Email Security Assessment

Phishing that gets through is a configuration problem.

Defender for Office 365 can stop most of what lands in your users’ inboxes - if it is configured to. We assess and harden the platform you already pay for, enforce DMARC, and test the one layer no filter covers: your people.

Built on Defender for Office 365 you already own DMARC enforced, not just monitored People tested with real-world simulations Standalone, or part of the full M365 assessment
This weekFinance team inboxes Defender for Office 365 · tuned
Stopped
Invoice update - "supplier" lookalike domain
Impersonation protection · policy we tuned
Stopped
Payroll change request - spoofed CEO
DMARC reject · enforcement we rolled out
Flagged
Unusual OAuth consent request to finance
Held for review · analyst notified
The gap
Vendor thread hijack - real account, real thread
No config stops this · this is why we test people
Config stops most of it · simulation trains for the rest
Why now

You are probably here because…

Email security gets budget the week after it almost went wrong. Better a week before.

The near miss
A payment-change email almost worked

Finance caught it at the last step. Nobody wants to rely on that twice.

Spoofing
Customers received email pretending to be you

Your domain is being used against the people who trust it.

Deliverability
Your own mail is landing in spam

Missing DMARC and DKIM hurt delivery long before they hurt security.

Insurance
The renewal asks about anti-phishing controls

And "we have Microsoft" is not an answer underwriters accept.

Volume
Users report more phishing than IT can review

Or worse: they report nothing at all.

The audit
NIS2 or ISO evidence needs email controls

Documented, tested, and mapped - not assumed.

~90%

of successful cyberattacks start with a phishing email. It remains the front door, decade after decade.

CISA · phishing guidance
$3.0B

reported lost to business email compromise in a single year - more than ransomware, by an order of magnitude.

FBI IC3 · Internet Crime Report 2025
Scope

Three layers, in the honest order

Configuration first - it is the cheapest fix with the biggest drop in what gets through. Domain enforcement second. Then, and only then, test the people.

Layer 1 · Platform

Defender for Office 365

Hardened, not default

The filtering you already license, configured the way Microsoft’s strictest baselines intend - because defaults are tuned for delivery, not defense.

  • Preset security policies vs your custom-policy sprawl
  • Impersonation protection for your VIPs and domains
  • Safe Links and Safe Attachments, verified end to end
  • Transport rules and allow-list exceptions that bypass everything
  • Mailbox forwarding rules - the classic quiet exfiltration
Assessed against · CIS · CISA SCuBA
Layer 2 · Domain

SPF, DKIM, and DMARC

Enforced, not just published

Most tenants have SPF and stop there. Full enforcement is what stops attackers from sending email as you - to your staff, your customers, and your suppliers.

  • DKIM signing on every sending domain
  • Staged DMARC rollout: monitor → quarantine → reject
  • Third-party senders (CRM, marketing, invoicing) mapped first, so enforcement breaks nothing
  • Reporting wired up so drift gets caught
Bonus · better deliverability
Layer 3 · People

Phishing simulation

Tested, not assumed

Some attacks pass every technical control: a real account, a hijacked thread, a plausible ask. The only defense left is the human who pauses. We measure whether they do.

  • Realistic scenarios, not obvious "click here" bait
  • Click rate and report rate, benchmarked
  • Results by department, never by public shaming
  • Ongoing awareness programs for teams that want the habit, not the one-off
Packaging · optional add-on
The expensive one

Anatomy of the invoice that costs six figures

Business email compromise is not malware. It is a patient attacker, a real mailbox, and one changed bank account. Here is how it actually unfolds - and where each control gets a chance to break it.

Week 0
A supplier’s mailbox is compromised
Not yours - theirs. The attacker reads months of invoice threads and waits for a payment cycle.
No control fires here
Week 3
A reply arrives inside a real thread
Real account, real history, real invoice number. Nothing is spoofed; every technical check passes.
Impersonation and first-contact cues we configure in Defender
Week 3, +2h
"Our bank details have changed"
A PDF matching every previous invoice, except the account number.
Payment-fraud heuristics, tuned on - plus a user trained to treat bank changes as hostile
Week 3, +1d
Finance pays the new account
Without a trained pause, the money moves. Recovery odds drop by the day.
No control fires here

No single layer stops this. Config narrows it, DMARC removes the easy version, and a trained human breaks it. That is why the assessment covers all three.

Before you buy anything

You probably don’t need a third-party gateway.

The reflex after a phishing scare is to buy another filter. But most organisations running Microsoft 365 already own enterprise-grade email security - unconfigured. A properly hardened Defender for Office 365 closes most of the gap a gateway is sold to fill, at zero additional license cost.

Where a gateway genuinely makes sense
  • Complex multi-platform estates (Google + Microsoft) can justify one.
  • Some industries have archiving or continuity requirements a gateway bundles in.
  • If you already own one and it is tuned, we will say so and leave it alone.
You ownDefender for Office 365
Typical gateway€3-8 / user / month
Our adviceConfigure what you have first
Our incentiveWe sell the fix, not a license
The people layer · optional add-on

Find out before an attacker does

A vendor-thread hijack passes every filter, because technically nothing is wrong with it. The phishing simulation measures the layer that has to catch it: whether your people click, and, more important, whether they report.

  • Realistic lures based on what your users actually receive - not "you won a prize"
  • Click rate and report rate, benchmarked against first-run norms
  • Department-level results; no individual naming, no shaming
  • A retest after training, so you can show the number moving

Want the habit, not the snapshot? We run ongoing awareness programs that keep testing and training on a cadence.

What the add-on includes

Simulation, debrief, retest

One campaign, tailored to your organisation. A debrief with numbers your leadership will actually read. A retest after training to prove movement.

  • Scenario design and safe execution
  • Click + report rates, benchmarked, by department
  • Targeted follow-up training for the teams that need it
  • Retest to demonstrate improvement
The deliverable

One report, written for three readers

Same format as our full M365 assessment: board-ready, remediation-ready, and auditor-ready in one document.

Written for board / CFO · redacted sample
High
Overall risk

Your domain can currently be spoofed, and the most likely BEC path, a payment-change email to finance, would reach the inbox. Both close with configuration: DMARC enforcement and impersonation protection, using licensing you already own. Simulation recommended for the finance and leadership teams once controls land.

2
Attack paths
11
Findings
4
Quick wins
0
New licenses needed
Includes a 1:1 readout call. We walk the findings with you, agree the DMARC rollout plan, and decide whether the simulation makes sense as a next step.
Method & safety

Safe enough to run on a Tuesday morning

Same ground rules as every Falconer assessment - plus two that are specific to email.

Read-only assessment

No settings changed during the assessment. No agents, no user impact, no downtime.

Access you control

Scoped, delegated read access via GDAP - granted by you, revocable by you.

Enforcement is staged

When you approve fixes, DMARC moves monitor → quarantine → reject with your senders mapped first. Nothing breaks on day one.

Simulations run safely

Campaigns are scheduled with your IT, exclude critical windows, and collect no credentials - landing pages train, they never harvest.

Days, not weeks

Collection is hours, analysis is days. Findings arrive while they are still true.

Your data stays yours

Evidence handled under GDPR, stored in the EU, deleted on the schedule we agree.

Email is one surface of four.

This assessment runs standalone - fixed fee, sized by tenant - or as the email module of the full Microsoft 365 Security Assessment, which adds identity, collaboration, and posture in the same three-reader report.

Compare the full assessment
FAQ

The questions email-security buyers ask

We already pay for Microsoft 365. Why does phishing still get through?

Because Defender for Office 365 ships tuned for delivery, not defense. Impersonation protection, Safe Links policies, and strict presets exist in your license - most tenants simply never turn them on, or quietly bypass them with transport rules. Configuration is the product here.

Will enforcing DMARC break our outgoing email?

Not the way we do it. We map every legitimate sender first - CRM, marketing platform, invoicing tools - then stage the rollout: monitor, quarantine, reject. Each step runs long enough to catch stragglers before tightening.

Is the phishing simulation included?

It is an optional add-on. The configuration and domain assessment is the base engagement; the simulation is priced separately, and honestly it lands best a few weeks after the technical fixes, so the test measures people rather than missing filters.

Will employees be named and shamed?

Never. Results are reported by department, not by individual. The metric we care most about is the report rate - the habit of forwarding something suspicious - because that is what ends real incidents early.

Do you collect passwords during simulations?

No. Landing pages train on the spot; they never harvest credentials. Campaigns are coordinated with your IT, scheduled around critical periods, and safe by design.

Can this stop BEC - the fake invoice / changed bank details attack?

No single control can, and we will not pretend otherwise. Configuration narrows it, DMARC removes the spoofed version, and a trained human breaks the rest. The report also recommends process controls for finance, like out-of-band verification of bank changes - simple, and worth more than any filter.

Do we need a third-party email gateway?

Probably not. A hardened Defender for Office 365 covers what most gateways are sold to cover, at zero extra license cost. There are honest exceptions - multi-platform estates, archiving requirements - and if you are one, we will say so.

How is this different from the full M365 assessment?

Same method, same report format, one surface instead of four. If email is the acute pain, start here. If you want identity, collaboration, and posture assessed at the same time, the full assessment includes this as its email module.

How long does it take, and what does it cost?

Days, not weeks - collection is hours, analysis takes a few days. It is a fixed-fee engagement sized by tenant and sender complexity, quoted before we start. The simulation add-on is quoted alongside if you want it.

What happens after the report?

Three honest paths: fix it yourselves with the included steps, have us implement the hardening and DMARC rollout, or fold email into ongoing management. The report stands alone whichever you choose.

Contact

Tell us what you’re dealing with

A Microsoft security specialist reads every message and replies, usually within one business day. Whether you need monitoring, help with a specific tool, or just have a question, start here.

New to this? Ask about a free Microsoft security review as a starting point.

What we can help with
  • Managed detection and response
  • Microsoft Sentinel engineering
  • Identity and email security
  • A free Microsoft security review
1You send a message
2A specialist replies within a business day
3We set up a call to scope what you need

"*" indicates required fields

This field is for validation purposes and should be left unchanged.