Pre-delivery AI · DMARC enforcement · 24/7 SOC
Email security for M365 and Google Workspace — phishing, BEC, and DMARC, closed out to "reject"
Layered protection that sits in front of (or alongside) Microsoft 365 Defender and Google Workspace. AI behavioral analysis, impersonation protection, attachment detonation, DMARC enforcement, and a user-training loop that actually moves the phish-prone needle.
Commodity phishing
Fake login links, bulk-sent, malicious domains in URL
- Primary layer
- Defender / Gmail + Area 1
- What gets blocked
- Pre-delivery, signature + URL reputation
Tailored BEC
"Your CEO" asking for a wire, no links, clean sender domain
- Primary layer
- Abnormal + Vade (behavioral AI)
- What gets blocked
- Sender-graph anomaly, language pattern deviation, timing
Vendor Email Compromise
Real vendor contact whose mailbox was hijacked, sends fake invoice
- Primary layer
- Abnormal VEC + Defender
- What gets blocked
- Banking-detail change detection, anomalous thread behavior
Malicious attachments
Office docs with macros, archives, HTML smuggling, PDFs
- Primary layer
- Sandboxing (Defender, Area 1)
- What gets blocked
- Pre-delivery detonation in VM, behavior-based verdict
Domain spoofing
Mail from forged-sender @yourcompany.com to customers
- Primary layer
- Valimail DMARC enforcement
- What gets blocked
- DMARC policy reject: receiving servers drop forgeries
Look-alike domains
yourc0mpany.com, yourcompany-payments.com typo-squat sends
- Primary layer
- Brand protection monitoring
- What gets blocked
- Daily domain-registration sweep, takedown workflow (Enterprise)
Account takeover
Attacker logs in with valid creds and sends internal phish
- Primary layer
- Defender + SOC triage + MFA (Duo)
- What gets blocked
- Anomalous login + internal send pattern → auto-disable + SOC page
A full threat-coverage matrix with per-vendor control mapping is in every proposal. Ask for the sample packet.
Which layer stops which threat. Because "we block phishing" doesn't mean anything.
Email attacks aren't one thing. They're seven different things, and they need seven different detection approaches. Here is what each layer in our stack catches, and where a single-vendor approach falls down.
The email stack we actually run
No white-label mystery boxes.
Three email protection lanes. Per-mailbox pricing. No MX swap required.
All tiers deploy via Microsoft Graph or Gmail API: zero mail flow disruption. Upgrades happen in-place. No licenses wasted if your inbox count changes mid-term.
Email Essentials
The minimum baseline on top of Defender or Gmail native filtering.
Annual agreement · 25-mailbox minimum
- Signature-based spam/malware + known-bad URL rewriting
- Attachment sandboxing for Office docs, PDFs, archives
- SPF + DKIM configuration & monitoring (reporting only)
- Monthly threat summary + top-targeted-users report
- KnowBe4 starter phishing simulations (4/year)
- Deployed via API
Advanced Threat Protection
Behavioral AI for BEC. DMARC to reject. Training loop with remediation.
Annual agreement · 25-mailbox minimum
- Everything in Essentials
- Abnormal + Vade behavioral AI for BEC & impersonation
- DMARC enforcement rollout (monitor → quarantine → reject)
- Vendor Email Compromise (VEC) detection on external senders
- KnowBe4 PhishER: 12 simulations/year + 90-sec remediation module
- 24/7 SOC triage on user-reported phish
Enterprise Email + DLP
For regulated industries, public companies, or 1,000+ mailbox estates.
Scoped by mailbox count & compliance framework
- Everything in Advanced Threat Protection
- Outbound DLP: PHI, PCI, PII, source code pattern policies
- Journaling + legal hold to Proofpoint or archive of choice
- Custom brand-impersonation monitoring for look-alike domains
- Quarterly tabletop BEC exercise with your finance team
Our free email threat assessment runs read-only against your tenant. We look at the last 30 days of mail flow for evidence of phishing that bypassed your filters, BEC patterns targeting finance and HR, DMARC posture on your sending domains, and impersonation attempts using look-alike domains. 1-page executive report.
Read-only audit of your tenant. 1-page executive report back.Get your email threat assessment
We'll audit your tenant for DMARC posture, historical phish delivery, and impersonation exposure. A quote follows if you want one.
We don't sell "compliance." We deliver the packet your auditor actually wants.
Every quarter we drop a ready-made evidence package into your portal: control mapping, log samples, policy attestations, tested backups, and user-access reviews. Your staff stops fighting spreadsheets. Your assessor finishes in days, not weeks.
SOC 2 Type IISecurity, availability, and confidentiality trust criteria. Most-requested by your B2B customers during procurement.
HIPAAHealthcare PHI safeguards, BAA-ready stack, annual risk analysis and workforce training records.
PCI-DSS v4.0Cardholder data environment scoping, quarterly ASV scans, segmentation validation.
CMMC Level 2110 NIST 800-171 controls for DoD subcontractors. Our partners are registered RPOs.
CJISCriminal Justice Information Services for agencies handling FBI-sourced data.
NIST CSF 2.0The framework your cyber-insurance carrier is actually scoring you against.
ISO 27001ISMS controls for clients doing business in the EU or with multinationals.
GLBA / FTC SafeguardsFor financial services, including the 2023 FTC Safeguards Rule for tax preparers and auto dealers.
Five questions. Honest answers.
We already have Microsoft 365 Defender. Why do we need another email security layer?
Defender for Office 365 catches the bulk volume but misses the tailored BEC and impersonation attacks that use clean-origin domains and have no payload. Our layered stack adds AI behavioral analysis (looks at sender-recipient history, language, and timing anomalies) and catches the threats that slip past native signature-based filtering. Most clients keep Defender and add our layer on top. No MX swap required.
Do you enforce DMARC? Will it break our legitimate email?
Yes, DMARC enforcement is included in Advanced Threat Protection and Enterprise tiers. We roll it out in three phases: monitor (p=none) for 30 days to discover every legitimate sender, then quarantine for 30 days with daily exception review, then reject. By the time we flip to p=reject your SaaS-sent email, CRM blasts, and HR payroll notifications are all authenticated.
How do you stop Business Email Compromise when there's no malicious link or attachment?
BEC attacks look clean to signature-based filters because there is no payload. Our behavioral AI (Abnormal + Vade) learns each user's normal communication graph: who your CFO talks to, how they phrase wire requests, when they usually reply. When a new email arrives from "your CEO" asking for a $184k wire to a first-time vendor at 5:47pm on a Friday, the system flags the anomaly and quarantines it pre-delivery.
How long does onboarding take and do we have to switch MX records?
No MX swap. Our stack integrates via Microsoft Graph API (M365) or Gmail API (Google Workspace): zero mail flow disruption. First 7 days run in observe-only mode to tune false positives against your real traffic. Day 8 we flip to active blocking on high-confidence threats. DMARC and user-training loop roll out over weeks 2-4. No downtime, no cutover weekend.
Do you cover the user training side, or just the inbox side?
Both. Advanced and Enterprise tiers include KnowBe4 PhishER-powered simulations (12 campaigns per year), a library of 500+ training modules mapped to role and risk, and monthly reporting tied to individual phish-prone scores. When a user clicks a simulated phish, they're enrolled in a 90-second remediation module before they can continue.
Email security
