01Filter
Anti-phishing & spam filtering
Filtering that catches spam, known malicious senders, and phishing attempts before they land in a mailbox.
- Spam and malware filtering
- Phishing detection and quarantine
- Safe links and safe attachments scanning
- Domain and sender reputation checks
- Quarantine review and release workflow
Best for: Any organization running Microsoft 365 or Google Workspace for email.
Typical timeline: Initial filtering setup typically takes 3–5 business days.
02Detect
Business email compromise (BEC) protection
Detection tuned for impersonation and account takeover attempts, which standard spam filters often miss.
- Executive and vendor impersonation detection
- Anomaly detection for compromised accounts
- Display name spoofing protection
- Sandbox analysis for suspicious attachments
- Alert escalation for confirmed BEC attempts
Best for: Finance and operations teams that handle wire transfers or vendor payments by email.
Typical timeline: BEC protection policies are typically configured within the first week.
03Protect
Encryption & data controls
Encryption and policy controls for sensitive information sent by email, without adding friction for routine mail.
- Email encryption for sensitive content
- Data loss prevention rules for outbound mail
- Attachment and link restriction policies
- Message expiration and access controls
- Compliance-driven retention settings
Best for: Regulated businesses that need to control how sensitive data leaves by email.
Typical timeline: Encryption policy setup typically takes 1 week.
04Train
Awareness training & simulation
Simulated phishing campaigns and short training that measurably reduce click-through rates over time.
- Simulated phishing campaigns
- Targeted training for repeat clickers
- Reporting on organizational risk trends
- New-hire security awareness onboarding
- Quarterly campaign scheduling
Best for: Organizations that have had a near-miss or actual phishing incident and want to reduce the human risk factor.
Typical timeline: First simulation campaign typically launches within 2 weeks.
05Authenticate
Email authentication (SPF/DKIM/DMARC)
SPF, DKIM, and DMARC configured and monitored so attackers can't spoof your domain in phishing emails sent to your customers and partners.
- SPF record configuration and validation
- DKIM signing setup
- DMARC policy rollout (monitor to enforce)
- DMARC report monitoring and alerting
- Domain spoofing protection for outbound reputation
Best for: Organizations that want to stop their own domain from being used to phish customers, partners, or vendors.
Typical timeline: DMARC rollout typically moves from monitoring to enforcement over 4–8 weeks.
06Respond
Incident response & mailbox recovery
Rapid mailbox recovery and cleanup when an account is compromised, so a single phished login doesn't turn into a wider breach.
- Compromised account isolation
- Malicious inbox rule and forwarding cleanup
- Session and token revocation
- Password and MFA reset coordination
- Post-incident mailbox audit
Best for: Organizations that need a fast, defined process the moment a mailbox is suspected compromised.
Typical timeline: Initial containment typically begins within 1 hour of detection.