Email security for the whole company, not just the website

Phishing is the leading way attackers get in, not the website. The nine measures that protect a company's mailboxes, in order.

4 minread 789words last updated

The short answer

Websites get the attention, but email is the channel the fraud arrives through. A phished mailbox password, a real invoice thread hijacked with new bank details, a supplier’s compromised account sending a convincing request: business email compromise costs small companies far more than website incidents do, and it lands in the finance department rather than on the website. Nine measures protect a company’s email. The technical ones stop most spoofing and account takeover; one plain rule about payment changes stops the fraud that gets through anyway.

The nine measures

MeasureWhat it protects againstEffort
1. A business-grade email provider, separate from web hostingWeak filtering, shared reputation, poor account securityA modest monthly fee per mailbox
2. Two-factor on every mailbox, authenticator or hardware keyAccount takeover from phished or reused passwordsAn hour to roll out
3. SPF, DKIM and DMARC at reject on your domainOthers receiving mail that pretends to be you; your domain’s reputationA careful afternoon, then monitoring
4. Phishing-aware habits: check the sender’s domain, hover before clicking, verify unexpected requestsThe click that starts the incidentShort, regular reminders; a way to report suspicious mail
5. The payment-change rule: no change to bank details or payment instructions without a phone call to a known numberInvoice fraud, the costliest attackA written rule everyone in finance knows
6. No automatic forwarding to external addresses; blocked at the providerData leaving your control; attackers’ favourite persistence trickA provider setting
7. Retention limits and archivingYears of sensitive mail exposed when one account is compromisedA policy and a setting
8. Access reviews: leavers removed same day, shared mailboxes with named owners, delegated access checked quarterlyLingering access, orphaned mailboxesFifteen minutes a quarter
9. Alerts on suspicious sign-ins and new forwarding rulesSilent takeoverProvider settings routed to a person

Why the payment-change rule matters most

  1. The attacker is inside a real thread, either in your mailbox, a supplier’s or a customer’s, reading for weeks.
  2. At the right moment, an invoice is due, they send a message that fits: new bank details, a changed payment link, an urgent transfer.
  3. Every technical control can be satisfied: the mail is genuinely from the compromised account, authenticated and clean.
  4. Only a human check stops it: a call to a number you already had, not one in the email, before any change is acted on.
  5. The rule must be absolute, including for the managing director, because urgency and authority are the attacker’s tools.

Rolling it out

Move to a business-grade provider if you are not on one; separate it from web hosting. Turn on two-factor for everyone in one session, with recovery codes in the password manager. Set SPF, DKIM and DMARC properly, moving to reject with monitoring. Block external auto-forwarding. Write the payment-change rule and put it where finance sees it. Set retention. Put the quarterly access review and the sign-in alerts in place. Then remind people, briefly and regularly, what phishing looks like this season, and make reporting it easy and blameless.

What this means for you

Protect email as the system through which money actually leaves. Business-grade provider, two-factor everywhere, authentication at reject, habits, the payment-change rule, no external forwarding, retention, access reviews and alerts. Most of it is a day of setup and a habit. The fraud it prevents is the kind that closes small businesses, and it is far more likely than the website hack everyone worries about.

Written by the CivSec S.M.A.R.T team

We build and run websites, software and AI systems for businesses. We write about what we see in that work, in plain language, and we update articles when things change.

Last checked . Spotted something outdated? Tell us.

Frequently asked questions

We have SPF, DKIM and DMARC. Are our mailboxes safe?

Those three protect others from mail pretending to be you, and protect your domain's reputation. They do nothing for a mailbox whose password is phished. Two-factor on every mailbox, phishing-aware habits and a rule for payment changes are what protect your own inboxes. You need both halves.

What is the single most effective measure?

Two-factor authentication on every mailbox, with an authenticator app or hardware key. It defeats nearly every account takeover that starts with a stolen or reused password, which is nearly all of them. Second is the rule that no payment detail change is acted on without a call to a known number.

Should staff forward work email to their personal accounts?

No. It moves company data and customer correspondence outside every control you have, into accounts with unknown security, and it survives the person leaving. Block automatic forwarding to external addresses at the provider level and say why.

Sources

  1. ENISA Threat Landscape 2025 (accessed 2026-09-14)
  2. FBI IC3 Internet Crime Report 2025 (accessed 2026-09-14)
  3. NCSC: Phishing (accessed 2026-09-11)