HomeServicesEmail Security

Email Security Services for Small and Mid-Sized Businesses

Phishing is the usual first step in an attack on a small business, and the messages that work no longer look like spam: a vendor's real mailbox asking for payment to a new account, or a shared-file notice leading to a fake Microsoft sign-in page. A filter catches part of it; NetSys builds the rest, from the DNS records that stop spoofing to the steps we take when a mailbox is taken over.

Take the Cybersecurity Assessment
By The NetSys Group · Published · Editorial policy

The short answer

An email security gateway is a filtering layer, cloud-based today, that inspects inbound and outbound mail for phishing, malware, spoofing and impersonation before it reaches the mailbox. NetSys email security services pair that filtering (Microsoft Defender for Office 365, Barracuda or both) with DMARC enforcement, encryption, business email compromise controls, phishing training and a response path for compromised mailboxes.

Closest related page: Microsoft 365 security hardening. That page hardens the whole tenant (Conditional Access, admin roles, app consent, audit logging); this page covers everything that touches mail, from the filter to the response when a mailbox is taken over.

Who email security services are for

Businesses on Microsoft 365 whose email carries money or confidential information: accounting and law firms, medical and dental practices, financial advisers and any company that pays vendors by wire. The trigger is usually a payment sent to the wrong account, a partner's mailbox sending invoices nobody wrote, or a cyber-insurance renewal asking about email security.

Many already pay for more protection than they use. Microsoft 365 Business Premium includes Defender for Office 365 Plan 1, yet a tenant can run for years with policies at baseline and user and domain impersonation protection covering no one, because those settings protect only the people and domains someone adds. We configure what you own before recommending anything new.

Audit, Monitor, Enforce, Review

We start by reading how your mail flows, with read-only access wherever it is offered: MX records and connectors, SPF, DKIM and DMARC for every domain, the outside systems that send as you, forwarding rules and the licenses you own. New policies run in a monitoring or report-only mode wherever the product offers one, so you see what they would block before they do. Enforcement follows in stages, with DMARC moving from none to quarantine to reject as the reports come back clean. Quarantine, user reports and DMARC reports are then reviewed on a set schedule.

What Our Email Security Services Cover

Email Security Gateway Filtering and Sandboxing

Most bad mail should never reach an inbox.

  • Defender for Office 365, Barracuda Email Protection or both in front of every mailbox, chosen against the licenses you own
  • Attachments opened in a sandbox before delivery, and links checked again when someone clicks
  • Quarantine reviewed by NetSys engineers, so a legitimate invoice is released and a near miss gets a closer look

Impersonation and BEC Protection

Business email compromise losses reported to the FBI passed $3 billion in 2025, second only to investment fraud.

  • Impersonation protection for the owners, finance staff and key vendors whose names can move money
  • Direct Send closed, and an alert on any new rule that forwards mail outside the company
  • A callback rule for bank-detail changes, confirmed at a phone number already on file

Email Security Protocols: SPF, DKIM and DMARC

So nobody else can send mail as your domain.

  • Every system that sends as your domain found first: Microsoft 365, invoicing, CRM, website forms and marketing tools
  • DMARC moved from none to quarantine to reject, with SPF and DKIM in place and the reports read at each step
  • Lookalike domains left to impersonation protection, because DMARC covers only the domain you own

Encryption and Outbound Data Loss Prevention

Sensitive mail protected without anyone remembering to click.

  • Microsoft Purview Message Encryption that outside recipients open with the address they already have
  • Data loss prevention rules that spot account numbers, Social Security numbers and patient identifiers, then encrypt
  • Archiving and retention set up where a regulator or a client contract requires them

Account Protection: MFA and Conditional Access

A stolen password should not open the mailbox.

  • MFA enforced through Conditional Access, with passkeys or hardware keys first for anyone who moves money
  • Legacy authentication blocked, so a bare password cannot sign in through an old protocol
  • Admin approval required before any third-party app can read mail and files

Phishing Training and User Reporting

Staff who report the lure instead of clicking it.

  • A report-phish button in Outlook, so reporting takes one click
  • Every report read by an engineer, and confirmed phishing pulled from all inboxes
  • Monthly simulations drawn from current lures, with a two-minute lesson after a click

Response to a Compromised Mailbox

Decided before the day it happens.

  • Sessions revoked, the password reset and MFA methods checked for anything the attacker added
  • Inbox rules, forwarding, app consents and admin roles reviewed and cleaned up
  • Sent mail traced, so clients and vendors who received fraudulent messages can be warned
  • If money moved: your bank asked at once to contact the receiving bank, and a complaint filed with the FBI's IC3
Why NetSys

Why businesses choose NetSys for email security

Tell us your Microsoft 365 plan, how many mailboxes and domains you run, and what prompted the question. We will tell you which protections you already own, which are off or missing, and whether a gateway is worth adding.

  • Licenses you already pay for configured first; a third-party gateway only where it earns its place
  • Defender for Office 365 and Barracuda run by engineers who manage Microsoft 365 tenants, identities and backups every day
  • DMARC taken all the way to enforcement, with every legitimate sender found first
  • Help desk seven days a week, 4 a.m. to 11 p.m. Eastern; monitoring and emergency service 24/7
  • Month to month, in business since 1998, from one office in Brooklyn
From our client work

Email Security in practice

Client names are withheld. Each card is the scope of a real NetSys engagement, as delivered.

Secure email gateway vs. Microsoft 365's built-in protection

Three layers can protect a Microsoft 365 mailbox. Every tenant has the first, many own the second but never configured it, and some add the third:

Built-in protection (EOP)Defender for Office 365Third-party gateway (Barracuda)
Comes withEvery Microsoft 365 organization with cloud mailboxes, on by defaultPlan 1 in Business Premium, Plan 2 in E5-level plans, both as add-onsA separate subscription
Where it filtersInside Microsoft 365Inside Microsoft 365, on top of the built-in layerIn front, through your MX records or connectors, or by API after delivery
Built forBroad, volume-based, known attacksZero-day malware, phishing and business email compromiseA second layer, plus outbound filtering, continuity during an outage and archiving
Links and attachmentsAnti-malware scanningFiles opened in a sandbox before delivery; links checked at the time of clickReal-time link and attachment analysis, with links rescanned after delivery
ImpersonationSpoof intelligence, but nothing for named people or lookalike domainsUp to 350 named people and 50 custom domains per policy, plus mailbox intelligenceBehavioral analysis and account takeover detection
Watch forPolicies stay at Microsoft's defaults until stricter ones are setNamed-person protection covers only the people added to the policyWith MX records pointed at it, Microsoft's Enhanced Filtering for Connectors should be on, or Microsoft 365 misreads where mail came from

As published by Microsoft and Barracuda, checked in October 2026. Microsoft's documentation now calls EOP the built-in security for all cloud mailboxes.

How email security services are priced

NetSys publishes no rate card. Email security is priced per mailbox per month, and these factors move the number:

FactorWhy it moves the price
Mailboxes and domainsEach mailbox is protected and watched; each domain needs its own SPF, DKIM and DMARC work
Microsoft licensingBusiness Premium includes Defender for Office 365 Plan 1; other plans may need it as an add-on
Layers in scopeA third-party gateway, encryption, archiving and training each add a line
Outside sendersEach invoicing, CRM or marketing system that sends as you is found, configured and tested
ComplianceHIPAA, the FTC Safeguards Rule or NY DFS rules add encryption, retention and evidence work
Managed or standaloneInside a NetSys managed agreement the work sits in the per-user fee; on its own, it is quoted after the review

Licenses such as a Defender plan or a Barracuda subscription are listed in the proposal. Agreements run month to month.

Common Questions

Email Security FAQs

What is an email security gateway?

An email security gateway is a filtering service in the mail path that inspects messages before they reach the mailbox, blocking phishing, malware, spoofed senders and impersonation. With a cloud gateway such as Barracuda, your MX records (the DNS entries that route your mail) point to the gateway, clean mail passes on to Microsoft 365, and outbound mail can be filtered too.

Do I need a secure email gateway if I use Microsoft 365?

Not always. Every Microsoft 365 organization with cloud mailboxes gets built-in filtering for spam, malware and spoofing at no extra cost, and Business Premium adds Defender for Office 365 Plan 1 with Safe Links, Safe Attachments and impersonation protection. Configure those first, then add a gateway if you want a second layer, outbound filtering, continuity during an outage or archiving from one vendor.

What is the best email security for a small business?

The best email security for a small business is the one fully configured on the licenses you already pay for, then extended where your risk calls for it. Judge any email security solution on five points: impersonation protection for whoever approves payments, sandboxing of links and attachments, DMARC at enforcement, one-click reporting for staff, and someone reviewing quarantine on a schedule.

How much do email security services cost?

NetSys prices email security per mailbox per month and publishes no rate card. The number moves with your mailboxes and domains, the Microsoft licensing you already own (Business Premium includes Defender for Office 365 Plan 1), whether a gateway, encryption, archiving or training is in scope, and how many outside systems send as you. Managed clients have it in the per-user fee.

How do you stop business email compromise?

Stop business email compromise with layers, because no single control catches it all. Enforce MFA so a stolen password is not enough, protect whoever approves payments from impersonation, take DMARC to enforcement, alert on new forwarding rules, and confirm every bank-detail change by phone at a number already on file. The FBI gives the same advice: verify payment requests in person or by phone.

What happens when an employee clicks a phishing link?

The employee reports it at once, with the report-phish button or a call to our help desk, and we take it from there. If a password was entered, we reset it, revoke every signed-in session, check MFA methods, inbox rules and forwarding, and pull the message from every other inbox. Safe Links can still block a known malicious page at the moment of the click.

What is cloud-based email security?

Cloud-based email security is filtering delivered as a service rather than from an appliance in your office, and it comes in two forms. A gateway sits in the mail path, reached through your MX records or Microsoft 365 connectors, and filters before delivery. API-based tools connect to Microsoft 365 directly and scan mail after it arrives, with no MX change. Barracuda offers both.

Email security

Find out what your mail filter is really set to do.

Send us your Microsoft 365 plan and domains. The review reads your MX, SPF, DKIM and DMARC records, checks which Defender policies are on and whom impersonation protection covers, then lists what we would change first.