Back to blog
6 minKim Ytredal

Email Security and Phishing Defense: Defense in Depth

EmailPhishingSecurity

Email remains by far the most exploited attack vector. According to most industry analyses, over 90 percent of successful cyberattacks start with a phishing email. Despite massive investments in technical controls, increasingly sophisticated attacks still get through — which is precisely why a layered defense is necessary.

Why Email Is Still Attack Vector Number One

Email combines three factors that make it perfect for attackers:

  • Universal reach — — everyone has an email address, and everyone opens email
  • Trust — — people are accustomed to receiving messages from strangers and acting on them
  • Low barrier — — sending a phishing email requires minimal technical skill

Modern phishing is no longer the Nigerian prince with spelling errors. Attackers use AI-generated text, stolen branding elements, and compromised legitimate accounts to send messages that are difficult to distinguish from genuine communication.

The Technical Layer

SPF, DKIM, and DMARC

These form the foundation of email security, yet surprisingly many organizations have them misconfigured or not implemented at all.

  • SPF (Sender Policy Framework) — — defines which servers are authorized to send email on behalf of your domain. Without SPF, anyone can spoof your sender address.
  • DKIM (DomainKeys Identified Mail) — — cryptographically signs emails so the recipient can verify the message was not altered in transit.
  • DMARC (Domain-based Message Authentication, Reporting and Conformance) — — tells the recipient what to do with emails that fail SPF or DKIM checks. Without DMARC enforcement (reject/quarantine), SPF and DKIM provide limited value.

Many organizations have DMARC in monitor mode (p=none) and believe they are protected. They are not. DMARC must be set to quarantine or reject for real protection.

Microsoft Defender for Office 365

Defender for Office 365 provides advanced email protection beyond standard Exchange Online Protection:

  • Safe Attachments — — attachments are detonated in a sandbox before delivery to the user
  • Safe Links — — URLs in emails are checked at click time, not just at delivery
  • Anti-phishing policies — — protect against impersonation of internal and external senders
  • Zero-hour Auto Purge (ZAP) — — removes emails judged malicious after delivery, based on updated threat intelligence

Anti-Spoofing and Impersonation

Configure protection against sender forgery:

  • Impersonation protection — — alerts or blocks emails where the sender name resembles executives or partners
  • Mailbox intelligence — — learns users' communication patterns and flags deviations
  • Spoof intelligence — — identifies senders attempting to impersonate your domain

The Human Layer

Technical controls alone are not enough. Some phishing attempts will always get through, and when they do, people are the last line of defense.

Security Awareness Training

Effective training is not about annual e-learning modules that employees click through on autopilot.

  • Short and frequent — — monthly micro-learning sessions of 5-10 minutes are more effective than lengthy annual courses
  • Contextual — — show examples of real phishing attempts relevant to the industry
  • Positive approach — — train people to be vigilant, not paranoid

Phishing Simulations

Regular simulations provide measurable data on organizational resilience:

  • Start with simple simulations and gradually increase difficulty
  • Use results to identify departments or groups that need additional training
  • Track the trend over time — click rates should decrease
  • Pair simulations with just-in-time learning — show training to those who click

Reporting Culture

The most impactful thing you can do for phishing defense is to establish a strong reporting culture:

  • Make it easy to report — use the Report Message button in Outlook
  • Reward reporting — give positive feedback to employees who flag suspicious messages
  • Never punish the victim — punishment destroys reporting willingness
  • Provide feedback — tell the reporter what happened with the message

The Process Layer

SOC Response to Reported Phishing

When a user reports a suspicious email, the following should happen:

  • Automated analysis — the email is automatically scanned for known indicators
  • SOC triage — an analyst assesses the message within a defined SLA
  • Search and purge — if the email is malicious, search all mailboxes and remove it
  • User feedback — the reporter is notified of the outcome
  • IOC registration — indicators from the attack are recorded for future detection

Automated Remediation

Use Sentinel playbooks to automate parts of the response:

  • Automatically enrich reported emails with threat intelligence
  • Automatically block malicious sender domains
  • Automatically remove identified phishing emails from all mailboxes
  • Automatically reset passwords for users who have submitted credentials

Feedback Loop

Ensure that lessons from phishing incidents actually improve defenses:

  • Phishing emails that bypass controls should be analyzed to identify gaps in technical protections
  • Simulations should be updated based on real attack techniques you observe
  • Detection rules in Sentinel should be updated based on new patterns

Practical Implementation Order

If you are starting from scratch, prioritize in this order:

  • SPF, DKIM, and DMARC — fundamental and free
  • Defender for Office 365 Safe Attachments and Safe Links — stops most threats
  • Report Message button in Outlook — activate the human defense layer
  • Anti-phishing policies — impersonation and spoofing protection
  • Phishing simulations — measure and improve human resilience
  • Automated playbooks — scale the response

Common Mistakes

  • Relying only on technical controls — — no technical solution catches everything
  • Punitive training culture — — employees who fear punishment do not report
  • No DMARC enforcement — — DMARC in monitor mode provides no protection
  • Ignoring internal phishing — — compromised internal accounts are used to phish further inside the organization, often evading technical controls

ForSec helps organizations build layered email defense — from technical configuration of DMARC and Defender, to training programs and SOC processes for phishing response.

Need help with cybersecurity?

We help Norwegian organizations protect against digital threats. Contact us for a no-obligation conversation.

Contact us