Cybersecurity
Email Security
Almost every incident we are called to started with an email that somebody had a good reason to open.
We filter inbound mail for the attachments and links that carry the actual payload, and for the convincing impersonation attempts that get past people rather than past software.
We also set up the authentication records that make your domain harder to forge. Without SPF, DKIM, and DMARC configured properly, anybody can send mail that appears to come from your company, and your customers are the ones who suffer for it.
The part that is not software matters as much: what your staff are trained to notice, and what your process is when an invoice arrives with changed bank details.
What this covers
- Inbound filtering for malicious attachments, links, and impersonation.
- SPF, DKIM, and DMARC configured and monitored on your domain.
- Protection against internal account takeover and the mail sent from it.
- Quarantine your staff can review without raising a ticket.
- A written process for the payment redirection attempts that target finance teams.
Common questions
We use Microsoft 365. Is that not enough?
It provides a real baseline, and how well it is configured varies enormously between tenants. We start by looking at what yours is actually set to, which in most inherited tenants is less than the license implies.
What is DMARC and do we need it?
It tells the world which servers are allowed to send mail as your domain, and what to do with mail that is not. Without it, forging your address is trivial. It is one of the cheapest protections available and one of the most commonly missing.
Part of Cybersecurity Services
Layered protection that is watched around the clock, so a bad day stays a bad hour.