Email security for the whole company, not just the website
Phishing is the leading way attackers get in, not the website. The nine measures that protect a company's mailboxes, in order.
The short answer
Websites get the attention, but email is the channel the fraud arrives through. A phished mailbox password, a real invoice thread hijacked with new bank details, a supplier’s compromised account sending a convincing request: business email compromise costs small companies far more than website incidents do, and it lands in the finance department rather than on the website. Nine measures protect a company’s email. The technical ones stop most spoofing and account takeover; one plain rule about payment changes stops the fraud that gets through anyway.
The nine measures
| Measure | What it protects against | Effort |
|---|---|---|
| 1. A business-grade email provider, separate from web hosting | Weak filtering, shared reputation, poor account security | A modest monthly fee per mailbox |
| 2. Two-factor on every mailbox, authenticator or hardware key | Account takeover from phished or reused passwords | An hour to roll out |
| 3. SPF, DKIM and DMARC at reject on your domain | Others receiving mail that pretends to be you; your domain’s reputation | A careful afternoon, then monitoring |
| 4. Phishing-aware habits: check the sender’s domain, hover before clicking, verify unexpected requests | The click that starts the incident | Short, regular reminders; a way to report suspicious mail |
| 5. The payment-change rule: no change to bank details or payment instructions without a phone call to a known number | Invoice fraud, the costliest attack | A written rule everyone in finance knows |
| 6. No automatic forwarding to external addresses; blocked at the provider | Data leaving your control; attackers’ favourite persistence trick | A provider setting |
| 7. Retention limits and archiving | Years of sensitive mail exposed when one account is compromised | A policy and a setting |
| 8. Access reviews: leavers removed same day, shared mailboxes with named owners, delegated access checked quarterly | Lingering access, orphaned mailboxes | Fifteen minutes a quarter |
| 9. Alerts on suspicious sign-ins and new forwarding rules | Silent takeover | Provider settings routed to a person |
Why the payment-change rule matters most
- The attacker is inside a real thread, either in your mailbox, a supplier’s or a customer’s, reading for weeks.
- At the right moment, an invoice is due, they send a message that fits: new bank details, a changed payment link, an urgent transfer.
- Every technical control can be satisfied: the mail is genuinely from the compromised account, authenticated and clean.
- Only a human check stops it: a call to a number you already had, not one in the email, before any change is acted on.
- The rule must be absolute, including for the managing director, because urgency and authority are the attacker’s tools.
Rolling it out
Move to a business-grade provider if you are not on one; separate it from web hosting. Turn on two-factor for everyone in one session, with recovery codes in the password manager. Set SPF, DKIM and DMARC properly, moving to reject with monitoring. Block external auto-forwarding. Write the payment-change rule and put it where finance sees it. Set retention. Put the quarterly access review and the sign-in alerts in place. Then remind people, briefly and regularly, what phishing looks like this season, and make reporting it easy and blameless.
What this means for you
Protect email as the system through which money actually leaves. Business-grade provider, two-factor everywhere, authentication at reject, habits, the payment-change rule, no external forwarding, retention, access reviews and alerts. Most of it is a day of setup and a habit. The fraud it prevents is the kind that closes small businesses, and it is far more likely than the website hack everyone worries about.
Frequently asked questions
We have SPF, DKIM and DMARC. Are our mailboxes safe?
Those three protect others from mail pretending to be you, and protect your domain's reputation. They do nothing for a mailbox whose password is phished. Two-factor on every mailbox, phishing-aware habits and a rule for payment changes are what protect your own inboxes. You need both halves.
What is the single most effective measure?
Two-factor authentication on every mailbox, with an authenticator app or hardware key. It defeats nearly every account takeover that starts with a stolen or reused password, which is nearly all of them. Second is the rule that no payment detail change is acted on without a call to a known number.
Should staff forward work email to their personal accounts?
No. It moves company data and customer correspondence outside every control you have, into accounts with unknown security, and it survives the person leaving. Block automatic forwarding to external addresses at the provider level and say why.
Sources
- ENISA Threat Landscape 2025 (accessed 2026-09-14)
- FBI IC3 Internet Crime Report 2025 (accessed 2026-09-14)
- NCSC: Phishing (accessed 2026-09-11)