Human layer
Most break-ins still start with one convincing message.
Email is the cheapest way into any organisation, and the attacks that work are rarely technical. They are a supplier asking you to update bank details, or a CEO who needs something urgently. We fix the technical side — proving your domain cannot be spoofed and tightening gateway policy — then run a training programme designed to change behaviour rather than simply record who failed.

- SPF · DKIM · DMARC
- Taken all the way to enforcement
- -71%
- Median drop in click rate after two quarters
- Monthly
- Simulation and coaching cycle
Sound familiar?
If two of these describe your week, this is the service that fixes it.
Finance regularly receives convincing requests to change supplier bank details.
Your domain is being spoofed and the reports that would prove it go unread.
Awareness training is an annual video everyone clicks through at speed.
What the service covers
How the work is actually done, day to day.
Proving your domain is really yours
SPF, DKIM and DMARC are the records that let the world reject fake mail sent in your name. We take them from monitoring to full enforcement without breaking legitimate senders like your billing and marketing platforms.
Hardening the mail platform
Anti-phishing, impersonation and attachment rules tuned to the lures actually used against your industry, plus a quarantine review process so blocked mail does not vanish silently.
Simulations that teach
Realistic, role-relevant test emails with an immediate explanation when someone clicks. Nobody is named or shamed — the aim is a lower click rate next quarter, not a leaderboard.
A report button that goes somewhere
One click sends a suspicious mail to our analysts. If it is malicious, the same message is pulled from every other mailbox in your organisation, usually within minutes.
What you receive
Documents you can hand to an auditor.
- Email authentication audit and enforcement plan
- Hardened gateway and tenant policy set
- Quarterly simulation calendar and results
- Risk scoring by department, so training goes where it is needed
- Analyst triage for every message your staff report
Platforms we work with
Fluent in the tools, loyal to none of them.
If you already hold licences, we operate them — no resale margin, no forced migration. When a change genuinely closes a gap or saves money, you see both cost models side by side before anyone recommends anything.
Onboarding
How email & phishing defence goes live.
- 01
A 45-minute conversation
What you run, what worries you, and what a bad week has already cost you. No slides and no product pitch — we are working out whether we can genuinely help.
- 02
Posture assessment
We examine the estate, compare it against a recognised framework and hand you a prioritised list of gaps. The report is yours to keep whether or not you buy anything.
- 03
Onboarding and a rehearsal
Log sources, agents, access and escalation contacts are agreed, then we run a live drill of a real incident before we call the service live. Untested escalation paths are decoration.
- 04
Steady-state operations
Monitoring, response and reporting run to a written SLA, with a quarterly review that changes the plan whenever your business changes.
Questions
What buyers ask about email & phishing defence.
Pairs well with
All servicesSOC as a Service
A team of analysts watching your systems every hour of the day, deciding which alerts are real and acting on them.
02NOC as a Service
Continuous monitoring of networks, servers and applications so faults are caught and fixed before your users notice.
03Data Loss Prevention
Controls across laptops, email, network and cloud apps that spot sensitive data leaving and stop it in the moment.
Hand email & phishing defence to people who do this daily.
Tell us how big the estate is and what deadline you are working to. Within three business days you will have a scope, a timeline and a flat monthly number — no discovery fee to get there.
