The cheapest way into a small business is still one convincing email.
Managed inbound email security for Microsoft 365 and Google Workspace. We operate the filtering, a person reviews what it holds back, and when something gets through we own the response. Connected by authorization, not a mail-flow cutover.
Business email compromise and funds transfer fraud accounted for 58% of the cyber incidents Coalition observed across more than 100,000 policyholders in 2025. The FBI logged over $3 billion in reported BEC losses last year, averaging around $123,000 per incident. These are not breach headlines from big companies. They are wire transfers and invoice fraud at businesses this size.
Built-in filtering stops a lot of it, and for many small teams that is genuinely enough. The gap opens when a targeted message is written to get past the built-in layer, when a link only turns malicious after delivery, or when a held message sits in a quarantine nobody is watching. That gap is what this service closes, and it is what a cyber-insurance questionnaire is testing when it asks about link protection and sandboxing for inbound mail.
What we do
The service, not a datasheet
We do not hand you a console and a box of features. We operate the inbound filtering, review what it holds, and own the response when a message slips through.
Managed inbound filtering
Every inbound message is scanned before it reaches the inbox. Phishing, business email compromise, malware attachments, and account-takeover attempts are detected and held at the gateway, not after someone clicks. We operate the filtering and tune it to your tenant. You do not run a console.
Links and attachments opened before delivery
Links and attachments are detonated in isolation before the message lands, so a payload that only activates after a delay, a CAPTCHA, or a specific location is still caught before it reaches the inbox. This is exactly what a cyber-insurance questionnaire's control #15, link protection and sandboxing for inbound mail, is asking about.
Quarantine review by a person
When a message is held back, we review the quarantine. A legitimate invoice does not sit unseen for a day, and a borderline message does not get waved through on a Friday afternoon. You are not left tuning a filter you did not build.
Response when something gets through
No filter catches everything. If a malicious message reaches a user, you are not translating tool alerts into next steps. We coordinate the response: pull the message from the other inboxes it landed in, check for the inbox rules and forwarding an attacker sets to hide their tracks, and run the account-compromise checklist.
The detection platform we operate is backed by a fully managed 24/7 incident response service, included as standard, so a serious threat is being worked the moment it is flagged, not the next morning. That around-the-clock service is the floor. Obsidian Ridge is the layer on top: we know your practice, we coordinate the response end to end, and we own the response. You have one point of contact for all of it, and it is us.
The detection engine underneath is a managed platform we operate, the same way our other services run on a platform we did not build. What you are buying from us is the operation: the tuning, the quarantine review, and the response coordination. We sell the outcome, not the engine.
Why it is different
We will tell you if your current setup is already fine
A lot of small businesses on Microsoft 365 already have more email protection than they have configured. Before we sell you a layer, we check whether your built-in filtering, your DMARC enforcement, and your identity monitoring are actually turned on and doing the job. If they are, we say so, and you keep your money. That is the whole brand: we tell you when you do not need us.
A rewritten link is not a trust signal. Attackers now launder phishing links through the security gateways that rewrite them, so a link wearing a vendor's domain is not automatically safe. Our filtering analyzes where a link goes and what it does, before delivery and again at click time, instead of trusting the rewrite.
A human reviews the quarantine. The difference between a filter and a service is whether anyone reads what got held. We do, so a real invoice is not lost and a borderline message is not waved through.
We own the response. When a message gets through, you get a person on our team who coordinates the cleanup, not a ticket telling you to investigate it yourself.
How onboarding works
Minutes of authorization, not a migration
01
Free 20-minute triage
A direct call with a person on our team. We confirm your seat count, what you run today, and whether you even need a dedicated inbound layer or whether your built-in protection is already enough. If it is, we say so.
02
30-minute briefing and written proposal
Within one business day after the briefing you get a fixed-fee proposal: scope, term, onboarding, and the environments we connect to, in writing before anything is signed. Pricing is quoted per environment, not read off a public list.
03
Onboarding by authorization, not migration
We connect to Microsoft 365 or Google Workspace by authorizing an application, not by changing your MX records. There is no mail-flow cutover, no downtime, and no migration project. Inbound protection starts once the authorization is in place, which is minutes of work, not a weekend.
04
Ongoing operation
We watch the quarantine, review what the filter holds, send a monthly report you can actually read, and stay the team you call when a message looks wrong. When something gets through, we own the response.
Pricing
Quoted per environment, with a 25-seat minimum
Managed email security is quoted per environment, not read off a public price list, because the right number depends on your seat count, your term, and what you already run. You get a fixed-fee proposal after the briefing, with scope and term in writing before anything is signed.
This service carries a 25-seat minimum, so it fits practices and firms of roughly 25 users and up. If you are smaller than that, the honest next move is the block below, not this page.
For the packaged Ridge Watch tiers this reinforces, see full pricing.
Start with your built-in filtering, ITDR, and DMARC enforcement instead
A dedicated inbound layer is usually not the best first dollar for a smaller team. For a small business, the filtering already built into Microsoft 365 or Google Workspace, correctly configured, plus identity monitoring and an enforced DMARC policy, covers much of what a dedicated inbound layer would, at a fraction of the cost. That is the honest order of operations, and we would rather point you to it than sell you the wrong thing.
Managed ITDR watches for what a phish is actually after. The account takeover, the new inbox rule, the forwarding you did not set up.
DMARC enforcement stops attackers from spoofing your own domain. The cheapest high-impact email control many small businesses have not turned on.
In each case, our team operates it and handles the response.
When you grow into dedicated-filtering territory, this page will be here.
Where this fits
Where this fits in your stack
Managed Email Security fits Protected ($32 per user per month) and Complete (from $55 per user per month), reinforcing the built-in filtering in Microsoft 365 or Google Workspace. It pairs with ITDR (the identity layer) and SAT (the human layer) to cover the way most incidents actually start.
Payment-redirect and vendor-impersonation email is the front door to the office manager's inbox. Managed email security plus DMARC enforcement stops attackers spoofing your own practice domain — the cheapest high-impact control many offices have never turned on.
Closing-wire fraud begins with a convincing email. Filtering, link protection, and DMARC enforcement cut the volume of what reaches a paralegal, and the callback-verification habit SAT teaches handles the rest.
Refund-redirect and IRS-impersonation email spikes in tax season. Managed email security plus DMARC keeps look-alike and spoofed mail off preparers' screens when they are moving fastest and least likely to double-check.
Email security and DMARC show up on the questionnaire directly.
Carriers ask about email filtering, link protection, and whether DMARC is enforced on your domain. These are concrete, checkable controls — the Readiness Sprint documents which ones you run and closes the gaps before the underwriter asks.
From $1,500, delivered in 7 business days — final quote depends on scope, up to $3,500. Signed evidence pack mapped to your carrier's questionnaire — delivered, or we keep working at no additional cost until it is. We don't control underwriter decisions. We control whether you walk in with the evidence they ask for.
No. We layer inbound filtering on top of what you already run, and we do not rip Defender out. For a lot of small teams, Defender configured well plus enforced DMARC is genuinely enough, and we will tell you that on the triage call rather than sell you a layer you do not need. Managed email security is for the teams that want dedicated inbound filtering and a human reviewing the quarantine and the response.
Do I have to change my MX records or migrate mail?
No. We connect through an authorized application to Microsoft 365 or Google Workspace. Your mail flow does not change, there is no cutover window, and there is no migration. Inbound protection begins once you authorize the connection.
Is there a minimum size?
Yes, this service has a 25-seat minimum, so it fits practices and firms of roughly 25 users and up. If you are under 25 seats, a dedicated inbound layer is usually not your best first move. Start with Managed Detection and Response and enforced DMARC, and come back to this when you cross into dedicated-filtering territory.
Who handles it when a bad email gets through?
We do. We review the quarantine so held messages get a human decision, and when something malicious reaches a user we coordinate the response: remove the message from the inboxes it reached, check for attacker-created inbox rules and forwarding, and run the account-compromise checklist. The platform we operate is backed by its own fully managed 24/7 incident response service, so serious threats are being worked the moment they are flagged, but you deal only with us. You get a person on our team, not a dashboard.
What about the links that other filters just rewrite?
A rewritten link is not a trust signal. Attackers have learned to launder phishing links through the very security gateways that rewrite them, so a link wearing a security vendor's domain is not automatically safe. Our filtering analyzes where a link actually goes and what it does, before delivery and again at click time, rather than trusting the rewrite itself.
What does it cost?
It is quoted per environment after the briefing, with a fixed fee and the scope in writing. There is no public per-user price because the right number depends on your seat count, your term, and what you already run. The 25-seat minimum applies. You will have the number before you decide anything.
See where you stand in about 10 minutes, or book a briefing. Both are free and we tell you when your current setup is already fine. 30 minutes, plain language, a person on our team who picks up the phone.