Why business email security matters
Email is used for identity, customer communication, invoices and access to other services. An attacker does not need to break every system if a convincing message can persuade one person to disclose a password, approve a payment or open a harmful file. Technical filtering helps, but it cannot replace sensible verification and a clear reporting route.
Common email-based attacks
Phishing and credential theft
Phishing messages imitate a trusted person or service and try to make the recipient click a link, open an attachment or share information. Check the sender address, destination of links and urgency of the request. Go to a service through a known bookmark rather than signing in from an unexpected message.
Business email compromise and vendor fraud
In a business email compromise attack, a criminal may use a compromised account or impersonate an executive, supplier or customer. Treat changes to bank details, payment requests and unusual confidentiality as high-risk. Verify them using a known phone number or an independently started conversation.
Malware and ransomware
Attachments, links and compromised websites can deliver malware. Ransomware may disrupt systems and make data unavailable, while a separate theft of data can create additional harm. Filtering reduces exposure but does not make every attachment safe. Keep devices patched, use managed endpoint protection and maintain tested, separate backups.
Targeted and automated campaigns
Attackers can personalise messages at scale, and tools used by defenders also change. Treat claims that a filter or artificial intelligence feature catches everything with caution. Security settings, user behaviour and monitoring all contribute to the result.
Practical email security controls
- Require MFA for email, administrator accounts and remote access. Review sign-in alerts and investigate unexpected MFA prompts.
- Use a reputable email service with filtering, malware protection and anti-spoofing controls. Configure SPF, DKIM and DMARC for your domain, then monitor reports before tightening enforcement.
- Keep operating systems, browsers and email applications supported and patched. Restrict risky attachment types where that fits the business.
- Train staff to report suspicious messages using a simple, known process. Make clear that reporting an accidental click quickly is the right action.
- Use unique passwords and a password manager. Disable accounts promptly when people leave and review delegated mailbox access.
- Verify payment and supplier changes through a second channel. Do not rely on the reply address or a familiar signature alone.
- Limit external sharing and review mailbox forwarding rules, OAuth app consent, administrator roles and audit logs.
- Include email compromise, lost access and ransomware in the incident response and continuity plans. Test recovery of important mail and files.
Microsoft 365 and email security
Microsoft 365 includes security settings and protection features, but what is available and enabled depends on the service, tenant configuration and subscription. Microsoft Secure Score can highlight recommendations; it is a measure of configuration progress, not a guarantee that a business is secure. Review the current Microsoft documentation for the tenant before relying on a named feature.
For a wider platform review, see the Microsoft 365 guidance. The same principles apply to other hosted email services: understand the controls, configure them deliberately and monitor what they report.
What to do after a suspicious email
- Stop interacting with the message and report it through the agreed route.
- If someone clicked, entered credentials or approved a request, say so immediately. Speed matters more than embarrassment.
- Use the service's account controls to reset credentials, revoke sessions and review forwarding rules where appropriate.
- Contact the bank or supplier through a known route if money or payment details are involved.
- Record what happened, preserve the message and assess whether other accounts or devices are affected.
The NCSC phishing guidance provides further advice for organisations and staff.
Next steps for SMEs
Start with MFA, domain anti-spoofing, payment verification and a reporting process. Then check permissions, filtering, patching, logs and recovery tests. If you want help prioritising those controls, J700 Group’s cyber security service is the relevant next step.

