Cybersecurity

Email security

Email is still the most common way attacks begin, and invoice fraud through a spoofed or compromised mailbox can cost more than ransomware. We secure Microsoft 365 and Google Workspace email, protect your domain from being impersonated, and make it easy for staff to report what gets through.

Who this service is for

A good fit if

  • Staff receive convincing phishing, or suppliers have been tricked by emails that looked like yours.
  • You have had a mailbox compromised, or a payment redirected by a fake banking change.
  • Your domain has no DMARC record, or it has one that nobody monitors.
  • Legitimate emails from your organization land in spam, or your newsletter provider asks for domain authentication.
  • You use Microsoft 365 or Google Workspace but have never reviewed the security settings.

Another approach may suit you better if

  • You run your own mail server and do not want to change anything about it. We can advise, but the options are narrower.
  • You only need a marketing email platform set up. That is a smaller, separate piece of work.

What this service is

Email security protects two things: your staff's inboxes, from phishing and malicious attachments, and your domain's reputation, so that criminals cannot easily send email pretending to be you. We work mainly with Microsoft 365 and Google Workspace, using their built-in protection and, where needed, an added email security gateway. The work can be a one-time hardening project or part of ongoing managed security.

Five practical steps to solve the email security problem

Most organizations can reduce email risk a great deal with five steps:

  1. Authenticate your domain. Configure SPF, DKIM and DMARC so receiving servers can reject messages that pretend to come from you. Major mailbox providers now expect authentication from organizations that send in volume, so this also helps your legitimate mail get delivered.
  2. Filter before it arrives. Use link and attachment scanning, and flag messages from outside the organization or from lookalike domains.
  3. Protect every mailbox. Enforce MFA, block older sign-in methods that bypass it, and alert on suspicious forwarding rules and sign-ins.
  4. Verify payment changes out of band. Require a phone call to a known number before any banking detail changes. This single process stops most invoice fraud.
  5. Train staff and make reporting easy. Give staff a report button and regular, short awareness training, and thank people who report.

Business email compromise

Business email compromise happens when an attacker gets into a real mailbox, often through a stolen password, and watches conversations before sending a well-timed request to change payment details. Because the message comes from a genuine account, filtering alone may not catch it. We reduce the risk with MFA, sign-in monitoring, alerts on mailbox rules and a clear payment verification procedure.

If you suspect a compromise, contact your bank immediately about any payments in progress, and speak to your insurer. If personal information may have been exposed, PIPEDA and some provincial laws require organizations to assess whether the breach creates a real risk of significant harm and, if so, to report it. This is not legal advice.

Signs your email security needs attention

  • Suppliers or clients mention receiving odd emails that appear to come from you.
  • Staff regularly report convincing phishing, or you only hear about it after someone clicked.
  • Your invoices or newsletters land in recipients' spam folders.
  • Mailboxes have rules that forward mail to outside addresses, and nobody knows why.
  • Some staff still sign in to email without MFA, or through older apps that bypass it.
  • Nobody reads DMARC reports, or you do not know whether you have a DMARC record.

Email and privacy

Email often carries personal and confidential information. We help you set sensible rules for external sharing, encryption of sensitive messages and retention, in line with your privacy obligations. For a wider review, see privacy and compliance readiness.

Part of your wider security

Email security works alongside EDR, which catches malicious files that reach a device, and Microsoft 365 management for the rest of your workplace. See all our cybersecurity services.

What is included

The exact list is agreed in writing for each project. These are the usual deliverables and the usual boundaries.

Typical deliverables

  • A review of your email platform, filtering, domain records and mailbox security settings.
  • Domain authentication: SPF, DKIM and DMARC configured for every service that sends as your domain.
  • DMARC reporting set up and monitored, moving from monitoring to enforcement in stages.
  • Filtering and sandboxing for malicious links and attachments, using built-in protection or an added gateway.
  • Impersonation and lookalike-domain protection for executives and key suppliers.
  • MFA and sign-in protection for every mailbox, with legacy authentication blocked.
  • Alerts for risky mailbox rules, forwarding to outside addresses and unusual sign-ins.
  • A report-phishing button or address, with reports reviewed.
  • A written procedure for verifying payment and banking changes.

Not included unless agreed separately

  • Email platform and filtering licences, billed separately or bought directly by you.
  • Migrating mailboxes between platforms, unless scoped separately.
  • Recovering funds lost to fraud, which is a matter for your bank, insurer and police.
  • Legal advice on email retention or e-discovery obligations.

What we will need from you

Most delays in this kind of work come from access and decisions, not from the technical build. Knowing these early keeps the project predictable.

  • Administrator access to your email platform and your domain's DNS.
  • A list of every service that sends email as your domain, such as newsletters, invoicing or CRM tools.
  • A named contact who can approve changes to mail flow.
  • Time for staff to set up MFA where it is not already in place.
Delivery

How the work is delivered

Each stage ends with something you can review before the next one starts.

  1. Review

    Check mail flow, filtering, mailbox settings and domain records, and look for signs of past compromise.

    Output: Findings and a prioritized list of changes.

  2. Authenticate the domain

    Configure SPF and DKIM for every legitimate sender, then publish DMARC in monitoring mode.

    Output: Domain records and DMARC reporting.

  3. Harden mailboxes

    Enforce MFA, block legacy sign-in, tighten forwarding and sharing, and switch on alerts for risky changes.

    Output: Hardened configuration and change log.

  4. Enforce and train

    Move DMARC to quarantine or reject once reports are clean, and show staff how to report suspicious mail.

    Output: Enforced DMARC policy and staff guidance.

  5. Monitor

    For managed-service clients, ongoing review of alerts, DMARC reports and reported messages.

    Output: Regular email security reports.

Testing and handover

  • Every legitimate sending service is identified and authenticated before DMARC is enforced, so real mail is not blocked.
  • Test messages confirm filtering, authentication and reporting all work.
  • Mailbox forwarding to outside addresses is reviewed and documented.
  • Staff know how to report suspicious mail and receive an acknowledgement.
  • Every configuration change is recorded with the reason for it.

What affects the cost

We do not publish package prices. Each estimate is based on an agreed scope, in Canadian dollars, with taxes shown separately. These are the things that move the number most:

  • The number of mailboxes and domains.
  • The number of third-party services that send email as your domain.
  • Whether built-in protection is enough or an added email security gateway is needed.
  • Evidence of past compromise that needs investigation.
  • Ongoing monitoring versus a one-time project.

Questions buyers usually ask

What are SPF, DKIM and DMARC?

They are DNS records that let receiving mail servers check whether a message really came from your domain. SPF lists approved sending servers, DKIM adds a cryptographic signature, and DMARC tells receivers what to do when a message fails and sends you reports. Together they make your domain much harder to spoof.

Will enforcing DMARC break our email?

Not if it is done in stages. We start in monitoring mode, identify every service that sends as your domain, fix their authentication, and only then move to enforcement.

Is Microsoft 365 or Google Workspace secure by default?

Both include solid protection, but several important settings are optional or depend on your licence. A review usually finds quick improvements, such as blocking legacy sign-in or alerting on external forwarding.

How do we stop invoice fraud?

Technology helps, but the strongest control is a process. Any change to banking details should be verified by phone using a number you already have, never one from the email. We help you write and roll out that procedure.

Do you monitor email security around the clock?

For managed-service clients, email security alerts are part of 24/7 monitoring. Response targets are set in the service agreement.

Worried about phishing or invoice fraud?

Tell us which email platform you use and what has happened so far. We will reply to arrange a conversation.