Skip to content

Platform / Prevent

Business Email Protection

Anti-phishing that understands your supplier graph, so an invoice redirect from a compromised partner is caught even when the sending domain is legitimate.

p=reject

DMARC enforcement we implement, not just advise

What you receive

  • Supplier-graph-aware invoice fraud detection
  • Inbound phishing and payload neutralisation
  • DMARC, SPF and DKIM enforcement programme
  • Targeted user simulation with measured risk scoring

When you need this

Three situations that call for it. If none of them is yours, it probably is not the right spend.

  • 01

    A supplier's mailbox is answering you

    The invoice arrives inside a thread you started, from the real domain, signed and aligned — because the sender genuinely is your supplier, only someone else is typing. Every authentication check passes, so the remaining anomaly is the change of bank details.

  • 02

    The phish came from the desk next to you

    Once one internal mailbox is taken over, the messages it sends to colleagues never leave the tenant and never pass an inbound gateway at all. Catching that means reading the mail flow inside the tenant rather than filtering at the perimeter.

  • 03

    You are stuck at DMARC p=none

    Enforcement stalls because nobody can name every system that sends as you — invoicing, ticketing, marketing, an acquired subsidiary's old domain. Publishing reject before that inventory exists breaks real mail, which is why the policy never moves.

How it runs

  1. 01

    Scoping call

    Thirty minutes with an engineer. We establish what you already run, where the gaps actually are, and whether a module earns its place beside your existing tooling.

  2. 02

    Connect and baseline

    We connect the data sources the module reads and spend the first weeks learning what normal looks like in your estate. Tuning against your traffic is what stops the alerts being noise.

  3. 03

    Go live

    The module starts writing to the adversary graph and escalating to you. Escalation routes, thresholds and who gets woken at 03:00 are agreed in writing beforehand.

  4. 04

    Continuous review

    A standing review of what fired, what did not, and what changed in your estate. A detection set that is not revisited decays — the attacks move even when your systems do not.

No lock-in

Scoping costs nothing and carries no obligation. If the answer is that you do not need this, that is a legitimate outcome of the call.

Who turns up

The engineer on your scoping call is on the delivery team. We do not hand you to a different group after signature.

Scope

What this does not cover

  • We do not sit inside your ERP or approve payments — a flagged change of bank details still has to be verified and released by your own finance controls.

  • Money already sent is a bank recall and, where a mailbox was breached, an Incident Response engagement; neither one is part of this service.

  • This protects mail addressed to you, whereas lookalike sites and fake apps phishing your customers are handled under Brand Protection.

Measured against

PCI DSS 4.0.1 Req. 5.4.1
Requires processes and automated mechanisms that detect and protect personnel from phishing attacks, not awareness training alone.
NIS2 Directive (EU) 2022/2555, Art. 21(2)
Lists cyber hygiene, staff training and secured communications among the risk-management measures in-scope entities must adopt.

If the scope is wrong

Tell us on the call. Re-scoping before we start costs nothing; discovering it at the readout costs you the engagement.

Questions

The ones we are actually asked.

Does DMARC at p=reject stop invoice fraud?

No. Enforcement stops other people sending as your domain, which is a different attack — it does nothing about a lookalike domain, a free-mail account carrying the right display name, or a real supplier mailbox in someone else's hands.

We already have Microsoft 365 — what does this add?

Native filtering handles bulk phishing and known payloads well, and we do not replace it. The gap is authenticated mail from a real counterparty, where the only signal is that this relationship has never asked for a bank change before.

Will enforcement break our outbound mail?

It will, if reject is published before the sender inventory is finished. The programme reads aggregate reports first, moves through quarantine, and enforces only once every legitimate sender is aligned and accounted for.

Next step

See what an attacker sees

We map your external attack surface the way an adversary does — exposed assets, leaked credentials, impersonation domains. No agent, no access, no cost.

30 min

A scoping call, with an engineer rather than a sales rep.

What it costs

Nothing, and there is no sequence afterwards. If we are not the right fit we will say so and suggest who is.

Under attack now?

Do not use this form. The hotline is answered around the clock and reaches a duty analyst directly.