Professional Email in a Modern Threat Landscape

Webinar

Transcript: 

Hello, and thank you for joining us. My name is Eric Petty. I’m the owner and CEO of Lean On Me IT. Today, we’re going to talk about email, including email professionalism and security in the modern threat landscape. Even within the last couple of years, a lot has changed. When most businesses think about email, they think about messages. Attackers think about identity, trust, and who you’re communicating with. A business mailbox often connects to calendars, documents, Teams conversations, other cloud applications, invoices, and customer conversations.

A compromised mailbox can look legitimate because the message comes from a real employee, a real conversation, and even from the correct domain. Take a moment and consider when was the last time that you received a phishing message or strange MFA prompt?

The goal today is not to make everyone afraid of email. It’s to show why multiple security layers are needed and where each layer fits. This session covers technology, user behavior, and response. No single tool makes your organization safe. Let’s start with the foundation, why a business-grade email account matters, and then we’ll get into advanced security.

A professional email address is part of your brand, but the bigger value is control. A business platform gives the organization the ability to manage identities, security policies, retention, encryption, and access when employees join or leave your organization.

Professionalism and trust is key. A company domain reinforces that the sender represents the business and gives customers a consistent point of contact. Especially in the modern age of phishing, seeing an email from Gmail or Yahoo tends to create a sense that they are not legitimate. You’ll find that many phishing emails come from personal addresses, causing end users to become even more suspicious.

Administrative control. You want the business to control the account, access, aliases, and off-boarding. If using a personal account, you have to rely on the employee giving you access to the account to get them out of it. With a business account, one flip of a switch and they can be locked out of all of your core business resources.

Filtering and threat protection. Business platforms can apply organization-wide spam, phishing, impersonation, malware, attachment scanning, and link scanning policies. In other words, it’s going to do a better job of minimizing spam and phishing while also scanning every attachment and link to ensure you stay safe. With a personal account, the goal is to ensure you receive all your emails, not that they’re safe. 

Encryption and data protection. Sensitive messages can be protected when your business needs or policies require it. With the appropriate license, you can send encrypted emails to ensure you adhere to any compliance requirements like HIPAA. It’s also possible to set up DLP, Data Loss Prevention Policies, to prevent sensitive information from being sent out. Think things like driver’s license numbers, social security numbers, credit cards, or other sensitive customer information.

Continuity. With a business account, you can have a shared process, delegated access, archiving, backup, and easier account transitions. One quick note, having a business account does not guarantee that all of these protections are correctly configured, monitored, or maintained.

We’re obviously a little biased, but we encourage you to work with an IT partner to ensure that all is configured best for your organization. The platform matters, but the way it’s configured and managed matters just as much.

Google Workspace and Microsoft 365 can both support secure business operations. It’s not about which system is safer; it’s about who is responsible for configuring, monitoring, and improving the environment, and which system works best to increase your overall business efficiency.

Many small businesses buy productivity subscriptions and treat the setup as complete once their email starts working. Security defaults, admin roles, recovery methods, device controls, third-party apps, logging, and response plans may never receive a structured review. Unfortunately, many IT partners will act the same. 

For the modern IT company focusing on keeping you and your team secure, you often find that they only support one of the two options. In most cases, you’re going to find that IT companies will lean towards Microsoft for a number of reasons.

The reality is that both platforms can provide security capabilities, and both can also be weakened by poor configuration or unmanaged exceptions. Microsoft 365, however, is often the better fit when a business also wants centralized Windows identity, Intune device management, conditional access, defender security tools and compliance capabilities in one ecosystem.

That probably sounds like a bunch of gibberish to most of you, but consider signing into your PC with your email address, automatically getting logged into all of your Microsoft apps and services, while also streamlining authentication and increasing overall security.

Ultimately, the question to ask yourself is, Who manages your email today, and how often are your configurations and security policies being reviewed?

So that brings us to the control nearly everyone recognizes, multi-factor authentication.

Multi-factor authentication, or MFA, is one of the most important security improvements a business can make. But just because MFA is enabled does not mean you’re good to go. The method, the policy, the device, and the session all matter. Basic MFA uses two or more factors, such as something you know, have, or are.

Common examples include SMS, one-time codes, authenticator prompts to an app on your phone, biometrics and security keys. Methods are not equal. SMS and manually entered one-time codes can be phished or socially engineered, making them less secure. Number matching or authenticator prompts improve the experience, but users can still be tricked or fatigued.

Passkeys, on the other hand, are designed to be phishing-resistant because the credentials are bound to the legitimate service rather than typed into a potentially look-alike page. Microsoft is working currently to move all of their customers towards passkeys as the default authentication method moving forward.

One scary note, something known as modern adversary in the middle phishing can capture credentials and session tokens in real time. If the attacker steals a valid session, the user may have completed MFA correctly while the attacker still gains access.

Instead of blindly requiring MFA authentication once every 90 days, we can implement intelligent conditional access policies to limit when and where someone can access your accounts or require reauthentication if something doesn’t seem quite right. Furthermore, adding an identity and threat detection response solution ensures any signs of compromise are identified and mitigated quickly.

Although MFA remains mandatory, the lesson is to strengthen the authentication method and surround it with an access policy, device trust, monitoring, and response.

So question, do you recognize what type of MFA your organization uses today?

Remember, MFA answers, can you prove who you are? While conditional access asks the broader question, giving everything we know about this request, should access be allowed right now?

So conditional access is the policy engine at the front door. It evaluates who is signing in, what they are trying to reach, where they are coming from, what device they are using, and what controls should be required.
Note, conditional access policies are not configured or implemented by default.

Some policy options. You can require MFA for targeted users, applications, or conditions. You can focus on device control, where you require a compliant or managed device for sensitive resources, or restrict access from certain types of devices.

Location and network control, you can treat a trusted office location differently from unknown networks or block countries or locations where the company does not operate.

Application control, you can apply stronger requirements to administrative portals, finance systems, or sensitive cloud apps. Session control, you can reduce persistent access, require re-authentication under defined conditions, or restrict what an unmanaged browser session can do.

Risk control, sign-in risk and user-risk policies can trigger remediation, stronger authentication, or blocking.
An example situation at Lean On Me IT, we require MFA for all of our users and implement intelligent risk controls to require re-authentication if a user’s sign-in or activity seems suspicious. For our team specifically, since we work remote, we use a cloud firewall solution.

Think of it as an office in the cloud, and we’re able to require reauthentication via MFA anytime a user is trying to access a system when not connected to that office. This is the same idea as requiring reauthentication if a user.
tries to log in outside of your physical office from home or a coffee shop.

Conditional access helps to decide whether a sign-in should succeed while the next layer tries to stop dangerous content before it ever reaches a user.

Good email security is not just a spam folder. It’s a set of policies that look for malicious senders, impersonation, unsafe links, harmful attachments, and patterns that do not match normal business communication.

Anti-spam and anti-phishing policies reduce unwanted mail and help detect spoofing, impersonation, and suspicious sender behavior. Safe attachments adds another layer by opening and analyzing attachments in an isolated environment before or during delivery, depending on how the policy is configured.

Safe Links checks URLs and can verify the destination at the time a user clicks it, which matters because a link that was safe at delivery can change later.

Lower confidence messages may be routed to junk, while higher confidence threats may be quarantined according to your policy. Policies are customized for the organization, protected users, domains, trusted senders, mail flow, dependencies, impersonation targets, quarantine workflows, and reporting all matter.

These services still need configuration and tuning. A license on the invoice is not proof that every relevant policy is enabled or optimized for your organization. When we combined identity, email, device, and data controls, the licensing discussion becomes less about more Office apps and more about a security platform.

It’s important to talk to your IT partner about your business needs and compliance requirements to ensure you have the correct licensing, configuration, and monitoring to secure your business.

Digging into that a little deeper, not all Microsoft licenses are created equal, so it’s important to consider your business needs and security and compliance requirements. Your average small business has a Microsoft Business Standard license, which includes your basic email and your desktop applications like Word, Excel, PowerPoint.Point, not Outlook.

For our clients that have these licenses, we also add some additional on top to allow for security and filtering configurations that we’ve discussed so far. We encourage each of you to consider the Microsoft Business Premium license. Business Premium is not simply Business Standard with a few extra add-ons.

It actually does a lot more, including adding identity, endpoint, email, and data protection capabilities that become the foundation of a small business security program.

Some things that Premium adds include Intune, which allows you to centrally manage and support devices, deploy policies and applications, evaluate compliance, and protect your business data across company-owned devices. You can also track the last known GPS location and remotely lock or wipe the devices if they’re lost or stolen.

Entra ID allows us to enable basic conditional access policies and stronger identity controls beyond the basic tiers. Note, a separate advanced Entra ID license is required for some of the intelligent policies that I referred to previously.
Microsoft Defender for Office 365 is included and adds safe links and safe attachment scanning, as well as enhanced phishing protection and email and collaboration protection.

You get Microsoft Purview capabilities, which allow you to classify and protect sensitive information, encrypt messages, and support data loss prevention policies and overall operational value. A common Microsoft ecosystem can connect identity, device compliance, endpoint security, email protection, and data protection, so policies reinforce one another.

So, if we deploy Business Premium and configure it properly, are we safe? Well, you’re safer, but we’re not finished yet. Technology can reduce risk, but every day your employees still make trust decisions. The challenge is that a malicious message often arrives from a familiar workflow, a familiar-looking sender or with a reason to act quickly.
So now, how many of you scanned that QR code I just had up?

Some people may have trusted it because we’re Lean On Me IT and we presented it to you. You recognized our brand and you were curious, while others avoided it because there is no context or mention of me asking you to scan it. Often, you’ll receive fake invoices, shared documents, voicemail notifications, password resets, shipping notices, benefits enrollment actions, and executive requests that look to engage your curiosity or the fact that you’re too busy working on other things to catch the minor details giving it away as a threat. The point is not to never scan a QR code or never click a link.

The point is to pause, verify context, inspect the destination when possible, and use a known channel when the request is sensitive or unexpected. In other words, if you didn’t expect it, pick up the phone and verify. Technology helps filter some of what reaches the user, but a security awareness training helps the user make better decisions when something still gets through.

Users aren’t the enemy. They are operating in busy, interruption-heavy environments while attackers deliberately create urgency, familiarity, and confusion. Training should help people recognize patterns and know exactly what to do next.

Security awareness training should use short recurring lessons rather than one annual information dump. It should pair education with realistic phishing simulation so employees practice in a controlled setting. We want to teach simple reporting paths, one button, one mailbox, or one help desk process. Employees should know the fast reporting is rewarded.

Focus on verification behaviors, unusual payment requests, changes to banking instructions, shared document prompts, QR codes, MFA prompts, and requests for credentials.

Use results to improve training and controls at the organization level. Avoid public shaming or turning isolated mistakes into employee performance judgments. Reinforce positive behavior. Reporting suspicious messages quickly can protect the entire organization. Our security awareness training solution sends 2 short training videos a month,
as well as one fake phishing attempt. If the user falls for the phishing email, they’ll be auto-enrolled in another video educating them on what they missed. Training can reduce the chance of compromise, but if the identity is compromised, speed of detection and containment determines how much damage can occur.

Which brings us to ITDR, or Identity Threat Detection and Response. This is a layer that assumes prevention may eventually fail. It continually watches your Microsoft 365 environment for evidence that an account, session, application, mailbox behavior may have become malicious.

Traditional response often begins after a user notices sent messages, a vendor reports fraud, or a customer receives phishing from the real account. That delay gives an attacker time to create inbox rules, authorize applications, maintain sessions, or impersonate the user. A managed ITDR solution monitors for identity-focused threats such as suspicious access, session hijacking, credential theft, adversary in the middle activity, rogue applications, and malicious inbox or forwarding rules based on the service deployed. 

When suspicious activity is confirmed, response can include revoking sessions, disabling access, removing malicious rules or applications, and forcing credential remediation.

According to the provider and the configured authority.

Lean On Me IT’s managed ITDR system alerts are reviewed 24/7 by a cybersecurity team and our own support team is engaged to assist with fast containment and business follow-up to ensure that everything is clean and everyone has been notified accordingly.

ITDR complements conditional access policies that we discussed previously. Prevention tries to keep the attackers out, while ITDR looks for signs that the attacker got in or established persistence. The strongest posture is not one product. It’s a layered system that prevents, detects, contains, recovers, and improves.

So this brings us to the recap. We want a professional platform. Does the business control the identity and information? Business domain, email, centralized administration, and offboarding.

Secure authentication. Can the person prove who they are with a strong method? MFA, passkeys, Windows Hello, security keys. Context-aware access. Should this request be allowed under these conditions? Conditional access, device compliance, location A, or session controls.

Message protection: Can dangerous content be stopped before interaction? Anti-phishing, impersonation protection, link scanning, or attachment scanning? Device and data protection: Is the device trusted and is sensitive data being protected? Intune?

Defender, email encryption, DLP policies, human resilience: will the user recognize, verify, and report suspicious activity? Security awareness training and simulations, detection and response: if prevention fails, how
quickly will we know and contain it? 
Manage ITDR 24/7 investigation, session revocation, and remediation.

Security is not the finish line. It’s a managed system of controls that should evolve as the business, workforce, and threat landscape change.

As we close today, the question is whether your email identities are professionally managed, strongly authenticated, intelligently protected, monitored for compromise, and supported by employees who know how to respond. If you are unsure about any of those layers, that’s a great place for us to start. Even if you’re already a Lean On Me IT client, we’d love to get together and review your licensing.

If you don’t currently work with us, we’d love to chat and offer a free identity security assessment. Feel free to reach out to me directly with the contact information you see here. You may also safely scan this QR code for links to our website and social media accounts.

Thank you for joining.

share this article -

img Lean on an IT partner

Partner with an IT services provider you can depend on

Whether you’re looking for ongoing IT support or guidance on your next technology decision, Lean On Me IT is here to help.