A convincing supplier invoice, a false request to change bank details, or a message that appears to come from a director can be enough to disrupt an otherwise well-run business. Learning how to secure business email is not simply an IT task. It protects cash flow, confidential information, client trust and your team’s ability to keep working when pressure is highest.
For many UK small and medium-sized businesses, Microsoft 365 has become the centre of day-to-day work. That makes email a valuable target for criminals. The good news is that the right mix of technical controls, clear processes and staff support can reduce the risk significantly without making work unnecessarily difficult.
1. Start with multi-factor authentication
A stolen password should not be enough for someone to enter an email account. Multi-factor authentication, often shortened to MFA, requires a second proof of identity, such as an approval in an authenticator app, security key or passkey.
MFA should be in place for every user, not only directors and finance staff. Attackers often compromise a junior account first, then use the trusted internal address to target colleagues. Administrator accounts deserve extra care because they can change security settings, create new users and access far more information.
Where possible, use phishing-resistant methods such as passkeys or hardware security keys for administrators and higher-risk roles. Text message codes are better than passwords alone, but they are more vulnerable to interception and social engineering than an authenticator app or security key.
There will be exceptions. A shared reception mailbox, legacy application or warehouse device may not support modern sign-in methods. Treat these as risks to resolve rather than permanent workarounds. Restrict their access, use dedicated accounts and set a clear plan to replace or reconfigure them.
2. Reduce the damage a compromised account can cause
Email security is not only about keeping attackers out. It is also about limiting what they can do if an account is compromised.
Use separate accounts for day-to-day work and administration. A person who manages Microsoft 365 should not browse the web, open attachments and read ordinary email while signed in with global administrator privileges. Give staff only the permissions they need, review privileged access regularly and remove accounts promptly when someone leaves.
Conditional access policies can add sensible checks around sign-ins. For example, you might block logins from countries where your business has no legitimate activity, require MFA when a user signs in from an unfamiliar device, or prevent access from devices that do not meet your security standards. These rules need careful testing. An overly strict policy can stop a member of staff working while travelling or dealing with an urgent client issue.
The aim is proportional control, not frustration. A managed approach can help you balance protection with the realities of remote work, contractors and operational teams working outside normal office hours.
3. Protect your domain from impersonation
Business email compromise often begins before an attacker gets into your systems. Criminals may send messages that look as though they come from your domain, hoping a customer, supplier or colleague will trust the sender.
Three domain protections work together to reduce this risk: SPF, DKIM and DMARC. SPF identifies which services are allowed to send email for your domain. DKIM adds a digital signature that receiving systems can check. DMARC tells receiving email providers what to do when a message fails those checks and provides reporting on attempted misuse.
These settings can be technical, particularly if you send email through marketing platforms, finance systems, scanners or third-party applications. Start by identifying every legitimate sending service. Then move DMARC carefully from monitoring to quarantine and, ultimately, rejection where appropriate. Going straight to a strict rejection policy without checking your senders can cause genuine messages to fail.
This is one area where a small configuration error can have a visible operational impact, but leaving it unfinished makes it easier for criminals to impersonate your business.
4. Use email filtering, but do not rely on it alone
A properly configured email protection service should scan incoming and outgoing messages for malware, malicious links, spoofing, suspicious attachments and signs of impersonation. It can also flag unusual messages that target finance teams or appear to come from senior people.
Filtering is valuable because it stops a large volume of unwanted email before it reaches staff. However, no filter catches every threat. Sophisticated phishing attacks are written for a particular recipient, may come from a compromised supplier account and may contain no suspicious attachment at all.
Review quarantine policies so genuine business messages are not held unnecessarily, especially in organisations dealing with time-sensitive orders, legal matters or clinical information. Staff should know how to report a suspected phishing message without forwarding it to colleagues or clicking links to investigate. A simple reporting route gives your IT team the chance to remove similar emails quickly across the business.
5. Make payment and data requests harder to fake
The most damaging email attacks often exploit urgency and authority rather than technical weakness. A message may ask a finance colleague to make an urgent payment, change a supplier’s bank details or send personal data to a supposed adviser.
Create a verification process that does not depend on replying to the email. For bank detail changes, payment requests and sensitive data disclosures, staff should confirm the request using a known telephone number, a trusted contact record or another independently verified channel. Never use the number or link supplied in the suspicious message.
This control can feel slower than simply acting on an email, but it is far quicker than recovering funds or explaining a breach to clients. Make the process clear enough that people can use it under pressure. A short written procedure, approval thresholds and a culture where staff are praised for checking can prevent expensive mistakes.
6. Train staff using realistic examples
Awareness training works best when it is regular, relevant and free from blame. A yearly presentation followed by a tick-box quiz is unlikely to prepare staff for a carefully targeted request that arrives during a busy afternoon.
Use examples that reflect your organisation. A logistics business may see false delivery instructions or freight documents. A professional services firm may be targeted with client data requests, password reset prompts or fake document-sharing notifications. Finance teams need to recognise invoice fraud, while senior leaders should understand the risks of impersonation and account takeover.
Short, targeted sessions and simulated phishing exercises can build useful habits. The purpose is not to catch people out. It is to give them confidence to pause, inspect a request and ask for help. Track recurring themes and adapt the training when threats change.
Human judgement remains a security control. Staff who know they will receive patient, practical support are more likely to report a concern early.
7. Secure devices and keep software current
An email account can be compromised through a device as well as a password. Laptops and mobiles used to access company email should have screen locks, encryption, supported operating systems and regular security updates. Endpoint protection helps detect malicious activity that email filtering may not see.
For Microsoft 365 users, device management can enforce basic standards before allowing access to company data. It can also help remove business information from a lost or departing employee’s device without deleting their personal files. The right level of management depends on whether devices are company-owned, personal or shared.
Do not overlook browser security. Credentials entered into a convincing fake sign-in page can give an attacker immediate access. Browser and internet protection can block known malicious sites, while a credential manager reduces the temptation to reuse passwords across work and personal services.
8. Prepare for the message that gets through
Even well-protected organisations should assume that a convincing phishing message may eventually reach an inbox. What matters next is how quickly it is recognised, contained and investigated.
Document who staff should contact, including an out-of-hours route where your business needs one. Your response plan should cover password resets, session revocation, checking email forwarding rules, reviewing sign-in activity, isolating affected devices and warning relevant contacts if fraudulent messages have been sent from a real account.
Back up the data that matters and understand what your backup actually covers. Retention in Microsoft 365 is not the same as an independent backup. Deleted emails, files and mailbox data may need recovering after accidental deletion, malicious activity or a retention-policy error. Test recovery before an incident, when there is time to fix gaps without business pressure.
Email security is an ongoing business discipline
The strongest email security is reviewed as your business changes. New staff, new suppliers, acquisitions, remote-working arrangements and additional cloud services all create fresh access and impersonation risks. Regular checks of users, permissions, domain settings and incident reports keep controls aligned with the way people really work.
For organisations without an in-house security team, this can be difficult to manage alongside clients, operations and budgets. MSnet can provide the practical protection, monitoring and staff guidance that makes security easier to manage, with real people available when something does not look right.
A useful next step is to ask one simple question at your next leadership or IT review: if a criminal sent a believable request from a trusted email address this afternoon, would our people and systems stop it? The answer will show where to focus first.

