Five ways to improve email security
Five practical email security measures, based on Canadian Centre for Cyber Security guidance, with a checklist for small and mid-sized organizations.
Email is still the most common way attacks begin, and invoice fraud through a spoofed or compromised mailbox can cost more than ransomware. We secure Microsoft 365 and Google Workspace email, protect your domain from being impersonated, and make it easy for staff to report what gets through.
Email security protects two things: your staff's inboxes, from phishing and malicious attachments, and your domain's reputation, so that criminals cannot easily send email pretending to be you. We work mainly with Microsoft 365 and Google Workspace, using their built-in protection and, where needed, an added email security gateway. The work can be a one-time hardening project or part of ongoing managed security.
Most organizations can reduce email risk a great deal with five steps:
Business email compromise happens when an attacker gets into a real mailbox, often through a stolen password, and watches conversations before sending a well-timed request to change payment details. Because the message comes from a genuine account, filtering alone may not catch it. We reduce the risk with MFA, sign-in monitoring, alerts on mailbox rules and a clear payment verification procedure.
If you suspect a compromise, contact your bank immediately about any payments in progress, and speak to your insurer. If personal information may have been exposed, PIPEDA and some provincial laws require organizations to assess whether the breach creates a real risk of significant harm and, if so, to report it. This is not legal advice.
Email often carries personal and confidential information. We help you set sensible rules for external sharing, encryption of sensitive messages and retention, in line with your privacy obligations. For a wider review, see privacy and compliance readiness.
Email security works alongside EDR, which catches malicious files that reach a device, and Microsoft 365 management for the rest of your workplace. See all our cybersecurity services.
The exact list is agreed in writing for each project. These are the usual deliverables and the usual boundaries.
Most delays in this kind of work come from access and decisions, not from the technical build. Knowing these early keeps the project predictable.
Each stage ends with something you can review before the next one starts.
Check mail flow, filtering, mailbox settings and domain records, and look for signs of past compromise.
Output: Findings and a prioritized list of changes.
Configure SPF and DKIM for every legitimate sender, then publish DMARC in monitoring mode.
Output: Domain records and DMARC reporting.
Enforce MFA, block legacy sign-in, tighten forwarding and sharing, and switch on alerts for risky changes.
Output: Hardened configuration and change log.
Move DMARC to quarantine or reject once reports are clean, and show staff how to report suspicious mail.
Output: Enforced DMARC policy and staff guidance.
For managed-service clients, ongoing review of alerts, DMARC reports and reported messages.
Output: Regular email security reports.
We do not publish package prices. Each estimate is based on an agreed scope, in Canadian dollars, with taxes shown separately. These are the things that move the number most:
They are DNS records that let receiving mail servers check whether a message really came from your domain. SPF lists approved sending servers, DKIM adds a cryptographic signature, and DMARC tells receivers what to do when a message fails and sends you reports. Together they make your domain much harder to spoof.
Not if it is done in stages. We start in monitoring mode, identify every service that sends as your domain, fix their authentication, and only then move to enforcement.
Both include solid protection, but several important settings are optional or depend on your licence. A review usually finds quick improvements, such as blocking legacy sign-in or alerting on external forwarding.
Technology helps, but the strongest control is a process. Any change to banking details should be verified by phone using a number you already have, never one from the email. We help you write and roll out that procedure.
For managed-service clients, email security alerts are part of 24/7 monitoring. Response targets are set in the service agreement.
Five practical email security measures, based on Canadian Centre for Cyber Security guidance, with a checklist for small and mid-sized organizations.
Training and phishing simulations that help staff recognize scams, report them quickly and handle information safely.
Set up, secure and manage Microsoft 365 so your people can work in familiar tools from any device, safely.
Tell us which email platform you use and what has happened so far. We will reply to arrange a conversation.