Resilience includes mapping dependencies, stress-testing supply chains, documenting critical processes, and scrutinising third-party relationships. Yet one dependency underpins almost every operational process that an organization runs and it almost never appears on a resilience map: the trust embedded in everyday business communications.
From casual emails between colleagues to supplier invoices, our workdays are defined by trusted connections. They are the operational fabric of every organization, and they are also increasingly the point at which resilience starts to break down.
When that trust is compromised by cybercriminals, it can come with a high cost. The FBI Internet Crime Complaint Center estimates the average cost of a business email compromise (BEC) incident is $123,000. But the consequences can extend far beyond that, damaging critical relationships and undermining the foundations the business is built on.
Understanding why such attacks succeed requires looking at how they are constructed. Threat groups have become increasingly effective at conducting their own malicious form of analysis before they strike.
Abnormal AI’s ‘2026 Attack Landscape Report‘, drawing on 159 million email attacks from the second half of 2025, found that accuracy rather than volume is now a defining factor.
Over one-third (39%) of all the BEC emails analysed for the report impersonated trusted internal contacts; including executives, business departments, and other colleagues. External contacts, such as vendors or partners, accounted for another 61%; with attackers deftly hijacking normal processes like payments and procurement.
These attackers research their targets, identify which vendor relationships carry implicit trust, study internal communication norms, and map the approval hierarchies that govern financial decisions. The attack is then engineered to fit seamlessly into that operational context.
Mirroring the legitimate business world, AI-powered tools have made this formerly resource-heavy task highly automated and accessible for even smaller threat groups.
It has become especially challenging when managing third-party risk. Abnormal AI’s research shows a growing trend of exploiting the early stages of the procurement process. Initial procurement enquiries are unlikely to raise any flags, setting up the imposters to steal payment further down the line. This trend is especially prevalent in EMEA, accounting for 41% of the vendor attacks in the region.
The limits of current resilience frameworks
Operational resilience frameworks accounting for third-party risk have matured considerably in recent years. Under DORA, financial entities must map their important business services and demonstrate continuity under stress.
However, most frameworks tend to focus on mapping technology dependencies and process vulnerabilities, but not on the communication layer, the trust assumptions, and the relationship patterns that run through every dependency they document.
This gap has always existed, but it has become increasingly critical as attackers have become faster and more adept at exploiting it. AI-powered impersonation now enables attackers to replicate not just a sender’s identity but their communication style and contextual detail. The informal human security layer of looking out for bad spelling or unusual tone is nowhere near enough anymore.
This is reflected by internal security strategies. Zero trust network architecture, which applies the principle of ‘assume nothing, verify everything’ to user movement and access requests, aims to restore trust on a systemic level.
But zero trust stops at the system boundary. It does not extend to the relational layer, those vendor relationships built over the years, and the internal approval that follows a familiar pattern.
Identity has become the new security perimeter – but managing identity at the infrastructure level is not the same as managing trust at the human level.
Building resilience into the human layer
Closing this gap is less a technical overhaul than an extension of existing resilience practice – applying dependency mapping, continuous monitoring, and adaptive response to the communication layer.
Getting to grips with this first requires organizations to establish behavioural baselines of what normal looks like. This needs to cover all internal employee relationships and extend outwards to vendors, partners, and any other third parties.
From here, it is possible to conduct reliable contextual examinations, assessing whether a request is consistent with the established pattern of that relationship, rather than just whether the sender appears legitimate. For example, you might have a vendor abruptly request changes to payment routing outside their usual cycle, with the email arriving at an odd time outside working hours. Anomalies like this need extra scrutiny, no matter how the email’s identity and contents read.
Finally, this needs to happen consistently at both speed and scale, and AI-native detection is the best way to achieve this. No team can manually assess the contextual signals embedded in thousands of messages every day. AI systems that analyse patterns, flag anomalies, and model intent across an organization’s full communication environment are essential for such a pervasive and fast-moving threat.
Protecting the dependency that holds everything else together
Resilience includes protecting what the business depends on. For most organizations, that still does not include the communication layer: the trusted connections that underpin every supplier relationship, approval process, and financial decision made each day.
Successful attacks begin with a message that nobody questioned. It is a weakness that belongs on the map alongside all the other dependencies that organizations have worked to protect. Resilience frameworks must evolve to accommodate and close this gap before attackers make the cost of inaction impossible to ignore.
The author
Mick Leach is Field CISO, Abnormal AI






