SVC-08 / Secure
Email Security & Anti-Phishing
Layered email protection - filtering, SPF/DKIM/DMARC, impersonation defence and mailbox monitoring - against the attack path behind most breaches.
What Email Security & Anti-Phishing means in practice
Email remains the front door for credential theft, invoice fraud and malware. This service hardens your mail flow and tenant, publishes proper domain authentication and watches for the telltale signs of a compromised mailbox.
Business email compromise causes some of the largest losses among small and mid-sized organisations because it targets payments and trust rather than technology. Technical controls plus verification procedures stop most of it.
Problems this removes
- Spoofed emails appearing to come from your own domain
- Invoice and wire-fraud attempts impersonating executives
- Malicious attachments reaching inboxes
- Forwarding rules secretly added to mailboxes
- No DMARC policy, so your domain can be abused freely
What you get
- Advanced filtering with attachment and link sandboxing
- SPF, DKIM and DMARC deployed and moved to enforcement
- Executive and vendor impersonation protection
- Mailbox rule and sign-in anomaly monitoring
- One-click phishing report button and triage
- Payment-change verification procedure
Typical platforms and tools
01Our delivery method for email security & anti-phishing
We treat every email security & anti-phishing engagement as a small project with a start, an end and a measurable outcome. The sequence is assess, design, implement, validate and hand over. At each step you see exactly what is changing, why and when. Documentation is created as we go and delivered at the end so your organisation is not dependent on one engineer's memory. Target: DMARC at enforcement within 90 days, phishing reports triaged inside one business hour.
02Typical clients for email security & anti-phishing
Clients who benefit most from email security & anti-phishing usually share three traits: they depend on technology to serve customers, they hold information they cannot afford to lose or leak, and they do not want to build a full IT department. Common examples include logistics & transportation, professional services and real estate organisations. The common thread is a desire for predictable operations and a partner who communicates plainly.
03How it connects with our other services
Email Security & Anti-Phishing works best as part of a coherent environment. Clients often pair it with Compliance (PIPEDA / SOC 2 readiness), 24/7 Helpdesk and Business Continuity Planning, which share the same monitoring, documentation and support desk. That integration avoids duplicate tools and finger-pointing between vendors, and it simplifies your monthly review because one report covers everything. You can start with one service and add others later, without renegotiating the whole relationship.
04Service levels and reporting
Our service targets are published: 99.9% uptime for managed services, 15-minute response on priority incidents and 24/7 monitoring coverage. Targets are goals backed by process, escalation and reporting rather than guarantees of outcome, and we review performance with you monthly. For email security & anti-phishing, reporting includes the metrics that matter to the business, with plain-language commentary instead of raw dashboards.
05Starting prices
As a guide, email security & anti-phishing is priced as a defined project from $2,500 or as part of a managed plan of $89 to $199 per user per month. vCIO retainers start from $1,500 per month and security assessments from $1,900. A 10% launch discount applies, 5% GST is added, and there is no lock-in. Call (604) 632-4959 or email info@SAZ.ca for a free 30-minute consultation and a fixed quote.
06Handling your data responsibly
Access to your systems is controlled: named engineers, individual accounts, multi-factor authentication and an audit trail. We document where email security & anti-phishing data is stored, who can reach it and how it is retained or deleted. Our practices are designed with PIPEDA and BC PIPA in mind, and we align vendor selections with SOC 2-aligned providers wherever possible.
07Getting started
Starting is straightforward. Book a free 30-minute consultation, share a high-level description of your environment, and we will propose a path. Within a few days you receive a written scope and fixed quote. If you proceed, we collect access, schedule the first work window and introduce your named senior contact. Because there is no lock-in, we expect to earn continued work through results.
Frequently asked questions
Which tools and platforms do you use for email security & anti-phishing?
Typical platforms include Microsoft Defender for Office 365, Google Workspace security, DMARC reporting, Entra ID and Third-party mail filtering. We choose mainstream, supported technology that fits your existing licences and that you can keep if you change providers.
Can email security & anti-phishing be combined with our internal IT team?
Yes. We regularly deliver email security & anti-phishing alongside in-house staff through our co-managed model, with responsibilities documented so there is no overlap or gap.
What is included in Email Security & Anti-Phishing?
Core deliverables include advanced filtering with attachment and link sandboxing, together with documentation, a hand-over session and reporting. Exact scope is confirmed in a written, fixed-price proposal after a short assessment.
Do we need to sign a long-term contract?
No. After onboarding the service is month to month with no lock-in, and you retain ownership of your documentation, configurations and data.
How much does email security & anti-phishing cost?
Projects start from $2,500 and managed plans from $89 to $199 per user per month. vCIO retainers begin at $1,500 per month and security assessments at $1,900. A 10% launch discount applies and GST of 5% is added.