Guides

Part of Business email: a complete practical guide for 2027

Business email security: what matters in 2027

Business email security organized by attack: account takeover, impersonation and payment diversion, and the specific setting or habit that blocks each one.

Almost nothing that goes wrong with company mail is a broken encryption algorithm. It is someone signing in as a colleague, or a supplier's invoice arriving with different bank details, or a forwarding rule quietly copying the finance inbox to an address nobody recognizes.

Those three failures have almost nothing to do with each other, and the controls that stop one do very little about the others. So this page is organized by attack rather than by feature: what actually happens, and which specific setting or habit blocks it.

A brass letter plate marked LETTERS, set into a glossy black front door beside a brass knob
Photo: Black door and letterbox, Wikimedia Commons, CC BY-SA 4.0.

What to take away

  • Account takeover, impersonation, and interception are three separate problems. Buying protection against one does not cover the others.
  • The strongest control against payment fraud is a process, not a product: verify a change of bank details on a channel the message did not arrive on.
  • After any compromise, look for what the intruder left behind. Forwarding rules and connected applications outlive a password reset.
  • Your recovery path is part of your security. A help desk that resets a password on a friendly phone call has replaced every control you bought.

Three different problems in one inbox

Account takeover means someone is using a real mailbox as its owner. Their mail is genuinely from you, passes every authentication check, and can read everything the account can read. Passwords, phishing pages that capture a second factor in real time, and reused credentials from an unrelated breach are the usual routes.

Impersonation means nobody broke into anything. A message arrives that looks like it came from a colleague or a supplier, using a similar display name, a similar domain, or a real but unrelated address. Authentication on your domain does nothing here, because the message is not claiming to be your domain.

Interception and misdirection means the message went somewhere it should not have: a mistyped recipient, an auto-complete entry for the wrong person, an oversized reply-all, or a forwarding rule set up by someone who has already been inside.

Write those three on a page before you evaluate anything. Most security features address exactly one of them, and vendors rarely say which.

Controls, matched to what they actually block

Control What it stops What it does nothing about
Second factor on every account, enforced rather than offered Reused and guessed passwords, most bulk credential attacks A convincing phishing page that relays the code while you type it
Phishing-resistant sign-in tied to the device or a hardware key Real-time credential relay An attacker already holding a valid session
Blocking legacy sign-in methods that cannot carry a second factor The quiet back door around your own policy Anything using a modern authenticated session
Domain authentication published and enforced Others sending as your exact domain Similar domains, similar display names, free mail accounts
Warning banners on mail from outside the organization Display-name impersonation of colleagues Compromise of a genuine supplier account
Restricting who may create forwarding rules to external addresses Silent exfiltration after a takeover The initial break-in
Reviewing which applications hold access to mailboxes Persistence through a connected app A human with the password

Rolling the second factor out is its own small project, and the argument you will have with colleagues about which method to require is covered well in the guidance on multi factor authentication for corporate services, which is blunt about what each method does and does not resist.

The row that surprises people is the last one on the second factor. A second factor is worth having and is not a wall. Plan for the case where it is bypassed, which is what the rest of this page is about.

The payment diversion problem

The single most expensive mail incident for a small business rarely involves your systems at all. A supplier's mailbox is compromised, their genuine invoice thread is read, and a message arrives in the middle of a real conversation, in the right tone, at the right moment, saying the bank details have changed.

No mail filter reliably catches this, because the message is real mail from a real account discussing a real invoice. What defeats it is a payment process, and the plain summary of that reasoning for small businesses is in Start with Security, which puts the control on the process rather than on the software:

  • A change of bank details is verified by voice, on a number you already held, never a number in the message.
  • The person who can change supplier bank details is not the person who approves payments.
  • New payees and changed payees get a small test payment and a confirmation before anything large moves.
  • Anyone can stop a payment to ask a question without needing a reason, and nobody is ever criticized for doing so.
  • Urgency in a message about money is treated as a reason for more checking, not less.

Write this down and give it to the people who pay invoices. It is worth more than any product decision on this page.

What an intruder leaves behind

A password reset ends the session. It does not undo the setup work. After any suspected compromise, and periodically anyway, check for:

  • Forwarding and redirect rules, at both the mailbox level and the account level. Look for rules with blank names, rules that move mail to an obscure folder, and rules that delete messages containing words like invoice or payment.
  • Delegated access, where another account has been granted permission to open the mailbox.
  • Connected applications holding a token that keeps working after the password changes. Revoking these is a separate action from resetting the password, and it is the step most often missed. The wider integration surface is worth reviewing at the same time.
  • New or altered aliases and reply-to addresses, which send the conversation somewhere else while looking normal in the sent folder.
  • Recovery details. A changed recovery phone number or address hands the account back to the intruder later.
  • Sign-in history for other accounts using the same password.

The order matters. Revoke sessions and application access, then reset the password, then remove the rules, then re-enable the account. Reversing that order gives the intruder a chance to re-establish everything.

The controls people wish they had set first

Some settings are cheap on day one and painful to retrofit once people have habits. Set them while the estate is small, ideally as part of the initial setup sequence:

  • Enforced multi-factor authentication for every account including administrators, with no permanent exemptions.
  • Separate administrator accounts, used only for administration, never for reading mail.
  • External forwarding disabled by default and granted case by case.
  • A rule that automated systems get their own account rather than borrowing a person's, so that offboarding does not break payroll.
  • Audit logging turned on, with the retention period checked rather than assumed. On many offers, useful retention sits above the entry tier, which belongs in your budget model rather than in a surprise after an incident.
  • A written recovery procedure for the case where an administrator loses their second factor, including who is allowed to authorize it and what proof they require.

That last one is the control most often left undefined, and it is the one an attacker will use. Every technical measure on this list is only as strong as the process for bypassing it in an emergency.

Common questions

Is encryption the thing to focus on?

Rarely. Transport encryption between mail systems is now normal, and storage encryption protects against a threat most small organizations do not face. End to end encryption is worth pursuing for a specific category of message, not as a general posture, and it complicates search, filtering, and record keeping in ways worth understanding before committing.

Does a stricter spam filter solve impersonation?

It helps with the crude attempts and not the good ones. A message from a compromised supplier is ordinary mail by every measurable property. Filters reduce volume; process decides outcomes.

How much of this depends on the provider?

Less than you would expect. Enforced second factors, administrator separation, forwarding restrictions, and audit logs are widely available. What varies is which tier they sit in and how much work they are to operate, which is a reasonable thing to test while evaluating candidates and a poor thing to discover afterward.

Who should be doing this in a small company?

One named person, with a calendar reminder, and a deputy. Most of the checks above take under an hour a quarter. The failure mode is not difficulty, it is that the work belongs to nobody, which is the same reason the administration layer drifts.

More in Guides

Maintenance

Best business email software 2027: practical details

A practical 2027 guide to best business email software 2027: practical details with current definitions, decisions, checks, and review steps.

Rules

Business email comparison: a side-by-side buyer guide

A practical 2027 guide to business email comparison: a side-by-side buyer guide 2027 with current definitions, decisions, checks, and review steps.

Reviews

Business email migration: how to switch without losing data

A practical 2027 guide to business email migration: how to switch without losing data 2027 with current definitions, decisions, checks, and review steps.