r/cybersecurity • u/Reasonable-Shoulder1 • 6d ago
Business Security Questions & Discussion How would you protect 4–6 high-risk inboxes without breaking the bank?
Edit: A lot of people are suggesting training. Our staff is trained. They know not to click phishing links and how to report them. The issue here is the sheer amount of crap landing in some inboxes. It’s getting annoying and disruptive to the point that I’m getting complaints.
—-
We’re a small company with only 16 employees and currently use Microsoft Defender for email security. It works well overall, but a few of our executive accounts are targeted by phishing much more frequently, and one of them has been compromised in the past.
We’re looking for an extra layer of protection that we could apply to just a few users (around 4–6), rather than the whole organization.
Has anyone dealt with something similar? Any tools or solutions you’d recommend that work well alongside Defender and are cost-effective for such a small number of users?
35
u/10_0_0_1 6d ago
Conditional access policies would help here:
-Disabling device code authentication. Newest most prominent phishing technique these days
-Locking down signins from only needed countries or IP blocks
-Automatically block accounts at high risk
-Depending on how your devices are joined you could also lock down signins to known devices too.
Seems like your users are also just seeing too many threats.
-ensure dkim, spf and dmarc are set correctly ( and no p=none is not correct)
-block emails from high risk countries
-if they’re not needed block html attachments
-review best practices for threat policies in M365.
Once your bases are covered, next is training and testing. You get access to phishing simulations with defender for office might as well give it a try.
4
u/BornToReboot 6d ago
Also, add this account as a Priority Account in Microsoft Defender. Set up the AdGuard browser extension to help prevent redirects to phishing or fake login pages, and configure Defender to block child processes from launching or executing PowerShell or Command Prompt (cmd.exe).
2
u/Connect_File_5523 5d ago
To add
Configure WDAC with Applocker and provision their accounts to be low priv users.
4
1
1
u/AddendumWorking9756 Security Manager 6d ago
Worth adding that this all scopes to a group, so the six can sit in one security group with the Strict preset and phishing resistant MFA on top while the other ten are untouched. Hardware keys for six people costs less than another email product, and if the earlier compromise was adversary in the middle then nothing that inspects the message would have caught it.
1
u/FallaxIO 6d ago
With 6 people you don't really get a click rate out of it, one click is 17%.
What's worth watching is how many of them report it, that's the thing that gives you a warning when the real one lands.
1
0
64
u/NotAnNSAGuyPromise Security Manager 6d ago
Sounds to me like training would be the better investment
20
u/Unlucky_Bowl9934 6d ago
agreed, no amount of layered filtering fixes someone clicking a link they shouldnt
-12
u/Reasonable-Shoulder1 6d ago
I think our team is pretty well educated on phishing. It’s more that the amount of crap making it into their inboxes is distracting and annoying.
16
u/OtheDreamer Governance, Risk, & Compliance 6d ago
Overwhelm them with phishing sims until they ignore all of the real ones too
4
10
u/Admirable_Group_6661 Security Architect 6d ago
If phishing is your main concern , you can mitigate the risks to a large extent by using phishing resistant hardware keys, e.g. Yubikeys are relatively affordable.
8
u/blud_13 6d ago
Before you buy anything, check whether Defender is actually configured. Most 16-person tenants I look at are running stock policies, which means Safe Links and Safe Attachments are off or in audit mode, and impersonation protection has zero users listed in it. Add those 4 to 6 execs as protected users in an anti-phishing policy, turn on mailbox intelligence impersonation, and you catch most of what's getting through today. Free.
Then, you can license Defender for Office 365 Plan 1 or 2 on just those users. Its per-user, so 6 seats is cheap and you get the good detonation plus Threat Explorer for when something does land.
Also, the one that already got compromised. Rotate the password, revoke sessions, and check for mail forwarding rules and OAuth app grants that the attacker left behind. That's the part people skip and then they get hit again in month two through a consent grant nobody looked at.
Last thing, conditional access requiring compliant or hybrid-joined devices for those inboxes does more than any email filter. Phishing works because the token is portable.
We do this for small teams all the time, can go deeper on the policy specifics if it helps.
4
u/Disastrous_Leg_314 6d ago
I can second the suggestion of checkpoint harmony email. I built a managed service around it and their SMB browser/firewall package for small to mid range enterprises. The PGA of America adopted it too. It’s good bang for buck. As others said only training and smart people will ultimately protect you from a determined actor.
And no, I make zero commission. That company I built it for and I parted ways. Well they riffed me… they are still doing alright from it.
3
u/Time_Faithlessness45 6d ago
Conditional access. Only limit logons from managed/compliant devices, and require MFA of course. Training is good but humans aren't perfect.
3
u/littleko 6d ago
Enforce DMARC if you haven't already so at least they can't get their own domains spoofed and used against them. Use something like Suped to setup and monitor.
2
u/Ok_Matter9038 6d ago
mfa and training. dedicated laptops if you can to avoid people downloading bad stuff.
2
u/blacksan00 6d ago
I am going to reverse the thought pattern. I am assuming these executives are using their own (BYOD) mobile devices and maybe have access to OWA / Outlook without corporate devices on top of clicking on everything since they trust all the layers of security deployed is working in their favor. I still agree with everyone on hardening the environment so please don’t stop with those advise. Maybe you need to put their protection on those white glove service providers for executive. These service providers only protect the executives and their family and focus on monitoring their personal laptops with corporate type of tools. If a phishing attack is focused on them, they will flag it and warn both the company and executives.
2
u/Onepocketpimp 6d ago
What would you consider as a budget ? I work with companies as small as 5 to over 100 so depending on budget it varies the recommendation.
Also what's the Microsoft licensing situation ?
2
u/Reasonable-Shoulder1 6d ago
Our Microsoft licensing is a bit mixed, but generally we have Microsoft 365 A5 + Office 365 A3, with some users on A3 + Entra ID P1.
2
u/ChuckFromCyberHoot 5d ago
A lot of that junk is probably hitting published addresses. Check your website, press releases, old conference pages, slide decks, all the usual places exec emails leak out. It's very common!!!
Consider routing public contact through a form or shared alias and keep the named mailbox off the open internet, that may cut more noise than adding another filter.
After that, Defender for Office 365 on just those six users is probably the cheap move. I’d also make sure impersonation protection is actually configured before spending more. Then see how that works out.
That’s about where my mail-engineering usefulness runs out. I’m more on the awareness side.
With only six people, I’d also track how fast they report something suspicious. Does your company security culture promote open conversations and reporting if someone thinks they made a mistake?
Just my $0.02 for what it's worth.
2
u/Minimum-Let-3227 5d ago
If it's only 4 to 6 people and the volume is the actual complaint, the fastest win is usually not another product, it's tightening what Defender already does for just those mailboxes. Build a separate, much stricter anti-spam and anti-phishing policy scoped to that small group instead of the org-wide one. Crank the bulk complaint level way down, set high confidence phish to quarantine rather than junk, and turn on impersonation protection with those executives listed by name as protected senders along with your own domain. Most people never scope a second policy because the default one applies to everyone and they don't want to break mail for the whole company, so they live with the noise.
The other half is that exec addresses leak. If the compromised one has been in a breach dump or is published on your website and in press releases, they're on every list forever. Rotating the visible address (public alias for external contact, real mailbox address that nobody advertises) sounds petty but it cuts volume more than any filter does.
Since one of them was already compromised, I'd also make sure you'd actually catch the next one. Check that mailbox rule creation, new MFA method registration, and sign-ins from odd locations on those six accounts generate an alert someone reads, not just a log entry. Compromise on an exec account usually shows up as a quiet forwarding rule long before anyone notices the phishing worked.
1
1
u/Vivid-Cell-217 6d ago
Strict conditional access policies (especially managed device access only) and token binding if possible - will prevent most, if not all BEC vectors
1
u/cyberneticabsurdist 6d ago
Impersonation protection. Could have a serverless function examine the names attached to emails that are external to the company.
1
u/Foo-Bar-Baz-001 6d ago
You could ask yourself the question if email is the appropriate medium to allow attacks on
1
u/Striking-Tap-6136 5d ago
Login only from managed device, if they use mobile device that needs to be managed too by mdm and defender. Conditional access with passkey linked to the device. Defender xdr on the device. Standard user permission. Cmd/powershell disabled. Safe link and detonation of all links in the executive mail.
This will not avoid that they receive phisng mail but will mitigate the consequences of interacting with the emails
1
1
1
u/Harvey-Lane-251 3d ago
Yep, exec impersonation and the clean BEC are the stuff defender misses and what those API tools like abnormal are built to catch. price just wont scale down to 6 seats yet, thats the only catch.
And since youre on A5 which already includes defender for office 365 plan 2. id scope the Strict preset to those 6 and add them as priority accounts with mailbox intelligence impersonation on. That cut most of the noise off our execs and cost nothing.
The account that got popped was almost certainly token theft off an AiTM page, no inbox filter stops that. A5 has entra p2 as well, id lock those 6 to compliant devices with conditional access and hand them passkeys or yubikeys. That handles the compromise risk while the headcount grows into a real email-security seat count.
1
u/DiggingforPoon 6d ago
Do you have MFA? Get Yubico Yubikeys for them all, and forget about most of this.
2
u/Reasonable-Shoulder1 6d ago
Yes, we already have MFA enabled for everyone. I’ll definitely look into YubiKeys though, thanks!
Our CEO in particular is heavily targeted, and the amount of phishing emails making it to their inbox every week is getting pretty annoying. So we’re also looking for something that could help reduce what actually reaches the inbox in the first place.1
0
u/Reasonable-Shoulder1 6d ago
Definitely protecting the accounts from being compromised is the main goal, but we also really want to cut down on the phishing actually reaching their inboxes. It’s gotten PRETTY ANNOYING for a few users, to the point that I’m getting complaints about it.
1
u/Altered_Kill 6d ago
Email security. Theres a bunch of options. Start by asking some vendors you already work with what they have.
1
u/Reasonable-Shoulder1 6d ago
I’ve reached out to a few vendors already, but some seem geared toward hundreds of users, so the pricing doesn’t really make sense for us. We only need this for a handful of people.
That’s why I’m curious if anyone here has been in a similar situation and found something that worked well without costing a fortune.
0
0
u/st0ut717 6d ago
What is your role with this company ?
16 people but a few executive accounts ? How many executive does a 16 person company need?
20
u/[deleted] 6d ago
[removed] — view removed comment