Managed cyber security

Advanced Email Security

Layered phishing, impersonation, malware and business email compromise protection.

What is Advanced Email Security?

Advanced email security combines Microsoft 365 configuration, filtering, impersonation controls, attachment and link inspection, domain authentication and managed review. It is designed to reduce phishing, business email compromise, malware and fraudulent payment requests while giving staff a clear route to report suspicious messages.

Who is this service for?

Businesses where email is central to finance, customer service, supplier communication or remote working, particularly firms using Microsoft 365 and handling payment instructions, confidential documents or high volumes of external correspondence.

What problem does it solve?

A convincing message can bypass basic spam filtering, imitate a director or supplier, steal Microsoft 365 credentials or persuade staff to change bank details. Technical filtering alone cannot eliminate this risk, so controls need to combine secure configuration, domain protection, user reporting and an agreed verification process.

What is included?

  • Inbound and outbound email filtering
  • Impersonation, lookalike-domain and display-name protection
  • Attachment and URL inspection
  • SPF, DKIM and DMARC review and management
  • Quarantine and false-positive support
  • Reported-message investigation route
  • Monthly threat and configuration reporting
  • Guidance for payment-change verification

What is not included?

  • Guarantee that every malicious message will be blocked
  • Full legal or fraud investigation
  • Remediation of unsupported legacy mail systems unless scoped
  • Employee disciplinary monitoring

How implementation works

We review domains, mail flow, Microsoft 365 security settings, privileged accounts, current filtering and common business workflows. Policies are introduced in a controlled way, starting with monitoring where appropriate. Domain records are corrected, staff reporting is enabled and priority impersonation targets are identified before stronger enforcement is applied.

Supported platforms and products

Primarily Microsoft 365 and Exchange Online, with support for compatible cloud email-security gateways and DNS controls. Hybrid or third-party platforms can be assessed, but the exact supported mail flow is confirmed before deployment.

How quickly are alerts investigated?

High-confidence malicious messages, compromised accounts and business-email-compromise indicators are investigated according to the contracted service window. Urgent cases are escalated to the named client contacts and, where included, to the MDR or incident-response team.

Who responds?

39Security reviews the message, sender infrastructure, links, attachments, tenant indicators and related user activity. Actions may include message search and removal, account protection, domain blocking and coordination with the client’s IT provider or finance team.

What evidence and reporting will you receive?

Reports can include blocked threat volumes, impersonation attempts, domain-authentication status, user-reported messages, material incidents and recommended changes. This helps demonstrate active management rather than reliance on a default filter.

Cyber Essentials, insurance and Microsoft 365

Email security contributes to malware protection, secure configuration, access control and staff awareness. It can support Cyber Essentials readiness, Microsoft 365 security improvement and insurer expectations, but no filter removes the need for MFA, patching and business verification procedures.

What does it cost?

Pricing is generally per mailbox or user, plus setup where domain remediation or migration is required. Current indicative pricing is shown excluding VAT. Complex multi-domain or hybrid environments are quoted after discovery.

How is the service governed?

Before activation, the proposal should identify the covered users, devices, locations and platforms, together with the service window, escalation contacts and change responsibilities. During operation, material exceptions are recorded rather than hidden, and recommendations are separated into urgent actions, planned improvements and optional projects. This gives managers a practical view of risk, cost and ownership.

Service reviews should test whether coverage still matches the business. New starters, leavers, acquisitions, cloud applications, office moves and supplier changes can all create gaps. 39Security therefore treats onboarding, reporting and periodic review as part of the control, not as administration around the edge of the product.

What should good delivery look like?

A buyer should be able to identify what is protected, who is watching it, what happens when something goes wrong and which evidence will be available afterwards. The provider should explain limitations honestly, avoid vague promises and document any dependency on Microsoft licensing, internet connectivity, third-party suppliers or customer action. Clear boundaries make response faster and reduce disputes during an incident.

Questions to ask before selecting a provider

  • Which systems, users and locations are included in the quoted scope?
  • Who reviews alerts, during which hours, and what happens when the named contact is unavailable?
  • What evidence will we receive for clients, insurers, auditors or board reporting?
  • Which actions are included in the monthly fee and which require separate project approval?
  • How are service quality, response times, exclusions and exit arrangements documented?

Frequently asked questions

Is Microsoft 365 email protection enough?

Microsoft 365 includes valuable anti-spam and anti-malware controls, but the protection achieved depends on licensing, configuration, monitoring and response ownership. Many businesses benefit from stronger impersonation protection, managed domain authentication, user reporting and an additional specialist review layer.

Will email filtering stop payment fraud?

It can reduce the number of fraudulent messages that reach staff, but it cannot replace an independent bank-detail verification process. The safest control is to verify payment changes using a trusted contact method that does not rely on the suspicious email.

What are SPF, DKIM and DMARC?

They are complementary email-authentication controls. SPF identifies permitted sending services, DKIM adds a cryptographic signature and DMARC tells receiving systems how to handle failures while providing reports that help protect the domain from spoofing.

Can staff report suspicious emails?

Yes. A reporting route can be added so users can send suspicious messages for review. Fast reporting helps the team remove related messages and protect affected accounts before the issue spreads.