Cybersecurity · Email
Email Security and Phishing Defence
Email is still where most losses start, and the expensive incidents rarely involve an attachment. They involve a convincing message about a payment, a mailbox quietly read for weeks, and a change of banking details that everyone believed was legitimate.
Email security is a layered problem: filtering what arrives, proving your own domain cannot be impersonated easily, watching mailboxes for signs of takeover, and giving staff a fast way to report something that feels wrong.
The problem
How business email fraud actually plays out
A supplier's mailbox is compromised somewhere up the chain. The attacker reads months of legitimate correspondence, waits for a real invoice, then replies in the same thread with updated banking details and a plausible reason. Nothing about the message is technically suspicious — the thread is genuine, the tone is right, and the sender is who they claim to be.
The internal variant is similar: a mailbox is accessed, a hidden inbox rule sends anything containing 'invoice' or 'wire' to an obscure folder, and the account is used to ask a colleague for a favour. Because the mail originates from inside the tenant, most filtering never sees it.
Neither case is solved by a spam filter alone. What limits the damage is a mixture of technical detection, domain authentication that makes impersonation harder, and a verification habit for any change to payment details.
What we do
Griffin IT Group's approach
- 01
Tune the filtering you already own
Microsoft Defender for Office 365 and Exchange Online Protection are capable when configured. We set anti-phishing, impersonation protection for executives and finance staff, safe-link handling and quarantine policies to sensible values, then review what they catch.
- 02
Authenticate your domain
SPF, DKIM and DMARC published and aligned, including the marketing and application senders people forget. DMARC reporting is monitored so a move to enforcement does not silently break legitimate mail.
- 03
Detect mailbox takeover
Alerting on new inbox rules, external forwarding, unusual sign-in locations and mass mail sending, with a defined response: sessions revoked, credentials reset, rules removed, and an audit of what was accessed.
- 04
Mark and explain external mail
Clear external sender indicators and targeted guidance for finance and reception — the roles that receive the most manipulation attempts.
- 05
Build the verification habit
A short written rule for banking or payment changes: confirmed by telephone to a previously known number, never to a number supplied in the email, and never approved by email alone.
- 06
Make reporting one click
A report button that routes suspicious mail to us for analysis, with feedback to the person who reported it. Staff who get an answer keep reporting.
Security considerations
Filtering is not the same as recovery
If a mailbox is compromised, the questions that follow are evidential: what was read, what was sent, what rules existed and when. Those answers require audit logging that was already enabled and retained before the incident, which is why we review logging alongside filtering.
Mail data also needs its own protection. Retention policies and a separate Microsoft 365 backup cover the cases filtering cannot — a deleted mailbox, a malicious purge, or a legal request for correspondence from two years ago.
- Unified audit logging enabled
- Sign-in and mail activity retention
- Microsoft 365 backup for mail
- Retention and litigation hold
- Documented takeover response
- Shared mailbox ownership
Where this fits
This work is delivered as part of the wider security programme described on cybersecurity services for St. Catharines organizations.
Questions
Frequently asked questions
- We already have Microsoft 365 filtering. Is that enough?
- It is a strong base, but the default configuration is deliberately permissive and impersonation protection has to be told who your executives and finance staff are. Most of the value comes from tuning, alerting on mailbox rules, and getting domain authentication right.
- What is DMARC, in plain terms?
- It is a public instruction telling receiving mail systems what to do with mail that claims to come from your domain but fails authentication. Set to enforcement, it makes casual spoofing of your domain far harder — which protects your clients as much as your staff.
- A staff member clicked a link and entered their password. What now?
- Treat it as a compromise: revoke active sessions, reset the password, re-register multi-factor authentication, check for inbox rules and forwarding, and review the sign-in and mail audit logs. If banking correspondence was in that mailbox, notify affected contacts.
Keep reading
Related cybersecurity services
- Identity & Access ManagementMFA, Conditional Access, privileged accounts and joiner-mover-leaver control.
- Ransomware ProtectionBlocking the intrusion path and keeping a recovery option that survives it.
- Endpoint Detection & ResponseBehavioural detection and isolation on laptops, desktops and servers.
- Managed Detection & ResponseAnalysts watching the alerts overnight so a detection becomes an action.
- Vulnerability ManagementContinuous discovery, risk ranking and verified remediation.
- Security AssessmentsA measured picture of current controls, gaps and priorities.
Next step
Talk to Griffin IT Group about your St. Catharines IT environment
Tell us how your technology is set up today and what is getting in the way. We will walk through your environment, outline the gaps we see and recommend a practical path forward.
