BEC protection for CPA firms
Business email compromise at an accounting firm usually doesn't start with a scary attachment. It starts with someone signing into a real staff mailbox and quietly setting it up to watch.
Once they're in, the attacker reads client threads, adds a rule that hides replies, maybe forwards a copy outside, and waits for a payment or a tax refund conversation. Then a change-of-bank-details email goes out from an address your clients already trust.
What matters most, in order
- MFA on every mailbox. Including the shared front-desk inbox and the partner who "never logs in from anywhere else."
- Call-back rule for money. Any change to wire, ACH or refund details gets confirmed by phone at a number you already have, never one from the email.
- Filtering on inbound mail. Microsoft 365 and Google Workspace both include it. Microsoft Defender for Office 365 Plan 1 adds Safe Links, Safe Attachments and impersonation protection. It's included in Microsoft 365 Business Premium and sold as an add-on at $2 per user per month on an annual commitment.
- Someone noticing a takeover after a login succeeds. This is the gap. Filters judge incoming messages. They don't tell you that a staff account just created a rule moving all mail from a client into an RSS folder.
How the options compare
| Option | What it does | Watches for takeover after login? | Price |
|---|---|---|---|
| Built-in Microsoft 365 or Google Workspace protection | Spam, malware and phishing filtering | Limited. Some alerts exist, but they often go to an admin mailbox nobody checks. | Included |
| Microsoft Defender for Office 365 Plan 1 | Safe Links, Safe Attachments, anti-phishing and impersonation protection | Not its focus | $2/user/mo add-on (annual), or included in Business Premium |
| API email security platforms (Abnormal, IRONSCALES, Avanan and others) | Behavioral analysis of inbound mail. Some include account-takeover detection. | Some do | Mostly quote-based |
| Managed SOC or MDR through an MSP | People watch and respond for you | Yes, if it's in scope | Varies by provider |
| InboxGuards | Read-only alarm on supported audit records: new-location sign-ins, forwarding, inbox rules, mailbox permissions, admin-role, OAuth and MFA changes | Yes. That is the whole product. | $2/user/mo or $20/user/yr |
InboxGuards doesn't replace filtering, and it doesn't respond for you. It's the alarm that tells the firm, or the firm's IT provider, that something changed in a mailbox that shouldn't have.
If you think it already happened
Dario Dulovic, who builds InboxGuards, wrote the cleanup steps for CPA Practice Advisor: How to Help a Client When Their Email Has Been Taken Over. We also keep a first-hour guide at inboxguards.com/business-email-hacked-what-to-do and a checklist for CPA firms.
About InboxGuards
- Price: $2 per active user per month, or $20 per user per year. No minimum, no setup fee.
- 30-day money-back guarantee. No free trial.
- Read-only access to supported Microsoft 365 and Google Workspace audit records. It does not read message content and cannot change tenant settings.
- It is an alarm. It is not a staffed SOC and not an email gateway.
- Owned and operated by Orion CMD LLC, Omaha, Nebraska. hello@inboxguards.com, 402-650-8407.