimates BEC costs organizations three times more in aggregate than any other cybercrime. A business email compromise tabletop exercise is the controlled setting where a leadership team can practice the one decision that determines the loss: whether to release a wire transfer.

This walkthrough shows how to build and run a BEC incident response drill that forces that decision, introduces a fraudulent-vendor inject, and carries participants through the recovery path rather than stopping at detection.

What the exercise is designed to accomplish

A tabletop is a discussion-based simulation in which leaders and responders walk through a scripted incident without touching live systems. The QuickStart 2026 guide describes it as an activity where participants talk through how they would detect, escalate, contain, and recover from a threat, with all actions staying on paper. NIST SP 800-84 remains the foundational framework, defining tabletop exercises as discussion-based events where personnel meet to talk through their roles and responses to a scenario guided by facilitators.

For a BEC drill, the GTIA Cybersecurity Guidebook frames the objective plainly. Its Business Email Compromise scenario is designed to help participants recognize the risks of social engineering and BEC, evaluate internal processes for handling sensitive information requests, and understand the coordinated response required when a key executive is compromised. The point is not to test firewall rules. It is to expose where financial controls, communication protocols, and role clarity break down when a convincing email applies pressure.

Two success measures matter most. First, does the organization treat a payment change or an urgent transfer as an event requiring verification rather than compliance. Second, once fraud is suspected, does the team know the recovery steps and the notification obligations that follow.

Set the room and the ground rules

The people at the table determine whether the exercise reveals anything. The QuickStart guide is direct that the right people must be present: IT, security, legal, executive leadership, communications, and HR, each with enough authority to commit to real trade-offs. When only security personnel attend, the decision bottlenecks that actually cause loss are never tested.

For a BEC scenario the finance function is not optional. The GTIA guidebook calls for executive leadership such as the CEO, COO, and CFO, department heads including legal and operations, and anyone responsible for critical business functions. The person who would actually approve or release a wire transfer must be in the room, along with whoever they would call to verify one.

The facilitator sets the tone. GTIA instructs the facilitator to explain that the exercise is a learning opportunity, not a test, to present the scenario chronologically, and to pause after each turning point to ask open-ended questions. The facilitator guides rather than supplies answers, observing who takes the lead, whether roles are clear, how the group handles pressure, whether anyone references an incident response plan, and where confusion or disagreement surfaces. A session of thirty to forty-five minutes is workable, though the QuickStart guide notes that exercises can run from one to four hours depending on complexity and the number of injects.

The scenario walkthrough

Keep the scenario grounded in how these attacks actually unfold. The GTIA guidebook stresses customizing each scenario to the specific business and environment, because the more realistic and relevant it is, the more honestly participants respond. Names, dollar amounts, and vendor relationships should mirror the organization's real operations.

Phase one, the initial contact

Present the opening quietly, the way a real BEC begins. A member of the finance team receives an email that appears to come from a senior executive, or from a long-standing vendor, referencing a legitimate transaction in progress. The QuickStart guide describes the aim as reacting to evolving information under pressure rather than reading a plan aloud, so the facilitator should reveal only what the recipient would see at that moment.

Prompt the group:

  • Who is expected to notice that this request is unusual, and what would make it look normal enough to proceed?
  • What internal process governs a change to payment instructions or an urgent transfer request?
  • Is there a documented plan that anyone would reach for at this point?

Phase two, the fraudulent-vendor inject

Introduce the pivot. The email chain now includes a message stating that the vendor has changed its banking details, with a new account number and a request to route an imminent invoice payment to it. The tone conveys urgency and a plausible reason for the change. This inject tests exactly what the GTIA social engineering scenario targets: financial controls and communication protocols around a fraudulent financial transfer.

Prompt the group:

  • What verification is required before payment instructions are changed, and does it rely on the same email channel the attacker controls?
  • Would anyone call the vendor back using a phone number from the new email, or from an independently known record?
  • Who has authority to override the standard control if the payment is described as time-sensitive?

The productive tension here is the collision between a control that requires out-of-band verification and the human instinct to accommodate an important vendor or executive. GTIA advises facilitators to gently challenge assumptions to stimulate deeper thought rather than jumping to solutions.

Phase three, the wire-transfer decision

Force the moment. The invoice is due, the executive appears to be traveling and unreachable by the usual channel, and the finance team must decide whether to release the funds. This is the decision the entire exercise is built around. Let the group work through it without rescue.

Prompt the group:

  • What is the exact approval path for releasing this transfer, and how many people must independently confirm it?
  • If verification cannot be completed, is the default to hold the payment or to release it?
  • Who declares that this may be an incident, and at what point does the conversation shift from a routine payment to a suspected fraud?

The QuickStart guide notes that more than seventy percent of first executive briefings in observed exercises contained material inaccuracies, and fewer than twenty percent of participants at the two-hour mark could identify the next regulatory notification deadline. A BEC drill should surface both weaknesses at this stage, when the team either verifies and holds or authorizes and loses.

Phase four, the recovery path

Do not end the exercise at the payment. The GTIA guidebook underscores the coordinated response required once a key executive account is compromised, and the Unit 42 assessment emphasizes recovering faster with a best-practice response playbook. Walk the team through what happens in the hours after fraud is suspected.

Prompt the group:

  • Who contacts the originating bank to attempt a recall or freeze, and how quickly can that call be made?
  • How is the email environment investigated for unauthorized access, mailbox rules, or data exfiltration, which Unit 42 identifies as common indicators of email compromise?
  • Which regulators, law enforcement contacts such as the FBI, insurers, and affected counterparties must be notified, and on what timeline?
  • Who owns external and internal communications so the first executive briefing is accurate rather than improvised?

Convert the exercise into change

The most common reason tabletops fail is that the exercise happens, a report gets filed, and nothing changes. The QuickStart guide identifies this pattern directly and points to the after-action review as the part that drives improvement, converting identified gaps into concrete, time-bound recommendations. Vague objectives compound the problem, so define measurable criteria in advance: time to declare an incident, time to notify legal, and time to approve or halt containment.

GTIA reinforces the discipline of documentation, instructing facilitators to close with a debrief that summarizes key takeaways and actionable improvements, then to produce a written report of findings and recommendations. Unit 42 similarly delivers a BEC tabletop through an after-action report aimed at policy and process improvement.

The improvements a BEC drill typically produces are specific and testable. They include an out-of-band verification requirement for any change to payment instructions, a mandatory second approver for transfers above a defined threshold, a clear rule that unverifiable urgent payments are held rather than released, and a documented escalation path that names who declares an incident and who calls the bank. The value of the exercise is proven only when those items appear on a schedule with owners and due dates.

Cadence and reinforcement

One drill does not build durable readiness. The QuickStart guide recommends at least one enterprise-wide cybersecurity tabletop each year, supplemented by focused drills after major incidents, architecture changes, or regulatory shifts. A finance-heavy scenario like BEC benefits from repetition, because the muscle memory it builds for escalation and verification is what reduces panic during a real event. As one practitioner quoted in the GTIA coverage of ChannelCon 2025 put it, everyone has a plan until they get punched in the face, and the more times a team rehearses the punch, the better it reacts. A business email compromise tabletop exercise, run against a realistic scenario and closed with a report that assigns accountability, is how an organization trades a costly first lesson for a rehearsed one.

Written by

Law & Forensics Editorial

Editorial team, Law & Forensics

The editorial team at Law & Forensics, the firm behind Tabletop.ai.

Get started

Make cyber readiness a board-visible program.

Pick a plan and run your first drill this week. One subscription covers your whole organization and every business unit under it.