Email has become an essential means of communication for both personal as well as corporate use. From personal online subscriptions to business deals, all take place over email now.

Email has become an essential means of communication for both personal as well as corporate use. From personal online subscriptions to business deals, all take place over email now. On a platform where most of your daily communication takes place, businesses should employ Email Security Best Practices to protect information against digital threats.
Email Security refers to the set of measures that an individual or a company takes to protect its email communications platform from various cyber threats. Since email communications platforms are widely used, they are also one of the most popular targets for cyber-criminals. Cyber Adversaries can use different techniques like phishing, social engineering, or domain spoofing and brand impersonating to gain unauthorized access to your email communications.
Mimecast’s State of Email Security 2021 report found that 61% of organizations had been impacted by ransomware in 2020, and it recorded a 64% year-over-year increase in threat volume. The same report found that 79% of respondents’ companies had experienced a business disruption, financial loss or other setback in 2020 due to a lack of cyber preparedness.
Even though the number of email victims is growing, you can still secure your email system by implementing appropriate email security tools and solutions. Through implementing additional email security solutions in addition to what Google, Microsoft and other email platforms provide, your organization would have much more comprehensive protection over email communications.
Eradicating the practice of sending confidential and sensitive information as attachments via email communications will also reduce your organization’s risk exposure. Adopt a culture and practice of providing links to source documents that are controlled by access control limits such as preventing viewing, editing and downloading.
Here are some popular cyber-attacks targeting email users:
Phishing During a phishing attack, the attacker sends the user some sort of direct message, text, or even email. In this email, the attacker presents the contents of the message as useful information and acts like a trusted individual to gain the trust of the user. The attacker can then manipulate the user into disclosing sensitive information such as account credentials, credit card details, etc.
Spam Spam is an old-school technique that has grown exponentially over the years. So much so that in 2014 it was reported that almost 90% of global email was spam. Unlike phishing attacks, not all spam emails are harmful. Spam emails are sent in bulk to a large number of recipients. Spam emails are usually marketing emails sent by botnets. In all modern email services, such messages are filtered out by a spam category.
Spoofing Spoofing is said to be a serious threat. In this scenario the attacker tricks the recipient into receiving a forged email. While the user believes the email is from a trusted source, the situation is quite the opposite. Here, an attacker changes the metadata of email to bypass email services’ security checks. Ultimately, the attacker can easily impersonate someone trustworthy to take hold of any sensitive information.
Control | Attack it addresses | Where it lives | Effort for a small team |
|---|---|---|---|
SPF, DKIM and DMARC records | Spoofing of your own domain | DNS, set once and monitored | Low |
Multi-factor authentication on every mailbox | Credential theft after a phishing email succeeds | Google Workspace or Microsoft 365 admin settings | Low |
Password manager and unique passwords | Credential stuffing and password reuse | Endpoint and browser | Low |
Secure email gateway or advanced threat protection | Malware attachments, malicious links, business email compromise | Mail platform add-on or third-party service | Medium |
Encryption in transit and at rest | Interception on untrusted networks, including public WiFi | Enforced TLS, provider storage encryption | Low |
Links instead of attachments for sensitive files | Data leakage through forwarded or stolen attachments | Document sharing policy and access controls | Low |
Phishing awareness and a reporting button | Phishing, social engineering, spoofed senders | Training program and mail client | Medium |
Due to the popularity of email attacks, the market has also developed several best practices to protect user emails. You can implement simple techniques within your personal or professional environment to ensure a secure email service in the long run.
You have probably already heard of it, yet the importance of strong passwords is often overlooked. Passwords that are easy to remember and simple, such as “123456” or “123456789,” are more likely to be compromised. This is not only dangerous for your email accounts, but for all your other online accounts as well. Use a password manager (e.g. LastPass, McAfee TrueKey) to generate and manage strong passwords for your online accounts.
Two-factor authentication (2FA) adds a second check, such as a code from an authenticator app or a hardware security key, on top of your password. If a phishing email or a data breach exposes your password, an attacker still cannot sign in without that second factor. Turn it on for every mailbox in Google Workspace or Microsoft 365, and prefer an authenticator app or security key over SMS codes where possible.
As mentioned previously, phishing emails are meant to trick the user into disclosing sensitive information by pretending to be a reputable service. Be very careful when you open an email. Pay attention to the URLs and attachments and do not click until you are fully aware of the contents of an email.
Although public WiFi can be a real help outdoors, that does not change the fact that they are also one of the most vulnerable access points. Traffic on public WiFi can be monitored by whoever runs the network, and a rogue hotspot can redirect you to fake login pages. Most email services now encrypt connections with TLS, but that does not protect you from a fake sign-in page, so use a trusted connection or a VPN when you handle sensitive email.
Encrypting your emails means converting them into a scrambled form. So, if a malicious user does get hold of your private information, they cannot decrypt it to understand its contents. Major business email providers encrypt messages in transit (TLS) and at rest by default, but message-level encryption, such as S/MIME or the provider’s own encrypted-message option, usually has to be configured, so make sure it is turned on for sensitive email.
Use a state-of-the-art antivirus program to scan all the contents of your emails. Most modern antivirus programs are well equipped to combat malware and will warn you if they detect anything suspicious in your emails.
An effective email environment requires more than just implementing some security measures. A reliable email security software solution can take your efforts to the next level by offering protection against modern-day attacks. Here are some honorable mentions
You do not need a separate email security product if you are a small team on Google Workspace or Microsoft 365, you have turned on MFA for every account, and you have published SPF, DKIM and DMARC for your domain. The built-in filtering from those providers is adequate for most small teams, and a gateway on top mostly adds cost and a second console to ignore.
Email security also does not solve the problem when the real gap is elsewhere. If finance can move money on the strength of an email alone, the fix is a call-back procedure for payment changes, not a better spam filter. If staff share customer data by forwarding spreadsheets, the fix is access-controlled document links.
Revisit the question when you handle customer data under contract, when a SOC 2 or ISO 27001 audit is on the horizon, when you have had a near-miss with a spoofed executive email, or when you grow past the point where an admin can review the quarantine by hand. At that stage the tools listed in the post start to earn their cost.
Cyber-criminals have no doubt made email platforms their favorite targets, but countermeasures available to combat their attacks have also advanced enough to stop their activities. Being an email service user, you or your company should take all necessary precautions to safeguard your email platforms against growing cyber-attacks. It may be challenging to secure emails, but with a little effort and the right guidance, you can communicate using emails without fear of cyberattacks.
Talk to a Cybersecurity Trusted Advisor at IRM Consulting & Advisory Check out our Marketplace
Our diverse industry experience and expertise in AI, Cybersecurity & Information Risk Management, Data Governance, Privacy and Data Protection Regulatory Compliance is endorsed by leading educational and industry certifications for the quality, value and cost-effective products and services we deliver to our clients.

