How to Secure Business Email: 8 Practical Steps

A convincing invoice, a supplier payment change or a Microsoft 365 sign-in alert can look entirely routine at 8.45am on a busy Monday. That is why learning how to secure business email is not simply an IT task. It is a practical way to protect cash flow, customer information, staff time and your organisation’s reputation.

For many SMEs, email remains the main route into a business. Cyber criminals use it to steal credentials, impersonate directors, introduce malware and redirect payments. The right response is not one expensive product or a single staff briefing. It is a set of sensible, layered controls that make an attack harder to deliver and easier to stop.

1. Protect every account with multi-factor authentication

A strong password is useful, but it is no longer enough on its own. Passwords can be guessed, reused from another breach or handed over through a convincing phishing page. Multi-factor authentication (MFA) adds a second check, such as an authenticator app approval or a security key, before access is granted.

MFA should be enabled for every email user, particularly directors, finance staff, administrators and anyone who can access shared mailboxes. It should also cover the administration portal for Microsoft 365 or your email platform. An attacker who gains administrator access can create forwarding rules, reset passwords and view mail across the organisation.

Authenticator apps are generally a better choice than text-message codes, which can be vulnerable to SIM-swap fraud. For higher-risk accounts, security keys offer another level of protection. The exact method depends on your workforce and devices, but the principle is straightforward: a stolen password should not be enough to enter the business.

2. Set password and access policies that people can follow

Password policies fail when they make daily work unnecessarily difficult. Requiring frequent, predictable password changes can lead staff to make only minor alterations or write passwords down. A better approach is to require long, unique passphrases, prohibit known compromised passwords and support employees with an approved password manager.

Access should also match each person’s role. A member of staff does not need administrator rights simply to use email, and former employees should not retain access to shared folders or mailboxes. Review user accounts when people join, change roles or leave, rather than treating access management as an annual exercise.

Pay close attention to shared mailboxes such as accounts@, sales@ or enquiries@. These can contain sensitive conversations and often have wider access than intended. Assign named users, remove access when it is no longer needed and avoid sharing a single login between several people. Shared credentials weaken accountability and make investigation much harder after an incident.

3. Stop impersonation with SPF, DKIM and DMARC

Email authentication helps receiving systems decide whether a message claiming to come from your domain is genuine. Three records work together here: SPF identifies authorised sending services, DKIM adds a digital signature to email, and DMARC tells recipients how to handle messages that fail those checks.

Without these controls, a criminal may be able to send messages that appear to come from your company domain. That can damage trust with customers and suppliers, even if your own mailbox has not been compromised. It can also make it easier for criminals to use your name in invoice fraud or phishing campaigns.

Configuration needs care. Many organisations send email through more than one system, including Microsoft 365, a website form, a CRM platform, marketing software or a hosted application. Leaving a legitimate sender out of an SPF or DKIM configuration can cause genuine messages to be rejected or sent to junk. Start by identifying all approved senders, monitor DMARC reports, then move gradually from monitoring to a policy that quarantines or rejects unauthorised mail.

4. Improve filtering, but do not rely on it alone

A well-configured email security service can block a large volume of spam, phishing links, malicious attachments and spoofed messages before they reach staff. It should scan incoming email, inspect web links and attachments, and provide protection against known malicious senders.

However, filtering is not infallible. Sophisticated attacks are often designed to bypass automated checks, while overly strict filtering can delay a genuine order, tender response or customer query. The right balance depends on the sensitivity of the business, the type of messages it receives and the consequences of a missed email.

Review your filtering policy periodically. Check quarantined messages, assess false positives and make sure the person responsible knows how to release legitimate mail safely. It is also sensible to apply controls to outbound email, helping prevent compromised accounts from distributing harmful content or confidential information by mistake.

5. Train staff to pause before they act

Most successful email attacks exploit urgency, authority or familiarity rather than a technical weakness. A message might appear to be from a director asking for an urgent payment, a supplier requesting updated bank details or a colleague sharing a document. Staff need clear permission to pause and verify rather than feeling pressured to act quickly.

Training works best when it is short, relevant and repeated. Show teams the warning signs they are likely to see: unusual sender addresses, unexpected attachments, a change in tone, requests to bypass process, sign-in prompts that arrive without warning, and payment details altered by email alone.

Create a simple reporting route for suspicious messages. Employees should know whether to use an email-reporting button, forward the message to IT or contact a named person. A prompt report can protect colleagues if the same campaign has reached several inboxes. Avoid blame when staff report a mistake quickly. Fast reporting gives your technical team the best chance to contain the problem.

6. Put payment verification outside email

Business email compromise is particularly damaging because it can look like normal commercial correspondence. An attacker who has access to a mailbox may watch supplier conversations, then send a believable request to amend bank details or approve a payment.

No email, however genuine it appears, should be the sole authority for changing supplier bank details or releasing an unusual payment. Use a known telephone number from your records, not a number supplied in the message, to confirm the request. For significant payments, use dual approval and document the verification.

This control is operational rather than technical, but it is one of the most effective. It acknowledges that even well-protected inboxes can receive a convincing message and gives finance teams a dependable way to challenge it.

7. Back up email and prepare for account compromise

Cloud email platforms provide strong availability, but that does not always mean you have a complete, independent backup of every message, calendar entry and file. Retention settings may not meet your business, contractual or regulatory requirements. Deleted data, malicious mailbox rules and accidental changes can still cause disruption.

Consider how quickly you would need to recover an executive mailbox, a shared customer-service inbox or a finance folder. Your backup approach should reflect that requirement and be tested, not merely purchased. Equally, keep an incident process that covers password resets, session revocation, mailbox-rule checks, affected-user communication and evidence preservation.

A written response plan reduces confusion when an incident happens. It should identify who can make technical changes, who communicates with customers or suppliers, and when specialist support, insurers or relevant authorities need to be involved.

8. Review your email security as the business changes

Email security is not a one-off project. New starters, new software, office moves, acquisitions and remote-working arrangements can all create new access routes or introduce unapproved sending systems. Regular reviews keep controls aligned with the way your organisation actually works.

At a minimum, review privileged accounts, MFA coverage, forwarding rules, shared mailbox access, email authentication records and security alerts. Check whether departing employees are removed promptly and whether new devices meet your security standards before they access business email.

For organisations without an in-house IT team, managed support can provide useful oversight. iData can help businesses assess their email environment, configure appropriate Microsoft 365 security controls and provide ongoing technical guidance alongside wider IT and connectivity support. The value is not just in applying settings, but in making sure they remain appropriate as the business grows.

The most effective email security programme is one your people can use confidently. Begin with MFA and payment verification, then build outward through authentication, filtering, training and regular review. Each layer reduces the chance that one misleading message becomes a costly business interruption.

« Back to Blog