Free guide for UK business owners

Free Email Hijack Guide for UK Businesses

How hackers break into business email, and steal money.

A short, readable guide by Yann Davies of ABCOM IT Solutions. It follows one business owner through an invoice fraud, then gives you a checklist of 10 layers of email security to put in place before it happens to you.

No sign-up. No spam. No pressure. Just a practical guide written for UK business owners.

Cover of the Email Hijack guide by Yann Davies of ABCOM IT Solutions: how hackers break into your email to plunder your business bank account.

Why email is the first thing attackers go for

If a hacker takes control of your email, they can usually get into other systems too, because most “forgotten password” links are sent to your inbox. A single hidden forwarding rule is enough for them to watch your invoices, wait for the right moment and redirect a payment. Cloud email is not secure by default, and even the best filters cannot catch everything.

90%+of successful attacks involve human error
40%of UK businesses enforce MFA everywhere
60%+of people reuse passwords across work and personal accounts (NCSC)

Figures as quoted in the guide.

What is inside the guide

A story you will recognise

A business owner finds £12,000 gone from his account. The story is fictional, but it is based on real incidents, and it shows the cash flow, staff and supplier fallout.

Seven common email scams

Hidden forwarders, look-alike domains, well-timed follow-up emails, compromised suppliers, edited PDF invoices, keyloggers and “the boss is on holiday” tricks.

10 layers of email security

A practical checklist to pick and choose from, so you are protected without tying your team’s hands.

Rules that stick

Why payment processes must apply to everyone, including the boss, and how to make them part of the culture.

The 10 layers of email security

Most businesses do not need every layer, and using all of them would slow everyone down. The guide explains each one in plain English so you can choose the right blend with expert help.

  1. Multi-factor authenticationConfirm every login on a second device. The simplest and most effective control.
  2. Forwarder monitoringGet alerted if a hidden email forwarding rule is ever set up.
  3. Proper email backupSo a compromised account can be rebuilt without losing a single email.
  4. AI email screeningSpots sudden changes in how a familiar contact writes.
  5. Endpoint securityLock down the computers your team uses to read email.
  6. Microsoft 365 advanced threat protectionStrong protection, if it is set up correctly for your business.
  7. Awareness trainingShort online courses that make people pause before they click.
  8. Cyber EssentialsBuilds the right habits, and more customers now ask for it.
  9. Payment processesApproval steps followed every time, especially when the boss is in a hurry.
  10. Cyber insuranceAnd follow the standards insurers set for best practice.

Not sure which layers your business needs?

Book a free cyber security consultation and we will look at your email setup with you. No pressure, just straight advice.

About the author

Yann Davies is Managing Director of ABCOM IT Solutions, a UK-based IT and cyber security provider supporting businesses and charities since 1996.

This guide is based on real-world incidents and patterns seen across UK organisations.

Scroll to Top
Free 3-minute quiz · No sign-up for your score

Is your team using AI you don’t know about?

Score your Shadow AI risk across policy, data, tools, people and detection, then get the three controls to fix first.

Take the Shadow AI Check10 questions · about 3 minutes