Email Security and Phishing Defense: Defense in Depth
Email remains by far the most exploited attack vector. According to most industry analyses, over 90 percent of successful cyberattacks start with a phishing email. Despite massive investments in technical controls, increasingly sophisticated attacks still get through — which is precisely why a layered defense is necessary.
Why Email Is Still Attack Vector Number One
Email combines three factors that make it perfect for attackers:
- Universal reach — — everyone has an email address, and everyone opens email
- Trust — — people are accustomed to receiving messages from strangers and acting on them
- Low barrier — — sending a phishing email requires minimal technical skill
Modern phishing is no longer the Nigerian prince with spelling errors. Attackers use AI-generated text, stolen branding elements, and compromised legitimate accounts to send messages that are difficult to distinguish from genuine communication.
The Technical Layer
SPF, DKIM, and DMARC
These form the foundation of email security, yet surprisingly many organizations have them misconfigured or not implemented at all.
- SPF (Sender Policy Framework) — — defines which servers are authorized to send email on behalf of your domain. Without SPF, anyone can spoof your sender address.
- DKIM (DomainKeys Identified Mail) — — cryptographically signs emails so the recipient can verify the message was not altered in transit.
- DMARC (Domain-based Message Authentication, Reporting and Conformance) — — tells the recipient what to do with emails that fail SPF or DKIM checks. Without DMARC enforcement (reject/quarantine), SPF and DKIM provide limited value.
Many organizations have DMARC in monitor mode (p=none) and believe they are protected. They are not. DMARC must be set to quarantine or reject for real protection.
Microsoft Defender for Office 365
Defender for Office 365 provides advanced email protection beyond standard Exchange Online Protection:
- Safe Attachments — — attachments are detonated in a sandbox before delivery to the user
- Safe Links — — URLs in emails are checked at click time, not just at delivery
- Anti-phishing policies — — protect against impersonation of internal and external senders
- Zero-hour Auto Purge (ZAP) — — removes emails judged malicious after delivery, based on updated threat intelligence
Anti-Spoofing and Impersonation
Configure protection against sender forgery:
- Impersonation protection — — alerts or blocks emails where the sender name resembles executives or partners
- Mailbox intelligence — — learns users' communication patterns and flags deviations
- Spoof intelligence — — identifies senders attempting to impersonate your domain
The Human Layer
Technical controls alone are not enough. Some phishing attempts will always get through, and when they do, people are the last line of defense.
Security Awareness Training
Effective training is not about annual e-learning modules that employees click through on autopilot.
- Short and frequent — — monthly micro-learning sessions of 5-10 minutes are more effective than lengthy annual courses
- Contextual — — show examples of real phishing attempts relevant to the industry
- Positive approach — — train people to be vigilant, not paranoid
Phishing Simulations
Regular simulations provide measurable data on organizational resilience:
- Start with simple simulations and gradually increase difficulty
- Use results to identify departments or groups that need additional training
- Track the trend over time — click rates should decrease
- Pair simulations with just-in-time learning — show training to those who click
Reporting Culture
The most impactful thing you can do for phishing defense is to establish a strong reporting culture:
- Make it easy to report — use the Report Message button in Outlook
- Reward reporting — give positive feedback to employees who flag suspicious messages
- Never punish the victim — punishment destroys reporting willingness
- Provide feedback — tell the reporter what happened with the message
The Process Layer
SOC Response to Reported Phishing
When a user reports a suspicious email, the following should happen:
- Automated analysis — the email is automatically scanned for known indicators
- SOC triage — an analyst assesses the message within a defined SLA
- Search and purge — if the email is malicious, search all mailboxes and remove it
- User feedback — the reporter is notified of the outcome
- IOC registration — indicators from the attack are recorded for future detection
Automated Remediation
Use Sentinel playbooks to automate parts of the response:
- Automatically enrich reported emails with threat intelligence
- Automatically block malicious sender domains
- Automatically remove identified phishing emails from all mailboxes
- Automatically reset passwords for users who have submitted credentials
Feedback Loop
Ensure that lessons from phishing incidents actually improve defenses:
- Phishing emails that bypass controls should be analyzed to identify gaps in technical protections
- Simulations should be updated based on real attack techniques you observe
- Detection rules in Sentinel should be updated based on new patterns
Practical Implementation Order
If you are starting from scratch, prioritize in this order:
- SPF, DKIM, and DMARC — fundamental and free
- Defender for Office 365 Safe Attachments and Safe Links — stops most threats
- Report Message button in Outlook — activate the human defense layer
- Anti-phishing policies — impersonation and spoofing protection
- Phishing simulations — measure and improve human resilience
- Automated playbooks — scale the response
Common Mistakes
- Relying only on technical controls — — no technical solution catches everything
- Punitive training culture — — employees who fear punishment do not report
- No DMARC enforcement — — DMARC in monitor mode provides no protection
- Ignoring internal phishing — — compromised internal accounts are used to phish further inside the organization, often evading technical controls
ForSec helps organizations build layered email defense — from technical configuration of DMARC and Defender, to training programs and SOC processes for phishing response.
Need help with cybersecurity?
We help Norwegian organizations protect against digital threats. Contact us for a no-obligation conversation.
Contact us