C://SECURE30Email Security
The way most
attacks arrive.
Email security covers filtering, impersonation protection, domain authentication, and the staff training that decides whether a convincing message gets clicked. It is for any organisation that pays invoices or receives instructions by email, which is all of them.
THE PROBLEM
Email is still how most attacks start, because it is the one channel every organisation has to leave open.
The cost of leaving this alone is rarely one visible failure. It is the slow accumulation: the workaround that became the process, the thing only one person knows, the renewal nobody questioned.
Our starting point is always the same: establish what is actually true today, then decide what to change. Work scoped against an assumption tends to solve a problem you do not have.
- 01Nobody owns itIt sits with whoever touched it last, which is not the same as being managed.
- 02No current pictureWhat you have, what it costs, and who has access are all slightly out of date.
- 03Only handled when it breaksAttention arrives after the disruption rather than before it.
WHAT YOU GET
What the engagement covers
Scoped before it starts, so you know what is included and what is not.
- 01
Advanced filtering
Attachments and links inspected before delivery rather than after somebody opens them, including links that are harmless when the message is sent and weaponised an hour later.
- 02
Impersonation protection
Detection for messages claiming to be from your directors, your accounts team, or your suppliers, which is where the expensive attacks live.
- 03
Domain authentication
SPF, DKIM, and DMARC configured so nobody can send mail that appears to come from your domain.
- 04
Staff training
Simulated phishing with coaching afterwards, aimed at building judgement rather than at catching people out.
HOW WE WORK
Baseline, remediate, monitor, evidence
Four stages with a written output at each one. You always know which stage you are in and what comes next.
- 01Week 1
Baseline
What is configured today, measured against a recognised standard, with gaps ranked by real-world risk rather than vendor score.
- 02Weeks 2 – 6
Remediate
Gaps closed in the order that buys the most safety fastest, with each change recorded.
- 03Ongoing
Monitor
Tuned to your environment so alerts mean something, and every alert has a named owner.
- 04Quarterly
Evidence
A written report you can hand to an insurer, a customer, or your board without translating it first.
WHAT CHANGES
What you should expect
- Someone other than you owns it, with that written down.
- The current state is documented and stays documented.
- Cost is planned ahead rather than discovered at renewal.
- Decisions are made against evidence rather than assumption.
FAQ
Questions we get asked
01What is email security?
Email security covers filtering, impersonation protection, domain authentication, and the staff training that decides whether a convincing message gets clicked. It is for any organisation that pays invoices or receives instructions by email, which is all of them.
02What is business email compromise, in plain terms?
Someone gets into a mailbox, reads the conversation quietly for a while, then steps in at the right moment with a believable message, usually asking for a payment to go to a different bank account. There is no attachment and no malware, which is why a spam filter does not catch it and why the message looks completely normal. It is the most expensive email attack there is, and it is almost entirely about timing.
03How can I tell if an email asking to change bank details is genuine?
Assume it is not, and verify by phone on a number you already hold, never one from the email itself. Genuine suppliers do not mind being called. This one habit, applied without exception to every change of payment details, prevents more loss than any piece of software, and it costs nothing. It is worth writing into your finance process as a rule rather than leaving it to judgement on a busy afternoon.
04Is the spam filter in Microsoft 365 or Google Workspace enough?
It stops the obvious volume and it is genuinely decent. What it is weaker at is the targeted message: no attachment, no dubious link, written specifically for your business, sometimes sent from a supplier account that has actually been compromised. That is where the additional layers and the domain authentication records earn their cost.
05Does phishing training actually work?
Yes, when it is done as coaching rather than as a test people can fail. Click rates fall substantially in the first few months and then plateau, which is the point at which the training stops being the main control and the technical layers have to carry the rest. Anyone who tells you training alone will solve this is selling training.
06What should I do if someone on my team clicked a phishing link?
Change that person’s password and sign them out of every session immediately, then check the mailbox for forwarding rules an attacker may have added, since that is the usual first move. Then work out what else that password was used for. Do not lead with blame. The staff who report a click quickly are the reason these incidents stay small, and they stop reporting if it goes badly for them.
07Why do we get emails that look like they came from our own domain?
Because sending email claiming to be from a domain is trivial unless that domain has SPF, DKIM, and DMARC records set correctly. Those three records tell receiving servers who is allowed to send as you and what to do about anyone who is not. Most organisations have a partial set, configured years ago, doing considerably less than the owner assumes.
08How much does email security cost in New Zealand?
We quote after scoping rather than before. Anyone pricing this work without looking at your environment is guessing, and the guess is rarely in your favour. Scoping itself is quick, and we tell you what it costs before we start it.
09How long does it take to get started with email security?
A first conversation takes about half an hour and costs nothing. Scoping is usually a week or two of our time depending on the size of the environment, and we agree the delivery dates with you before anything is booked in.
10Can you deliver email security alongside our existing IT team or provider?
Yes, and it is common. We are happy to work as an extra pair of hands under your internal team, or alongside an incumbent provider on a defined piece of work. We will set out in writing where the responsibilities split, so nothing falls between us.
11Do we have to move our whole IT contract to Atlas?
No. This can be delivered as a standalone piece of work for an organisation we have never worked with before, or folded into a managed agreement if you already have one with us. Plenty of clients use us for one thing and keep everything else where it is.
12Can you support us if we are not based in Auckland?
Our team is based in Auckland and we attend sites across the wider region. Most of this work is delivered remotely, so we support organisations throughout New Zealand, and we will say up front where being on site genuinely matters.
13Who will we be dealing with when something actually happens?
Named people, not a queue. You get a lead who knows your environment and stays with it, which is the difference between explaining your business once and explaining it every time you make contact.
14What happens after it is in place?
You keep the documentation regardless, and anything registered in your name stays in your name. Whether we stay involved is your call. Some clients take it in house from there, others move it onto an ongoing agreement with us. We would rather you left cleanly than stayed because leaving was difficult.
Start with a conversation.
Tell us what you are dealing with and we will tell you whether this is the right service for it, and what it would take.
← All services