Ask most business owners where an attack on their company would start, and they picture something technical, a firewall being breached, a server exploited, someone clever working their way in from the outside. In practice, it is almost always simpler than that. It starts with an email, and someone doing exactly what the email asked them to do.
That is not a comment on your staff. It is a comment on how good the emails have become.
Why email is still the way in
Email remains the most reliable route into an organization for one reason: it is the one system that must accept unsolicited contact from strangers. Every other door can be closed. Your accounts team cannot refuse to open attachments from people they have never met, that is the job.
Attackers know this, and the messages have moved on considerably from the badly written scam of a decade ago:
- Invoice fraud. A supplier you genuinely use emails to say their banking details have changed. The invoice is real, the amount is expected, and the payment goes to the attacker.
- Executive impersonation. A message that appears to come from a director, asking someone in finance for an urgent transfer while the director is conveniently travelling.
- Credential harvesting. A link to a login page that looks exactly like your Microsoft 365 sign-in, because it was copied from it.
- Thread hijacking. The attacker gets into one mailbox, finds a real conversation, and replies within it. There is no suspicious first contact to notice.
The last one is worth sitting with. If an attacker replies inside a genuine thread, using the right names and referencing real work, the usual advice about checking the sender’s address and looking for spelling mistakes simply does not apply.
What a single successful email actually costs
The damage from a compromised mailbox rarely stops at the mailbox:
- Direct financial loss from a payment sent to the wrong account, which is frequently unrecoverable once it has moved.
- Onward attacks on your customers sent from your real domain, the reputational damage of your clients being attacked from your address is hard to undo.
- Ransomware, which often begins with a single set of stolen credentials rather than a dramatic technical breach.
- Notification obligations. If personal information was in that mailbox, you may be legally required to report the breach and inform the people affected.
- Downtime while accounts are locked, passwords reset and the extent of the access is established.
What actually reduces the risk
There is no single product that solves this, but a handful of controls do most of the work, and none of them are exotic.
Filter before it arrives
A secure email gateway removes the overwhelming majority of malicious and unwanted mail before anyone sees it. Attachments are opened in an isolated sandbox rather than trusted on sight, and links are checked at the moment they are clicked rather than only when the message arrives. The best outcome is the message your staff never have to make a judgement call about.
Turn on multi-factor authentication, properly
MFA is the single highest-value control available for email, because it makes a stolen password insufficient on its own. Enable it for everyone, not just executives, and prefer app-based prompts or hardware keys over SMS codes where you can.
Verify payment changes out of band
Make it policy that any change to bank details is confirmed by phone, on a number you already hold, never a number supplied in the email requesting the change. This single rule defeats most invoice fraud, and it costs nothing to introduce.
Configure SPF, DKIM and DMARC
These records tell the rest of the world which servers are allowed to send email as your domain, and what to do with messages that fail. Without them, impersonating your company is trivially easy. They are a configuration task, not a purchase.
Train people on what actually arrives
Annual slide decks change little. Regular, realistic phishing simulations show you where the weak points are and give staff practice at recognising a genuine attempt. Just as importantly, make reporting easy and never punish someone for reporting late, the worst outcome is an employee who clicks and then says nothing for a week.
Have a plan for when it works anyway
Assume that eventually something gets through. Know in advance who disables the account, who checks for mail-forwarding rules the attacker may have created, who reviews what that mailbox could reach, and who decides whether the incident is reportable. Deciding this during an incident wastes the hours that matter most.
The honest summary
Email security is not about buying one more tool. It is about accepting that your organization’s most exposed system is the one everybody uses all day, and putting layers around it: filter what you can, make stolen passwords useless, verify money movements by voice, publish your sending records, and give your people realistic practice.
None of this is expensive compared with a single successful invoice fraud. Most of it is configuration and habit rather than capital cost.
If you are not certain how your email is currently protected, or whether MFA is genuinely enabled for everyone, or whether your DMARC record is doing anything at all, that is worth finding out before someone else does.


