| Email security is the combined set of technology, monitoring, and staff practices that protects a business email system from threats such as phishing, fraud, spoofing, and account takeover, so attackers cannot use email to steal money, credentials, or data. |
An invoice arrives from a supplier you pay every month. The bank details have changed, the wording looks normal, and someone in accounts pays it. The supplier never sent it, and the money is gone.
Email is where attackers reach your people directly, which is why it is the starting point for most breaches that hit New Zealand businesses. One convincing message can cost a real payment, a set of logins, or a client database.
This guide explains what email security covers, the threats it stops, and how a business decides whether to handle it in-house or bring in help. If you want the technical checklist of controls to switch on, that sits in a separate guide linked below.
What Is Email Security and Why Does It Matter?
Email security is the protection of your business email system against threats that arrive by message, spanning the filtering that blocks bad mail, the authentication that proves a message is genuine, the access controls that guard the account, and the staff awareness that catches what technology misses. It matters because email touches every person in your business and carries the requests, invoices, and links attackers use to cause harm.
The stakes have risen sharply. The average worker handles well over a hundred messages a day, and hidden among the genuine ones are messages built to trick someone into paying, clicking, or handing over a password. The days of spotting a scam by its bad spelling are gone. Attackers now use AI to write clean, personalised messages that copy the tone of a real supplier or manager, so telling staff to watch for the obvious tells no longer protects you.
The shift is worth understanding, because it changes where the effort should go. A decade ago, the main defence was a spam filter and a warning to staff about dodgy links. Today the messages are polished, the requests are plausible, and the attacker may have studied your business first. Protection has moved from a single filter to a set of layers, and it needs someone to keep it current instead of setting it once and leaving it.
For an NZ business, the fallout from weak protection is concrete: financial loss, a data breach that triggers obligations under the NZ Privacy Act, and the reputational damage of a client learning their details were exposed through your inbox.
Why Is Email the Number One Attack Vector?
Email is the number one attack vector because it reaches every employee and relies on human trust rather than a technical weakness. An attacker does not need to break through a firewall when they can simply ask a person to approve a payment or click a link, and email gives them a direct, low-cost way to make that ask at scale.
This is also why protection cannot rest on staff vigilance alone. When a fake message is indistinguishable from a real one, the technology layer has to carry most of the load, and the human layer becomes the backstop for the small number of highly targeted messages that get through.
What Threats Does Email Security Protect Against?
Email security protects against six main email threats: phishing, business email compromise, spoofing, account takeover, malware and ransomware delivery, and accidental data leakage. Each targets a different weakness, and a complete defence has to account for all of them rather than the one that makes the news.
Understanding the threats is the first step in judging whether your current protection is enough. The list below describes what each attack looks like from the inside of a business, so you can recognise the pattern before it costs you.

How Do Phishing and Business Email Compromise Work?
Phishing is a message that impersonates a trusted source to trick the reader into revealing credentials or clicking a malicious link, while business email compromise (BEC) goes further by impersonating a specific manager or supplier to redirect a real payment. BEC causes the largest financial losses for NZ SMEs because it targets money directly and often carries no malicious link for a filter to catch.
A typical BEC attack is patient. The attacker watches how your business communicates, learns which supplier you pay regularly and who signs the payments off, then sends a request that matches the usual tone and timing. Often the only thing that has changed is the bank account number. The defence is a combination of technical detection and one simple human habit: verify any change to payment details through a second channel, such as a quick call to a number you already have on file.
What Are Spoofing and Account Takeover?
Spoofing is when an attacker sends mail that appears to come from your domain, damaging trust in your business and helping their messages slip past filters. Account takeover is the reverse, where an attacker gains control of one of your mailboxes and uses it to attack your staff, clients, and suppliers from a genuine, trusted address.
Account takeover is especially dangerous because the messages come from a real account, so they pass most checks. Protecting the account itself with multi-factor authentication is the single highest-impact step against this threat, which is why it appears first in almost every security recommendation.
What Does Business Email Security Actually Cover?
Business email security covers four layers working together: filtering and scanning that block bad mail on arrival, authentication that proves messages are genuine, account protection that stops stolen passwords being used, and monitoring that catches an attack in progress. No single layer is enough on its own, and a gap in any one of them is where attackers get through.
These layers do not sit in isolation. Email is one part of a wider set of defences that includes endpoint security on every device and identity and access management across your systems, because a compromised mailbox is often the first step into the rest of the network.
How Do the Protective Layers Fit Together?
The protective layers fit together as a sequence that a threat has to survive to reach a person. Filtering removes the bulk of junk and known-bad mail, authentication checks stop spoofed messages, link and attachment scanning handle the dangerous parts of anything that passes, and account controls limit the damage if a login is ever stolen.
The exact settings and records that make up each layer, and how to confirm yours are switched on, are covered in detail in our guide to email security best practices. This page stays at the level of what email security is and what it protects, so you can decide how much of it your business needs to build.
Where Does Cloud Email Fit In?
Cloud email platforms such as Microsoft 365 make collaboration easy but ship with only basic protection switched on by default. The stronger anti-phishing, link scanning, and account controls usually need to be enabled and tuned deliberately, and many businesses never complete that step.
The practical result is that moving to a modern cloud platform improves productivity but does not, by itself, make your email secure. You still have to switch on the stronger protections and tune them for how your business actually works.
What Does Weak Email Security Cost a Business?
Weak email security costs a business far more than the price of protecting it. A single successful attack can trigger a redirected payment, days of downtime, legal and recovery fees, and lasting damage to client trust, and for a small or medium NZ business without in-house security expertise, one incident is enough to do real harm.
The financial hit is only part of it. A breach that exposes client information brings obligations to notify and manage the fallout, and the reputational cost of that conversation with a customer often outlasts the direct loss. These are the outcomes proper protection exists to prevent.
It helps to put the numbers side by side. A single redirected supplier invoice can run to tens of thousands of dollars, and a few days of downtime while a compromised system is cleaned up carries its own cost in lost billable work and staff time. Against that, the controls that would have blocked the attack are often already included in software the business pays for, and simply need switching on and maintaining. The imbalance between the cost of prevention and the cost of an incident is the practical case for treating this as a priority now, not a someday task.

Should You Manage Email Security In-House or Use a Provider?
Whether to manage email security in-house or use a provider depends on your team and capacity. A business with skilled internal IT can configure and monitor these controls itself, while many SMEs find it more reliable to have a managed cyber security provider set them up and keep them enforced, because the protection erodes the moment a setting drifts or a new mailbox is left uncovered.
The deciding factor is whether every control stays switched on months after setup, once staff have changed and the platform has updated itself. Monitoring matters as much as configuration, which is why services such as managed detection and response exist to watch for an attack in progress and contain it before it spreads from the inbox to the wider business.
How Do You Strengthen Email Security in Your Business?
You strengthen email security by first understanding where you stand, then closing the biggest gaps, and finally keeping the controls current as your business and the threats change. The order matters. Some steps block far more risk for far less effort than others, so a clear starting point stops you spending money in the wrong place.
A sensible sequence for most NZ businesses looks like this:
- Confirm multi-factor authentication is on for every email account, with no exceptions for senior staff or shared mailboxes.
- Check that your domain authentication records are complete and set to enforce, not just monitor.
- Review that filtering and anti-phishing protection are enabled and tuned for your business.
- Add link scanning and attachment sandboxing to handle the dangerous parts of messages that pass the filter.
- Pair the technology with ongoing staff awareness so people can catch the rare message that slips through.
How Do You Know if Your Current Protection Is Enough?
You know your current protection is enough only when you can confirm each layer is switched on and enforced, rather than assuming the platform defaults cover you. The reliable way to find out is a structured cyber security assessment that checks your email configuration against known gaps and gives you a prioritised list of what to fix.
Technology stops most threats, but people remain the final layer, so ongoing security awareness training is part of any real check on whether your business is protected. The goal is a setup where the technology carries the load and your team knows how to handle the small number of sophisticated messages that reach them.
Get Your Email Security Reviewed by a Local Team
If you cannot say with confidence that filtering, authentication, account protection, and monitoring are all switched on across your business, the safe assumption is that there is a gap. Exodesk helps Christchurch and Dunedin businesses put strong email security in place and keep it enforced as threats evolve.
Contact us today to discuss how we can help your business or connect with us on LinkedIn to stay updated with more insights.
Frequently Asked Questions
What is email security?
Email security combines four things: filtering that blocks bad mail, authentication that proves a message is genuine, account controls that stop stolen passwords being used, and staff awareness for anything that slips past. Together these layers keep dangerous messages away from your people and limit the harm if one gets through. Most attacks are stopped before anyone has to make a judgement call.
Why is email the most common way businesses get attacked?
Email is the most common attack vector because it reaches every employee and relies on human trust rather than a technical flaw. Attackers can simply ask a person to click a link or approve a payment, and modern AI-written messages make those requests hard to spot. This reach and believability are why email security is now a baseline requirement for any business.
What is the difference between phishing and business email compromise?
Phishing is a message that impersonates a trusted source to steal credentials or plant malware, while business email compromise impersonates a specific manager or supplier to redirect a genuine payment. Business email compromise causes the largest financial losses for NZ SMEs because it targets money directly and often carries no malicious link. Both are core threats that email security is designed to stop.
Does Microsoft 365 include enough email security on its own?
Microsoft 365 includes basic email protection, but the stronger anti-phishing, link scanning, and account controls usually need to be enabled and tuned deliberately. The default settings are built for the average customer, not your specific risk, so most businesses have gaps until the platform is configured properly. The platform provides the tools, and someone still has to switch them on and maintain them.
What is account takeover and why is it dangerous?
Account takeover is when an attacker gains control of one of your mailboxes and uses it to attack staff, clients, and suppliers from a genuine, trusted address. It is dangerous because the messages come from a real account and pass most security checks. Multi-factor authentication on every account is the single most effective control against this threat.
How much does email security cost a business?
Email security costs far less than most owners expect, especially measured against the cost of a breach. Several of the strongest controls, including multi-factor authentication and authentication records, are already included in plans businesses pay for and simply need configuring. The main investment is the time to set the controls up correctly and the ongoing attention to keep them current.
Can a managed IT provider handle email security for us?
Managed IT providers can configure, monitor, and maintain email security on your behalf, which is often the most reliable approach for an SME. The provider keeps controls enforced and up to date as staff change and platforms update their defaults, so protection does not weaken over time without anyone noticing. Exodesk supports Christchurch and Dunedin businesses with setup and ongoing management.
How is email security different from staff training?
Email security is the technical protection that blocks threats automatically, while staff training prepares people to handle anything that slips through. The technology does the heavy lifting because it stops most attacks without relying on a human decision, and training covers the small number of highly targeted messages that remain. A well-protected business needs both layers working together.
How often should email security be reviewed?
Email security should be reviewed at least quarterly and after any major change such as a new email platform, a merger, or a domain change. A review confirms that filtering, authentication records, account protection, and monitoring are all still correct and enforced. Settings drift over time as staff and systems change, so regular checks prevent quiet gaps from opening.
Where can businesses in Christchurch and Dunedin get email security help?
Businesses in Christchurch, Dunedin, and across the South Island can get email security help from Exodesk, a local managed IT and security provider established in 1989. Exodesk assesses your current setup, closes the highest-impact gaps first, and keeps the controls enforced as threats change. Local support means faster response and advice suited to New Zealand businesses and their obligations.

