Request a quote
Emergency SectorsCareers About us Blog Get in touch
NLNederlandsENEnglishESEspañolFRFrançaisTRTürkçe
Long aisle between black server racks with orange lights in a data centre

The desk and the mailbox, where it starts

Almost every incident arrives through a message somebody opens or through a device running something that should not be there. That makes these two the place where security returns most, and where most organisations already have something installed without it being set up well.

The layers

Four layers, rising in price and effect

The first two belong everywhere; the last two are a trade-off.

  • Anti-malware on the workstationThe basics, and these days usually built into the operating system. The question is not whether something is running but whether it is watched centrally and whether anybody sees that it is switched off somewhere.
  • Filtering emailMessages with an infected attachment or a link to a fake sign-in page are stopped before anybody sees them. This is the cheapest layer with the largest effect.
  • Detection on the workstation (EDR)Not only recognising known malicious software but behaviour that does not fit: a program suddenly encrypting a thousand files. This produces alerts, and alerts need somebody watching.
  • Protection around the mailbox itselfRules that notice a mailbox suddenly forwarding outside, or a sign-in from a place where nobody is. This catches what the filter misses, namely an account already taken over.
What returns most

Three things often not in place

They cost little and in most environments they are switched off.

  • Two-step verification on emailThe filter stops messages; this stops a leaked password from working. Of the two this is the measure with the largest effect and the fastest to switch on.
  • Macros off in documents from outsideA setting that can be applied centrally in minutes and removes a whole category of attacks. It snags where one department needs macros, and then the exception is the answer rather than the postponement.
  • Watching forwarding rulesOne of the first things an attacker does with a taken-over mailbox is quietly forward outside. An alert can be set on that, and it is done almost nowhere.

What belongs with this

This is the layer most incidents arrive through.

Start where it saves most

Tell us which mail environment runs and what is on the workstations. You get back which three settings already make a difference this week.

Practical IT knowledge in your inbox

New guides on management, security and the workplace, written by the people doing the work. No sales talk, and you can unsubscribe in one click.

We use your address for the newsletter only. Privacy policy.

Request a quote Call