What it is
Filtering of inbound messages, domain authentication with SPF, DKIM and DMARC, and user awareness, all managed as one service rather than a setting at a time.
Cybersecurity
Email is still the most common way attackers reach a small business, because it does not require a technical flaw: you just have to write to someone. This page explains what actually protects a business inbox, how you stop an outsider from writing on behalf of your domain, and what OKTO Solutions puts in place for Quebec organizations.
Email protection comes down to three things done together: filtering that blocks what arrives, domain authentication with SPF, DKIM and DMARC that prevents impersonation, and employees who can spot an unusual request. Taken separately, none of the three is enough. Managed as one service, fraudulent messages that reach the inbox become rare.
In brief
Email protection comes down to three things done together: filtering that blocks what arrives, domain authentication that prevents impersonation, and employees who can spot an unusual request. Taken separately, none of the three is enough.
Filtering of inbound messages, domain authentication with SPF, DKIM and DMARC, and user awareness, all managed as one service rather than a setting at a time.
Any organization that uses Microsoft 365 or Google Workspace and receives invoices, payment requests, employee files or personal information by email.
Fraudulent messages that reach the inbox become rare, no one can write in your domain’s name any more, and a change of banking information is verified before it is paid.
The context
A small business publishes its email addresses everywhere: on its site, in signatures, on LinkedIn, at the bottom of invoices. An attacker does not need to break anything to reach you. What is left is to impersonate someone you already know.
Three families of attack keep coming back. Classic phishing lures an employee into entering their password on a fake Microsoft 365 page. Vendor or executive fraud asks for a bank account number to be changed on an otherwise authentic invoice. Mailbox takeover lets the attacker reply inside a real email thread, which is nearly impossible to spot with the naked eye.
What ties the three together: they do not exploit a software flaw, they exploit a work habit. An antivirus does nothing against them. You have to work on filtering, on domain identity and on people’s reflexes at the same time.
What we put in place
Protection is built in layers, and each layer catches what the previous one lets through. Here is what we set up for a client, in this order.
What it is. Messages are analyzed before they reach the mailbox: attachments, links, sender reputation, and how closely the sending domain resembles yours or a known supplier’s.
What it does. The vast majority of fraudulent messages never land in front of the employee, so they never have to decide whether to click.
What it is. SPF publicly declares which servers are allowed to send email on your behalf. DKIM signs every outgoing message. DMARC tells receiving servers what to do when the signature does not match, and returns a report.
What it does. An outsider can no longer write to your clients using your address. It is the only measure that protects people outside your organization.
What it is. A second factor is required at sign-in, and the old protocols that let attackers bypass it are turned off.
What it does. A password stolen on a fake page is no longer enough to get into the mailbox.
What it is. Redirect and auto-delete rules are inventoried, and the creation of a new rule by an account is flagged.
What it does. The first move of an attacker inside a mailbox is to create a rule to hide their tracks. We catch it right away.
What it is. A visible banner is added to messages coming from outside the organization.
What it does. An employee receiving an urgent request from the president can see at a glance that the message did not come from inside.
What it is. The OKTO vCIO module includes four phishing simulations per year, with follow-up on people who clicked and a reminder of the right reflexes.
What it does. The reflex holds over time instead of fading three weeks after a one-off training session.
Detection
A compromised mailbox does not set off an alarm. It shows up as details that no one looks at. If you recognize one of the signs below, treat it as an incident, not as a curiosity.
How it unfolds
The work happens in four steps, and nothing is tightened before it has been observed. A DMARC rule set too quickly breaks newsletters, appointment reminders and automated invoices.
Email is the front door for ransomware: our ransomware protection and our cybersecurity services cover both fronts, and secure remote work closes the accesses that sit outside the office. This service is delivered across Quebec, from our office in Trois-Rivières, in the Mauricie, in Montreal and around Quebec City. Further reading: SPF, DKIM and DMARC explained, phishing simulations and QR code scams.
Questions and answers
We look at your inbound filtering, the state of SPF, DKIM and DMARC, and the current settings of your accounts, and we give you a short list of what to fix, in order of priority.
We use cookies that are strictly necessary for the site to work. Only with your consent do we add measurement cookies that tell us which pages get read. Refusing costs you nothing, and you can change your mind at any time from the bottom of any page. Cookie details.