BEC is a finance problem before it's an IT problem.
average loss per BEC incident — paid out through normal finance processes, not a technical exploit.
is how long you have to recall a fraudulent wire. After that, recovery is the exception, not the rule.
audit logs record the takeover — login, forwarding rule, OAuth grant — but nobody is reading them at 3 a.m.
Two attacks. Two timelines.
Rules decide. AI verifies and explains.
Cross-checked signals drive the rule engine. AI writes the explanation and validates the evidence — a hallucination can't invent a threat, or hide one.
Night-shift logins and GeoIP quirks are learned from your tenant's actual behavior, not a generic exception list — so alerts mean something.
A trusted sender with decisive compromise evidence still triggers a verdict. Decisive evidence is never whitelisted away.
Built to survive a bank's scrutiny.
When money moves, the report has to hold up outside your company — with your bank, your insurer, and law enforcement. ICES collects the evidence itself, first-hand, and keeps it isolated per tenant.
Run it yourself, or let our analysts watch.
About two weeks. Nothing installed.
30-minute walkthrough, tenant scope, and success criteria agreed.
Google Workspace or M365 connected read-only — first detections within days.
Alert routing and escalation paths set up — including an SPF, DKIM, and DMARC review.
Baselines measured on your tenant's real behavior; verdicts reviewed together.
Scroll — ICES catching a fraud.
Google Workspace, Microsoft 365, NAVER WORKS — read-only API connections to the mail platform you already run. No agent, no MX change.
Deployment is an API consent screen — roughly two weeks to live, matching the ICES rollout stat.
A week of 123 login events collapses into the two that matter — a new country, an impossible hour, an unfamiliar network.
Baselines are per-account: a night-shift login that is normal for one user stays quiet for that user.
Received mail is scored and sorted — malicious, suspicious, safe — with the reasoning attached to every verdict.
Verdicts come from deterministic rules; AI adds the explanation, not the decision.
Nine failures from one address, then a success, then audit logging goes dark — the audit view catches the sequence, not just the events.
Single events look harmless; sequences don't. The audit trail is built to read sequences.
SPF, DKIM, DMARC and content scoring converge on each message — the wire-change request scores 82 and is escalated before anyone replies.
Median detection is measured in minutes — before the reply, not after the loss.