Human layer

Most break-ins still start with one convincing message.

Email is the cheapest way into any organisation, and the attacks that work are rarely technical. They are a supplier asking you to update bank details, or a CEO who needs something urgently. We fix the technical side — proving your domain cannot be spoofed and tightening gateway policy — then run a training programme designed to change behaviour rather than simply record who failed.

Clay-style illustration of an envelope caught on a hook beside an amber warning beacon
SPF · DKIM · DMARC
Taken all the way to enforcement
-71%
Median drop in click rate after two quarters
Monthly
Simulation and coaching cycle

Sound familiar?

If two of these describe your week, this is the service that fixes it.

  • Finance regularly receives convincing requests to change supplier bank details.

  • Your domain is being spoofed and the reports that would prove it go unread.

  • Awareness training is an annual video everyone clicks through at speed.

What the service covers

How the work is actually done, day to day.

01

Proving your domain is really yours

SPF, DKIM and DMARC are the records that let the world reject fake mail sent in your name. We take them from monitoring to full enforcement without breaking legitimate senders like your billing and marketing platforms.

02

Hardening the mail platform

Anti-phishing, impersonation and attachment rules tuned to the lures actually used against your industry, plus a quarantine review process so blocked mail does not vanish silently.

03

Simulations that teach

Realistic, role-relevant test emails with an immediate explanation when someone clicks. Nobody is named or shamed — the aim is a lower click rate next quarter, not a leaderboard.

04

A report button that goes somewhere

One click sends a suspicious mail to our analysts. If it is malicious, the same message is pulled from every other mailbox in your organisation, usually within minutes.

What you receive

Documents you can hand to an auditor.

  • Email authentication audit and enforcement plan
  • Hardened gateway and tenant policy set
  • Quarterly simulation calendar and results
  • Risk scoring by department, so training goes where it is needed
  • Analyst triage for every message your staff report

Platforms we work with

Fluent in the tools, loyal to none of them.

Microsoft Defender for Office 365ProofpointMimecastKnowBe4DMARC analytics

If you already hold licences, we operate them — no resale margin, no forced migration. When a change genuinely closes a gap or saves money, you see both cost models side by side before anyone recommends anything.

Onboarding

How email & phishing defence goes live.

  1. 01

    A 45-minute conversation

    What you run, what worries you, and what a bad week has already cost you. No slides and no product pitch — we are working out whether we can genuinely help.

  2. 02

    Posture assessment

    We examine the estate, compare it against a recognised framework and hand you a prioritised list of gaps. The report is yours to keep whether or not you buy anything.

  3. 03

    Onboarding and a rehearsal

    Log sources, agents, access and escalation contacts are agreed, then we run a live drill of a real incident before we call the service live. Untested escalation paths are decoration.

  4. 04

    Steady-state operations

    Monitoring, response and reporting run to a written SLA, with a quarterly review that changes the plan whenever your business changes.

Questions

What buyers ask about email & phishing defence.

Hand email & phishing defence to people who do this daily.

Tell us how big the estate is and what deadline you are working to. Within three business days you will have a scope, a timeline and a flat monthly number — no discovery fee to get there.