Mayer Networks

Cybersecurity

Email Security

Email remains the most common entry point for attacks. Mayer Networks layers filtering, domain authentication, identity protection, encryption and user training to reduce phishing and business email compromise.

Security lifecycle

  1. Identify
  2. Protect (this page)
  3. Detect (this page)
  4. Respond
  5. Recover

Email security is a Protect control with a Detect component. It works on the delivery method most attacks against staff still use. See the full Mayer Networks cybersecurity approach.

What it is

Email Is Still One of the Most Common Ways Attackers Reach Users.

Attackers do not need to defeat the firewall if they can send a convincing message to somebody who works there. Phishing, malicious links, malicious attachments, impersonation of executives and vendors, business email compromise, fraudulent payment requests and credential harvesting all arrive the same way.

Email security analyses messages for those characteristics: reputation, link destinations, attachment behaviour, sender authentication and impersonation patterns. Cloud email security inspects mail inside the Microsoft 365 environment rather than only at the gateway, which also means internal and already-delivered messages can be examined.

Default filtering stops bulk malicious mail. The targeted remainder is what this layer exists for.

The problem it solves

What Email Security Is There to Stop

The messages that cause real loss usually look entirely reasonable.

  • Credential phishing that mimics a Microsoft 365 sign-in page
  • A payment or banking-change request timed against a real invoice
  • Mail from a genuinely compromised account at a vendor you actually use
  • Impersonation of an executive, a clerk or a department head
  • Malicious attachments and links that pass default filtering
  • Mailbox rules quietly forwarding a copy of everything outside the organization

How Mayer Networks uses it

How Mayer Networks Operates Email Security

Filtering is configured against real mail flow, and it is paired with the tenant configuration that decides how much damage a successful message can do.

  • Assess

    Current filtering, authentication records, mailbox rules and identity protections are reviewed before anything is changed.

  • Authenticate the domain

    SPF, DKIM and DMARC are configured so spoofed mail claiming to be your organization is rejected rather than delivered.

  • Filter and tune

    Anti-phishing, malware detection, link inspection, attachment analysis and impersonation protection are deployed and tuned against the organization's actual mail, including legitimate senders that look unusual.

  • Watch the mailbox

    Forwarding rules, unusual sending behaviour and suspicious sign-ins are alerted on, because a compromised mailbox is often quieter than the phishing that created it.

  • Respond

    A compromised account gets credential reset, session revocation, rule cleanup and a review of what was sent from it, coordinated with the wider incident process.

  • Train

    Ongoing awareness training and phishing simulation, because the targeted remainder is aimed at people rather than at filters.

Platform

The Platform: Avanan by Check Point

Mayer Networks uses cloud email security to analyse messages in the Microsoft 365 environment, alongside the built-in Microsoft protections the tenant already licenses.

Avanan by Check Point

Avanan by Check Point

Cloud email security

Anti-phishing, malware and link analysis, attachment inspection, impersonation protection, policy control and alerting applied to mail inside the Microsoft 365 environment.

  • Anti-phishing
  • Malware detection
  • Link inspection
  • Attachment analysis
  • Impersonation protection
  • Policy and alerting

Microsoft 365 tenant hardening

Configuration, not a product

External sender marking, legacy protocol restriction, forwarding controls and audit logging. Capability depends on the licensing the organization holds.

Check Point and Avanan are trademarks of Check Point Software Technologies Ltd. Capabilities depend on the licensed product tier and the tenant configuration.

Layered defence

What Email Security Does Not Replace

Some messages will always reach people. The layers behind email are what decide the outcome when one does.

  • MFA, which is what stops a phished password from working
  • Identity threat detection, for what happens after a session is taken over
  • Endpoint security, for attachments and payloads that execute
  • Backup and recovery, for the mailbox data and the files behind it
  • A payment verification procedure that does not use email to confirm email
  • User awareness, because judgement is the last control in this path

The payment-verification process is a business procedure rather than a product, and it prevents more loss than any single tool in this category.

Cybersecurity overview: the layered Mayer Networks standard

Lifecycle stage: Protect and Detect

The layers most closely connected to this one. Each covers a front this control does not.

We can review filtering, domain authentication and mailbox settings, and show where a convincing message would still succeed today.

Review Your Email Security

The attacks that get through filtering

Filtering stops bulk malicious mail. What reaches people is the targeted remainder: a message from a genuine compromised account at a vendor the organization actually uses, a payment change request timed to a real invoice, a mailbox rule quietly forwarding a copy of everything to an outside address.

Those need controls rather than better filtering: multi-factor authentication on mailboxes, alerting on forwarding rules and impossible-travel logins, external sender marking, and a payment verification procedure that does not depend on email confirming email. The last one is a business process and it prevents more loss than any product.

Why Mayer Networks

  • Email security handled with identity security, not separately
  • Practical process guidance for payment verification
  • One organization accountable for support, engineering, security, infrastructure and communications.
  • Responsive remote and onsite support from engineers based in Southern Illinois, not a queue in another time zone.

Security considerations

  • MFA as the foundation of mailbox protection
  • Legacy authentication protocols disabled where possible
  • Alerting on suspicious mailbox rules and sign-ins

Questions

Frequently asked questions

Still have a question? Call 618-529-4922 or send us the details.

Does Microsoft 365 already include email security?

It includes baseline protection. Additional filtering, correct authentication records, identity hardening and training meaningfully reduce risk beyond defaults.

What is business email compromise?

An attacker gains access to or convincingly imitates a legitimate mailbox and uses it to redirect payments or extract information. It often involves no malware at all.

Can we encrypt email to clients?

Yes, using encryption options that let recipients read messages securely without complicated software.

Does training actually help?

Yes, particularly when it is ongoing and paired with technical controls. Neither alone is sufficient.

Let's talk about your technology

Tell us what you are running and what is not working. We will tell you plainly what we would do about it.