The cheapest way into a small business is still one convincing email.
Managed inbound email security for Microsoft 365 and Google Workspace. We operate the filtering, a person reviews what it holds back, and when something gets through we own the response. Connected by authorization, not a mail-flow cutover.
Business email compromise and funds transfer fraud accounted for 58% of the cyber insurance claims Coalition observed across more than 100,000 policyholders in 2025. The FBI logged over $3 billion in reported BEC losses last year, averaging around $123,000 per incident. These are not breach headlines from big companies. They are wire transfers and invoice fraud at businesses this size.
Built-in filtering stops a lot of it, and for many small teams that is genuinely enough. The gap opens when a targeted message is written to get past the built-in layer, when a link only turns malicious after delivery, or when a held message sits in a quarantine nobody is watching. That gap is what this service closes, and it is what a cyber-insurance questionnaire is testing when it asks about link protection and sandboxing for inbound mail.
What we do
The service, not a datasheet
We do not hand you a console and a box of features. We operate the inbound filtering, review what it holds, and own the response when a message slips through.
Managed inbound filtering
Every inbound message is scanned before it reaches the inbox. Phishing, business email compromise, malware attachments, and account-takeover attempts are caught at the gateway, not after someone clicks. We operate the filtering and tune it to your tenant. You do not run a console.
Links and attachments opened before delivery
Links and attachments are detonated in isolation before the message lands, so a payload that only activates after a delay, a CAPTCHA, or a specific location still gets caught. This is exactly what a cyber-insurance questionnaire's control #15, link protection and sandboxing for inbound mail, is asking about.
Quarantine review by a person
When a message is held back, we review the quarantine. A legitimate invoice does not sit unseen for a day, and a borderline message does not get waved through on a Friday afternoon. You are not left tuning a filter you did not build.
Response when something gets through
No filter catches everything. If a malicious message reaches a user, you are not translating tool alerts into next steps. We coordinate the response: pull the message from the other inboxes it landed in, check for the inbox rules and forwarding an attacker sets to hide their tracks, and run the account-compromise checklist.
The detection engine underneath is a managed platform we operate, the same way our other services run on a platform we did not build. What you are buying from us is the operation: the tuning, the quarantine review, and the response coordination. We sell the outcome, not the engine.
Why it is different
We will tell you if your current setup is already fine
A lot of small businesses on Microsoft 365 already have more email protection than they have configured. Before we sell you a layer, we check whether your built-in filtering, your DMARC enforcement, and your identity monitoring are actually turned on and doing the job. If they are, we say so, and you keep your money. That is the whole brand: we tell you when you do not need us.
A rewritten link is not a trust signal. Attackers now launder phishing links through the security gateways that rewrite them, so a link wearing a vendor's domain is not automatically safe. Our filtering analyzes where a link goes and what it does, before delivery and again at click time, instead of trusting the rewrite.
A human reviews the quarantine. The difference between a filter and a service is whether anyone reads what got held. We do, so a real invoice is not lost and a borderline message is not waved through.
We own the response. When a message gets through, you get a practitioner who coordinates the cleanup, not a ticket telling you to investigate it yourself.
How onboarding works
Minutes of authorization, not a migration
01
Free 20-minute triage
A direct call with the practitioner. We confirm your seat count, what you run today, and whether you even need a dedicated inbound layer or whether your built-in protection is already enough. If it is, we say so.
02
30-minute briefing and written proposal
Within one business day after the briefing you get a fixed-fee proposal: scope, term, onboarding, and the environments we connect to, in writing before anything is signed. Pricing is quoted per environment, not read off a public list.
03
Onboarding by authorization, not migration
We connect to Microsoft 365 or Google Workspace by authorizing an application, not by changing your MX records. There is no mail-flow cutover, no downtime, and no migration project. Inbound protection starts once the authorization is in place, which is minutes of work, not a weekend.
04
Ongoing operation
We watch the quarantine, review what the filter holds, send a monthly report you can actually read, and stay the practitioner you call when a message looks wrong. When something gets through, we own the response.
Pricing
Quoted per environment, with a 25-seat minimum
Managed email security is quoted per environment, not read off a public price list, because the right number depends on your seat count, your term, and what you already run. You get a fixed-fee proposal after the briefing, with scope and term in writing before anything is signed.
This service carries a 25-seat minimum, so it fits practices and firms of roughly 25 users and up. If you are smaller than that, the honest next move is the block below, not this page.
A dedicated inbound layer is usually not the best first dollar for a smaller team. For a small business on Microsoft 365, built-in filtering plus a correctly enforced DMARC policy plus endpoint detection and response covers much of what a dedicated inbound layer would, at a fraction of the cost. That is the honest order of operations, and we would rather point you to it than sell you the wrong thing.
Managed Detection and Response catches the endpoint and account compromise that a phish is trying to reach, and a practitioner handles the response.
DMARC enforcement stops attackers from spoofing your own domain, which is the cheapest high-impact email control many small businesses have not turned on.
When you grow into dedicated-filtering territory, this page will be here.
FAQ
Questions that come up before the briefing
Do you replace Microsoft 365 Defender?
No. We layer inbound filtering on top of what you already run, and we do not rip Defender out. For a lot of small teams, Defender configured well plus enforced DMARC is genuinely enough, and we will tell you that on the triage call rather than sell you a layer you do not need. Managed email security is for the teams that want dedicated inbound filtering and a human reviewing the quarantine and the response.
Do I have to change my MX records or migrate mail?
No. We connect through an authorized application to Microsoft 365 or Google Workspace. Your mail flow does not change, there is no cutover window, and there is no migration. Inbound protection begins once you authorize the connection.
Is there a minimum size?
Yes, this service has a 25-seat minimum, so it fits practices and firms of roughly 25 users and up. If you are under 25 seats, a dedicated inbound layer is usually not your best first move. Start with Managed Detection and Response and enforced DMARC, and come back to this when you cross into dedicated-filtering territory.
Who handles it when a bad email gets through?
We do. We review the quarantine so held messages get a human decision, and when something malicious reaches a user we coordinate the response: remove the message from the inboxes it reached, check for attacker-created inbox rules and forwarding, and run the account-compromise checklist. You get a practitioner, not a dashboard.
What about the links that other filters just rewrite?
A rewritten link is not a trust signal. Attackers have learned to launder phishing links through the very security gateways that rewrite them, so a link wearing a security vendor's domain is not automatically safe. Our filtering analyzes where a link actually goes and what it does, before delivery and again at click time, rather than trusting the rewrite itself.
What does it cost?
It is quoted per environment after the briefing, with a fixed fee and the scope in writing. There is no public per-user price because the right number depends on your seat count, your term, and what you already run. The 25-seat minimum applies. You will have the number before you decide anything.