A convincing fake invoice can arrive at 09:12, be approved before lunch and send money to the wrong account by 14:00. That is why learning how to protect business email is not just an IT task. For a small business, email is where orders, customer details, supplier payments and password reset links often pass every day.
Attackers do not always need to break into a server. They usually look for the easiest route: a reused password, a rushed member of staff, an unpatched laptop or a supplier email account that has already been compromised. The right protection is a set of practical layers. If one control fails, another should stop a minor mistake becoming a serious incident.
How to protect business email with the right foundations
Start by identifying who has access to each mailbox, from where and for what reason. It is common to find old accounts belonging to former staff, shared inbox passwords, or administrator access granted far more widely than necessary. These are straightforward problems to fix, and they reduce your exposure immediately.
Every user should have their own account. Shared addresses such as accounts@ or support@ are useful, but staff should access them through their individual login where possible. That gives you an audit trail and means one leaver does not require a password change that locks everyone else out.
Use strong, unique passwords stored in a reputable password manager. The aim is not to make people memorise complicated strings. It is to stop one stolen password from opening email, accounting software, cloud storage and every other business system. A long generated password is usually safer and easier to manage than a short password changed regularly.
Multi-factor authentication should be enabled for every mailbox, especially for directors, finance staff and administrators. An authenticator app or hardware security key is generally safer than a text message code, as criminals can target mobile numbers through SIM-swap fraud. SMS is still better than relying on a password alone if it is the only option available.
There is a trade-off here. Additional sign-in checks can feel inconvenient, particularly on shared workshop or office devices. But recovering a compromised account is far more disruptive. Configure trusted devices carefully, keep recovery methods under business control and make sure at least two authorised people can administer the email platform.
Stop phishing before it reaches the inbox
Most business email compromises begin with phishing. The message may pretend to be Microsoft, a courier, a bank, a customer or a company director. It may ask the recipient to sign in, open an attachment, pay an invoice or change bank details. Modern phishing messages are often well written, so spelling mistakes are no longer a reliable warning sign.
Your email service should use spam and malware filtering, but filtering is not a substitute for judgement. Configure it to quarantine suspicious attachments and known malicious senders, then review the quarantine process so genuine messages are not missed for days. Businesses receiving invoices, CAD files or large customer attachments may need less aggressive filtering than a firm that rarely receives files. Tune it to the way your team actually works.
Staff need a simple reporting route. Tell them to report suspicious messages rather than merely delete them. One report can help protect the whole business if IT can block the sender, remove similar messages and check whether anybody has clicked the same link.
Give particular attention to payment requests. A request to change supplier bank details, purchase gift cards or make an urgent transfer should always be verified through a known phone number or an existing contact record. Do not reply to the email or use a number supplied in it. This one process prevents many costly business email fraud cases.
Use domain authentication properly
If you send email from your own domain, configure SPF, DKIM and DMARC. These records help receiving email systems check whether a message claiming to come from your domain is legitimate. They also reduce the chance of criminals impersonating your business to customers and suppliers.
The details matter. SPF identifies approved sending services, DKIM applies a cryptographic signature, and DMARC tells receiving systems what to do when those checks fail. Start DMARC in monitoring mode if you are unsure which systems send on your behalf, then move towards quarantine or reject once legitimate senders have been identified. A badly configured policy can block genuine email, so this is worth checking carefully rather than guessing.
Secure the devices that read your email
Email security is not limited to the mailbox. A laptop with malware, an unencrypted phone left in a taxi, or an old PC that no longer receives security updates can expose the same messages.
Keep operating systems, browsers, office software and email apps updated. Apply critical security updates promptly, particularly on devices used by finance staff or administrators. Use reputable endpoint protection and ensure that it reports problems to someone who will act on them. Protection software that nobody monitors is only part of the job.
Require screen locks on every business device and encrypt laptop drives. For phones and tablets, use mobile device management where appropriate so you can remove business data if a device is lost or a staff member leaves. Smaller teams may not need a complex management platform, but they still need a clear rule: personal devices accessing company email must have a passcode, current software and the ability to remove the account remotely.
Avoid using a single local administrator account for everyday work. Staff should use standard accounts and only gain elevated access when it is needed. This limits the damage if malware runs from an email attachment.
Control access when people join, change roles or leave
A surprising number of email security gaps are administrative. New starters need access quickly, roles change, contractors come and go, and departing staff are sometimes forgotten. Treat account management as a repeatable process, not a memory test.
When someone joins, provide only the mailboxes, folders and systems required for their role. Review access when they move department or take on finance, HR or management responsibilities. When they leave, disable access promptly, revoke active sessions and remove any authentication methods registered on personal devices. Set an out-of-office reply and forwarding arrangement only where there is a clear business reason and management approval.
Administrator accounts deserve separate handling. Keep the number low, use dedicated admin accounts rather than daily email accounts, and review their sign-in logs. If an attacker obtains admin access, they can create forwarding rules, reset passwords and hide their activity far more easily.
Watch for hidden forwarding rules and unusual sign-ins
Once criminals get into an inbox, they often create rules to forward messages elsewhere or hide replies from banks and suppliers. Check mailbox rules, delegated access and connected applications regularly. A rule that forwards all messages containing words like “invoice” or “payment” should be investigated straight away.
Review sign-in activity for impossible travel, unfamiliar locations, repeated failed logins and access from devices nobody recognises. Location data is not perfect - mobile networks and VPNs can make it misleading - but it is useful when considered alongside the user, device and timing.
Set alerts for high-risk changes, including new forwarding rules, new administrator accounts, multi-factor authentication changes and large numbers of failed sign-ins. The faster a suspicious change is spotted, the less chance there is of losing data or money.
Back up email and test recovery
Many businesses assume their email provider is their backup. Providers protect their infrastructure, but that does not always mean they can recover every deleted message, mailbox setting or historical record exactly when you need it. Retention periods vary, and an attacker can delete or encrypt data within your account.
Use an independent backup that covers mailboxes, calendars, contacts and files where required. Keep copies separate from the main email platform, protect backup access with multi-factor authentication and test restoring a mailbox. A backup is only useful if you know how long recovery takes and whether the restored data is complete.
Decide how long you need to retain email based on legal, financial and operational needs. Keeping every message forever can create privacy and storage issues, while deleting records too soon can leave you without evidence during a dispute. A clear retention policy is better than unlimited storage by default.
Give staff a short, useful response plan
Training works best when it is specific and repeated. A one-off annual presentation is easily forgotten. Brief reminders based on real threats are more useful: how to spot a fake sign-in page, what to do with an unexpected attachment, and how to verify payment details.
Every employee should know what to do if they click a suspicious link or enter their password into the wrong site. The correct response is to report it immediately, not to hope nothing happened. IT can reset credentials, revoke sessions, check mailbox rules and review affected devices. Fast reporting is a success, not a failure.
If you are unsure whether your setup is properly protected, start with an access review, multi-factor authentication and a check of your domain authentication records. DCC Workshop can help Dundee businesses assess email, devices, backups and the wider systems that support them. The aim is simple: make a suspicious email an inconvenience, not the start of a business-stopping problem.
Please Login or Register