See where you standA professional review of your Microsoft 365 and Azure security posture. Gaps and fixes, no sales pressure.Book a security assessment
Email Security Assessment
Phishing that gets through is a configuration problem.
Defender for Office 365 can stop most of what lands in your users’ inboxes - if it is configured to. We assess and harden the platform you already pay for, enforce DMARC, and test the one layer no filter covers: your people.
Built on Defender for Office 365 you already ownDMARC enforced, not just monitoredPeople tested with real-world simulationsStandalone, or part of the full M365 assessment
This weekFinance team inboxesDefender for Office 365 · tuned
Stopped
Invoice update - "supplier" lookalike domain
Impersonation protection · policy we tuned
Stopped
Payroll change request - spoofed CEO
DMARC reject · enforcement we rolled out
Flagged
Unusual OAuth consent request to finance
Held for review · analyst notified
The gap
Vendor thread hijack - real account, real thread
No config stops this · this is why we test people
Config stops most of it · simulation trains for the rest
Why now
You are probably here because…
Email security gets budget the week after it almost went wrong. Better a week before.
The near miss
A payment-change email almost worked
Finance caught it at the last step. Nobody wants to rely on that twice.
Spoofing
Customers received email pretending to be you
Your domain is being used against the people who trust it.
Deliverability
Your own mail is landing in spam
Missing DMARC and DKIM hurt delivery long before they hurt security.
Insurance
The renewal asks about anti-phishing controls
And "we have Microsoft" is not an answer underwriters accept.
Volume
Users report more phishing than IT can review
Or worse: they report nothing at all.
The audit
NIS2 or ISO evidence needs email controls
Documented, tested, and mapped - not assumed.
~90%
of successful cyberattacks start with a phishing email. It remains the front door, decade after decade.
CISA · phishing guidance
$3.0B
reported lost to business email compromise in a single year - more than ransomware, by an order of magnitude.
FBI IC3 · Internet Crime Report 2025
Scope
Three layers, in the honest order
Configuration first - it is the cheapest fix with the biggest drop in what gets through. Domain enforcement second. Then, and only then, test the people.
Layer 1 · Platform
Defender for Office 365
Hardened, not default
The filtering you already license, configured the way Microsoft’s strictest baselines intend - because defaults are tuned for delivery, not defense.
Preset security policies vs your custom-policy sprawl
Impersonation protection for your VIPs and domains
Safe Links and Safe Attachments, verified end to end
Transport rules and allow-list exceptions that bypass everything
Mailbox forwarding rules - the classic quiet exfiltration
Assessed against · CIS · CISA SCuBALayer 2 · Domain
SPF, DKIM, and DMARC
Enforced, not just published
Most tenants have SPF and stop there. Full enforcement is what stops attackers from sending email as you - to your staff, your customers, and your suppliers.
Some attacks pass every technical control: a real account, a hijacked thread, a plausible ask. The only defense left is the human who pauses. We measure whether they do.
Realistic scenarios, not obvious "click here" bait
Click rate and report rate, benchmarked
Results by department, never by public shaming
Ongoing awareness programs for teams that want the habit, not the one-off
Packaging · optional add-on
The expensive one
Anatomy of the invoice that costs six figures
Business email compromise is not malware. It is a patient attacker, a real mailbox, and one changed bank account. Here is how it actually unfolds - and where each control gets a chance to break it.
Week 0
A supplier’s mailbox is compromised
Not yours - theirs. The attacker reads months of invoice threads and waits for a payment cycle.
No control fires here
Week 3
A reply arrives inside a real thread
Real account, real history, real invoice number. Nothing is spoofed; every technical check passes.
Impersonation and first-contact cues we configure in Defender
Week 3, +2h
"Our bank details have changed"
A PDF matching every previous invoice, except the account number.
Payment-fraud heuristics, tuned on - plus a user trained to treat bank changes as hostile
Week 3, +1d
Finance pays the new account
Without a trained pause, the money moves. Recovery odds drop by the day.
No control fires here
No single layer stops this. Config narrows it, DMARC removes the easy version, and a trained human breaks it. That is why the assessment covers all three.
Before you buy anything
You probably don’t need a third-party gateway.
The reflex after a phishing scare is to buy another filter. But most organisations running Microsoft 365 already own enterprise-grade email security - unconfigured. A properly hardened Defender for Office 365 closes most of the gap a gateway is sold to fill, at zero additional license cost.
Where a gateway genuinely makes sense
Complex multi-platform estates (Google + Microsoft) can justify one.
Some industries have archiving or continuity requirements a gateway bundles in.
If you already own one and it is tuned, we will say so and leave it alone.
You ownDefender for Office 365
Typical gateway€3-8 / user / month
Our adviceConfigure what you have first
Our incentiveWe sell the fix, not a license
The people layer · optional add-on
Find out before an attacker does
A vendor-thread hijack passes every filter, because technically nothing is wrong with it. The phishing simulation measures the layer that has to catch it: whether your people click, and, more important, whether they report.
Realistic lures based on what your users actually receive - not "you won a prize"
Click rate and report rate, benchmarked against first-run norms
Department-level results; no individual naming, no shaming
A retest after training, so you can show the number moving
Want the habit, not the snapshot? We run ongoing awareness programs that keep testing and training on a cadence.
What the add-on includes
Simulation, debrief, retest
One campaign, tailored to your organisation. A debrief with numbers your leadership will actually read. A retest after training to prove movement.
Scenario design and safe execution
Click + report rates, benchmarked, by department
Targeted follow-up training for the teams that need it
Retest to demonstrate improvement
The deliverable
One report, written for three readers
Same format as our full M365 assessment: board-ready, remediation-ready, and auditor-ready in one document.
Written for board / CFO · redacted sample
High
Overall risk
Your domain can currently be spoofed, and the most likely BEC path, a payment-change email to finance, would reach the inbox. Both close with configuration: DMARC enforcement and impersonation protection, using licensing you already own. Simulation recommended for the finance and leadership teams once controls land.
2
Attack paths
11
Findings
4
Quick wins
0
New licenses needed
Written for IT / engineering · redacted sample
Critical
DMARC absent on the primary sending domain
CheckedSPF, DKIM, DMARC posture across all sending domains
ExpectedDMARC at p=quarantine or stricter
FoundSPF only · 2 shadow senders discovered · xxxxxxxxx
FixDKIM on all senders, staged rollout to p=reject · records included
High
Impersonation protection not covering executives
CheckedDefender anti-phishing policies vs organisation VIP list
ExpectedUser and domain impersonation enabled for finance-relevant identities
FoundDefault policy only · zero protected users configured
FixProtected-user list + mailbox intelligence, portal steps included
High
Transport rule bypasses filtering for a "trusted" partner
CheckedTransport rules and connection-filter allow lists
ExpectedNo unconditional SCL-bypass rules
FoundOne rule whitelists an entire domain · xxxxxxx
FixScoped exception with spoof checks intact, rule rewrite included
Written for auditor / insurer · redacted sample
DMARC not enforcedCIS 2.1.9SCuBA MS.EXO.4.1NIS2 Art. 21(2)(g)Cyber Essentials · Malware
Includes a 1:1 readout call.We walk the findings with you, agree the DMARC rollout plan, and decide whether the simulation makes sense as a next step.
Method & safety
Safe enough to run on a Tuesday morning
Same ground rules as every Falconer assessment - plus two that are specific to email.
Read-only assessment
No settings changed during the assessment. No agents, no user impact, no downtime.
Access you control
Scoped, delegated read access via GDAP - granted by you, revocable by you.
Enforcement is staged
When you approve fixes, DMARC moves monitor → quarantine → reject with your senders mapped first. Nothing breaks on day one.
Simulations run safely
Campaigns are scheduled with your IT, exclude critical windows, and collect no credentials - landing pages train, they never harvest.
Days, not weeks
Collection is hours, analysis is days. Findings arrive while they are still true.
Your data stays yours
Evidence handled under GDPR, stored in the EU, deleted on the schedule we agree.
Email is one surface of four.
This assessment runs standalone - fixed fee, sized by tenant - or as the email module of the full Microsoft 365 Security Assessment, which adds identity, collaboration, and posture in the same three-reader report.
We already pay for Microsoft 365. Why does phishing still get through?
Because Defender for Office 365 ships tuned for delivery, not defense. Impersonation protection, Safe Links policies, and strict presets exist in your license - most tenants simply never turn them on, or quietly bypass them with transport rules. Configuration is the product here.
Will enforcing DMARC break our outgoing email?
Not the way we do it. We map every legitimate sender first - CRM, marketing platform, invoicing tools - then stage the rollout: monitor, quarantine, reject. Each step runs long enough to catch stragglers before tightening.
Is the phishing simulation included?
It is an optional add-on. The configuration and domain assessment is the base engagement; the simulation is priced separately, and honestly it lands best a few weeks after the technical fixes, so the test measures people rather than missing filters.
Will employees be named and shamed?
Never. Results are reported by department, not by individual. The metric we care most about is the report rate - the habit of forwarding something suspicious - because that is what ends real incidents early.
Do you collect passwords during simulations?
No. Landing pages train on the spot; they never harvest credentials. Campaigns are coordinated with your IT, scheduled around critical periods, and safe by design.
Can this stop BEC - the fake invoice / changed bank details attack?
No single control can, and we will not pretend otherwise. Configuration narrows it, DMARC removes the spoofed version, and a trained human breaks the rest. The report also recommends process controls for finance, like out-of-band verification of bank changes - simple, and worth more than any filter.
Do we need a third-party email gateway?
Probably not. A hardened Defender for Office 365 covers what most gateways are sold to cover, at zero extra license cost. There are honest exceptions - multi-platform estates, archiving requirements - and if you are one, we will say so.
How is this different from the full M365 assessment?
Same method, same report format, one surface instead of four. If email is the acute pain, start here. If you want identity, collaboration, and posture assessed at the same time, the full assessment includes this as its email module.
How long does it take, and what does it cost?
Days, not weeks - collection is hours, analysis takes a few days. It is a fixed-fee engagement sized by tenant and sender complexity, quoted before we start. The simulation add-on is quoted alongside if you want it.
What happens after the report?
Three honest paths: fix it yourselves with the included steps, have us implement the hardening and DMARC rollout, or fold email into ongoing management. The report stands alone whichever you choose.
A Microsoft security specialist reads every message and replies, usually within one business day. Whether you need monitoring, help with a specific tool, or just have a question, start here.
New to this? Ask about a free Microsoft security review as a starting point.
What we can help with
Managed detection and response
Microsoft Sentinel engineering
Identity and email security
A free Microsoft security review
1You send a message
2A specialist replies within a business day
3We set up a call to scope what you need
"*" indicates required fields
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional
Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes.The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional
Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes.The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.