Christchurch · Dunedin · Nationwide
Email Security Services for New Zealand Businesses
Phishing, invoice fraud and impersonation all reach your people the same way. Exodesk configures the protection around your email, tunes it so genuine mail keeps flowing, and keeps it current as attackers change what they send.
Supporting New Zealand businesses since 1989
The problem
The emails that threaten your business
An invoice arrives from a supplier you pay every month. The bank details have changed, the wording looks normal, and someone in accounts pays it. The supplier never sent it, and the money is gone.
That message gets through a basic spam filter without difficulty. It carries no attachment, no malicious link and no bad spelling, so there is nothing obvious for a filter to catch and nothing obvious for a person to notice. Stopping it takes protection built for the way attacks actually arrive, which is what email security services are for.
It is not a rare problem. Phishing and credential harvesting is consistently the largest single category of cyber incident that New Zealand organisations report to the National Cyber Security Centre. In the April to June 2026 quarter it was 36 of the 110 organisation incidents handled through general triage.
Invoice and payment fraud
A real supplier or manager appears to ask for a payment, or for bank details to change. Impersonation detection reads who the message claims to be from, and a verification habit on any change to payment details catches what it misses.
Credential phishing
A sign-in page that looks like your own, reached from a link in a plausible message. Link protection checks where the link actually goes, and sign-in protection means a stolen password on its own is not enough.
Lookalike domains and spoofing
Mail that appears to come from your business, or from a domain one character different. Your domain authentication records are kept complete and enforced, and lookalike domains are flagged on arrival.
Account takeover
A genuine mailbox in your business sending attacks to your staff, clients and suppliers. Protecting the account itself is identity work rather than message filtering, so it sits with our identity threat detection and response, running alongside this.
Malicious attachments and links
A file or link that installs something once it is opened. Attachments are checked before delivery, with isolation testing where the selected protection supports it, and links are re-checked at the moment somebody clicks them.
Accidental data leakage
Information sent to the wrong recipient, usually in a hurry. Recipient warnings and sharing controls are tuned so they prompt on the risky messages rather than on all of them.
What you get
What our email security service includes
Six areas, configured and managed together as one arrangement rather than six separate products.
Filtering and threat detection
Junk, known-bad mail and bulk phishing removed before anyone sees it, with the detection tuned to the way your business communicates so genuine mail keeps arriving.
Link and attachment protection
Attachments checked before they reach a mailbox, including isolation testing where the protection we select supports it, and links checked when they are clicked rather than only when the message was sent.
Impersonation and domain protection
Messages imitating your people, your suppliers or your domain are identified and held. Domain authentication records are completed and enforced, and the DMARC reports reviewed rather than just switched on.
Quarantine and release
Held mail stays visible rather than silently discarded, and the helpdesk checks and releases anything legitimate. Recurring false positives feed back into the tuning, while every message stays subject to the same checks.
Coverage checked, not assumed
Coverage is agreed at the start and then checked, so new starters, shared and resource mailboxes and addresses set up outside the usual process are not left out. A gap is how protection quietly stops applying.
Your people and reporting
A clear way for staff to flag a message that looks wrong, and reporting that shows what was stopped. Pairs with security awareness training where a business wants it.
Microsoft 365
What Microsoft 365 already covers, and where it stops
Most of our clients run Microsoft 365, and it already does more than many businesses realise. The gap is rarely that no email security is switched on. It is that nobody can say what is.
What applies on its own
Microsoft enables built-in protection by default, and it applies Safe Links and Safe Attachments across an organisation that holds any Defender for Office 365 licences, unless a user is excluded or covered by another policy.
What depends on your setup
Impersonation protection, tuned anti-phishing policies, quarantine policies and alerting all depend on the licences you hold and the configuration someone has chosen. Defaults are built for the average customer, not for your risk.
What still needs deciding
Where the platform protection ends and a dedicated filtering layer earns its place, and which of the two is doing the work for each threat. That decision belongs to your setup rather than to a product sheet.
We also work with Google Workspace and with hosted or on-premises Exchange. The starting point is the same on any platform, which is establishing what is actually active before anything is bought.
How it works
How the service works
Four steps, in this order. Email security work goes wrong most often when protection is bought before anyone has established what the business already has.
Establish what is already switched on
We check the current state of filtering, domain authentication, quarantine policies and alerting, and show you what is active, what is licensed but unused, and where the gaps are. Most businesses have never seen this written down.
Close the gaps that matter first
The order is decided by what blocks the most risk for the least disruption, not by what is easiest to sell. Often a good part of it is already inside licences the business holds.
Choose and tune the protection layer
Where a dedicated filtering layer is warranted we select the product that fits your platform and your mail flow, then tune it. Tuning is the part that decides whether staff trust it, because protection that holds legitimate mail gets switched off.
Keep it current
New starters, new suppliers, a new sending service for invoices and a platform that changes its own defaults all move the picture. We keep the settings right as the business changes and act when something looks wrong.
Under review
What we keep under review
Email security is not a setup job. These are the things that drift, and they drift quietly.
- Coverage. Whether new mailboxes have actually been brought under the policies, because a new starter added in a hurry is the common way a gap opens up.
- Forwarding rules. A scheduled check of the mailboxes that handle invoices, because a rule that quietly copies mail elsewhere is easy to miss. Detecting and responding to an account already compromised sits with identity threat detection and response.
- Domain authentication. Records kept complete as marketing tools, accounting systems and new suppliers start sending on your behalf, and the DMARC reports read so a new sender is spotted before its mail starts failing.
- Policy exceptions. The exclusions added to get something working, which are meant to be temporary and frequently are not.
- What is getting through. The messages staff report, and what they say about where the tuning needs to change.
Cost
What affects the cost of email security
Scope drives it, which is why a per-user figure on its own tells you very little.
- How many people and mailboxes. The number of users covered, and whether shared, resource and archive mailboxes are in scope.
- What you already hold. Some protection sits inside licences a business already pays for. Establishing that first changes what actually needs buying.
- Whether a dedicated layer is warranted. A separate filtering product carries its own licence, and it is not the right answer for every business.
- The state of the starting point. Whether configuration needs putting right first, and how much of that is one-off work rather than ongoing.
- How much ongoing management. How much continuing review, tuning and reporting forms part of the arrangement.
A quote should separate the one-off work from the ongoing management, name anything charged separately, and be clear about which parts you are already paying for.
Why Exodesk
Why work with Exodesk
- We are not tied to one product. We work with several email security platforms and choose the one that fits your mail flow, your licences and your business. A vendor selling direct has one answer available.
- The management layer is the service. Buying an email security product is the easy part. What makes the difference is someone configuring it properly, tuning it as complaints and misses come in, and keeping it right months later.
- It connects to the rest of your IT. Email protection sits alongside accounts, devices and backups. We look after those too, which is why a compromised mailbox does not turn into a search for whose problem it is. See our wider cyber security services.
- Local, and here since 1989. Offices in Christchurch and Dunedin, clients throughout New Zealand, and advice that accounts for the Privacy Act rather than a different country.
- We will tell you what you do not need. If the protection you are paying for already covers a gap, the useful answer is to switch it on rather than sell you another one.
The technical detail of the records and settings behind all of this sits in our guide to email security best practices, if you want to see what the work involves before talking to anyone.
Questions
Email security questions
What are email security services?
Email security services are the protection put around a business email system, together with the work of keeping it effective. That means filtering and threat detection, link and attachment protection, defences against impersonation and misuse of your domain, a quarantine people can actually work with, and coverage that is agreed and then checked rather than assumed. The products are only part of it. The service is having someone configure them for your business, tune them as real mail flows through, and keep them right as things change.
Is Microsoft 365 email security enough on its own?
Sometimes. Microsoft enables built-in protection by default, and it applies Safe Links and Safe Attachments across an organisation that holds any Defender for Office 365 licences, unless a user is excluded or covered by another policy. What is available beyond that depends on the licences you hold and how the tenant has been configured. The honest answer for any given business comes from establishing what is currently active and where the gaps are, rather than assuming either that nothing is switched on or that everything is.
Which email security product do you use?
We are not tied to a single product. Several platforms do this well, and they differ in how they connect to your mail flow, what they cost, and how much tuning they need. The right choice depends on your email platform, the licences you already hold, how your business sends and receives mail, and whether the protection needs to sit in front of your mail or work inside the platform. We make that recommendation after looking at the setup, not before.
How much do email security services cost?
It depends on how many people and mailboxes are covered, what protection you are already paying for inside existing licences, whether a dedicated filtering layer is warranted, the state of the current configuration, and how much ongoing management you want. Establishing what you already hold usually changes the answer, because some of the protection is often sitting unused inside licences the business has been paying for all along. Email security can also be bought on its own, without moving the rest of your IT to us.
What happens if a legitimate email gets blocked?
Some messages being held is normal, particularly in the first weeks after the protection goes in. What matters is what happens next. Held mail stays visible rather than being silently discarded, and your staff contact the helpdesk during business hours to have a message checked and released where appropriate. Recurring false positives feed back into the configuration so the pattern is corrected. Releasing one message does not put that sender beyond future checks, because an account that is legitimate today can be compromised tomorrow.
What happens if one of our mailboxes is compromised?
Containment goes well beyond changing the password. Microsoft treats revoking active sessions as a step separate from resetting the password, and app passwords are not revoked by a reset either. We check for unauthorised forwarding and inbox rules, which can carry on exposing or hiding messages after the credentials have been changed. Authentication methods need reviewing in case a second factor was added, and application permissions need looking at. Any mail already sent from the account needs identifying so the people who received it can be warned. That work sits with identity threat detection and response rather than with email filtering, and exactly what we act on without checking with you first is agreed when the service is scoped, so nobody is guessing during an incident.
What is business email compromise and why does it get through filters?
Business email compromise is when an attacker uses impersonation, or a business account they have already taken over, to obtain money, information or some other unauthorised action. It gets through basic filtering because there is frequently no attachment, no link and no malware to detect, only a plausible request and a changed bank account number. The message is still an attack. It simply carries nothing for a scanner to find. Stopping it needs impersonation detection that looks at who a message claims to be from and whether that matches how they normally communicate, combined with one human habit that no technology replaces: verify any change to payment details on a second channel, using contact details you already held.
Do you work with businesses outside Christchurch and Dunedin?
Yes. We have offices in Christchurch and Dunedin and clients throughout New Zealand. Email security is managed remotely in the ordinary course, so where a business is located makes very little difference to how the service runs. Being a New Zealand provider matters for a different reason, which is that the advice accounts for the Privacy Act and for how New Zealand businesses actually operate.
How is this different from security awareness training?
Email security is the technical protection that stops threats before a person has to make a decision. Training prepares people for the messages that get through. The technology should carry most of the load, because a business that depends on every employee spotting every convincing message will eventually be disappointed. The two work together, and neither substitutes for the other. We can provide both, or just the technical side if training is already handled.
How do we get started?
Tell us which email platform you are on, roughly how many people you have, and the problem you want solved. We will talk through whether the service fits and agree the next step. Where a detailed assessment is needed first, we will explain what it covers and what it costs before anything starts. Call 0800 396 337 or send the form below.
Next step
Talk to us about email security
Tell us which email platform you are on and what is worrying you. We will establish what protection is already active, show you where the gaps are, and set out what closing them involves.
It helps to know roughly how many people you have and whether you are on Microsoft 365. If you do not have those details to hand, start with what you know.
Get in touch
Discuss your email security
Tell us a little about your setup and we will be in touch to arrange a time that suits.
Prefer to talk?
Christchurch
Level 1, 85 Riccarton Road
Christchurch 8011
03 343 3124
Dunedin
Level 3, Bartons Building
2 Stafford Street, Dunedin 9016
03 479 2941