A single convincing email can be enough to expose payroll details, redirect a supplier payment or lock your files behind ransomware. Knowing how to secure office email is not about making work harder for your team. It is about putting sensible checks in place before a rushed employee clicks a dangerous link or an old password falls into the wrong hands.
For small and medium-sized London businesses, email is often the front door to everything else: invoices, customer records, cloud storage, Teams conversations and financial systems. That makes it a prime target. The good news is that most successful email attacks rely on common gaps that can be fixed quickly with the right setup and clear staff habits.
Start with the accounts that matter most
Begin by finding out who has access to your email system, especially shared mailboxes and accounts with administrator rights. Former staff, temporary workers and suppliers should not retain access once they no longer need it. Remove unused accounts, review mailbox forwarding rules and make sure each employee uses their own login rather than a shared password.
Administrator accounts need extra care. These accounts can create users, reset passwords and change security settings, so they should be limited to the people responsible for IT. Where possible, use a separate administrator account for technical tasks and a standard account for daily email. If a daily-use account is compromised, this reduces the damage an attacker can cause.
It is also worth checking shared addresses such as accounts@, sales@ or finance@. Shared mailboxes are useful, but access should be reviewed regularly. A departing employee should be removed promptly, and nobody should forward a shared mailbox automatically to a personal email address.
How to secure office email with multi-factor authentication
Multi-factor authentication, often called MFA or two-step verification, is one of the strongest protections available. It asks for more than a password when someone signs in, usually by approving a prompt in an authenticator app, entering a code or using a security key.
This matters because passwords are stolen every day through fake sign-in pages, reused passwords and data breaches. With MFA enabled, a criminal who knows an employee’s password still has another barrier to get past. For most businesses using Microsoft 365 or Office 365, enforcing MFA for all users should be a priority, not an optional extra.
Authenticator apps are generally more secure than text-message codes, although text messages are still better than password-only access. Security keys can offer even stronger protection for directors, finance staff and IT administrators. The right choice depends on your team and working patterns, but every user should have a recovery method that is controlled and documented.
Avoid collecting employees’ recovery codes in an unprotected spreadsheet. Treat them like passwords. Store them securely, restrict access and ensure at least one trusted person can recover an account if a phone is lost or an employee is unavailable.
Use passwords that are hard to reuse and easy to manage
Long, unique passwords remain essential. A good password does not need to be a random collection of symbols that people write on sticky notes. A long passphrase made from unrelated words is often easier to remember and harder to guess.
The bigger issue is reuse. If the password for a shopping account is also used for office email, a breach elsewhere can become a business problem. A reputable password manager helps employees create and store unique passwords without relying on memory. It also reduces the temptation to send passwords by email or save them in an unprotected document.
Password changes should be handled sensibly. Forcing everyone to change passwords constantly can lead to predictable variations such as Summer2026! and Summer2027!. Change passwords immediately after suspected compromise, when a staff member leaves, or if an account has been exposed. Combined with MFA and strong unique passwords, this is far more effective than routine changes for their own sake.
Stop phishing before it reaches an inbox
Phishing emails are designed to create urgency. They may appear to come from Microsoft, a delivery company, a client, your managing director or a supplier. Some are obvious. Others use a real company logo, copy an existing email thread or impersonate a known contact after their account has been compromised.
Your email security settings should filter spam, malicious attachments and suspicious links before staff see them. Check that your Office 365 or Microsoft 365 security features are switched on and configured for your business, rather than left at basic defaults. External sender warnings can also help staff spot messages that claim to be internal but originate outside the organisation.
Technology will not catch every threat. Train staff to pause before entering passwords, opening unexpected attachments or approving an MFA request they did not initiate. They should check the sender’s full email address, not just the display name, and be cautious of last-minute changes to bank details or payment instructions.
A simple reporting process is just as important. Staff need to know who to tell when an email looks suspicious, without worrying that they are wasting somebody’s time. Quick reporting can prevent the same message reaching other colleagues and gives your IT support team a chance to block the sender or remove dangerous emails.
Protect payment and invoice conversations
Business email compromise is particularly costly because it targets trust rather than software. A fraudster may impersonate a director and request an urgent payment, or pose as a supplier and send new bank details. The email may not contain a virus or suspicious link, which is why normal anti-spam checks can miss it.
Put a clear payment verification process in place. Any request to change bank details, release a large payment or buy gift cards should be confirmed using a trusted phone number already on file. Do not use the phone number supplied in the email. Two people checking high-value payments may feel slower, but it is far quicker than trying to recover money sent to a fraudster.
Finance staff should be given extra phishing awareness training because they are frequent targets. Directors should also be careful about how much information is publicly available about their role, travel plans and supplier relationships, as criminals use this detail to make impersonation messages more believable.
Secure the technical foundations
Email protection is stronger when the rest of your IT is maintained properly. Keep laptops, desktops, phones, browsers and email applications updated. Updates fix known weaknesses that attackers can use to access devices or steal session details. Unsupported systems should be replaced or isolated, particularly if they handle business email.
Use reputable endpoint protection on every work device, including home devices if staff are allowed to access office email from them. Set screen locks, encrypt company laptops and make sure lost mobile phones can be removed from company access remotely. A secure mailbox is less useful if an unlocked laptop gives someone direct access to it.
For businesses that send email using their own domain, configure email authentication records: SPF, DKIM and DMARC. These help receiving mail systems check whether messages claiming to come from your domain are legitimate. They reduce the risk of criminals spoofing your business name and can improve the delivery of genuine messages. Setup needs care, especially if you use several systems to send newsletters, invoices or website forms, so test it before enforcing a strict policy.
Create an offboarding and incident plan
People change roles, devices are lost and mistakes happen. A short process for these moments prevents a small issue becoming a major outage. When someone leaves, disable their account, remove them from shared mailboxes and groups, revoke active sign-in sessions, collect company devices and arrange forwarding only where it is genuinely required and approved.
If an employee thinks their account has been hacked, act quickly. Reset the password, revoke active sessions, check mailbox rules and forwarding settings, review recent sign-ins and alert colleagues or customers if suspicious messages may have been sent. Do not simply reset the password and assume the problem is over. Attackers often create hidden forwarding rules so they can continue reading email after the initial login is blocked.
Keep a secure backup strategy for important business data and test that it can be restored. Email retention and backup requirements vary by business, especially where customer data, contracts or regulated information are involved. Cloud email services offer valuable protection, but they do not remove the need to decide what your business must retain and how quickly it must recover.
A practical email security check for your office
If you need a starting point, check these areas first:
- MFA is enabled for every email account, with administrator accounts protected most carefully.
- Unused users, old devices, shared mailbox access and automatic forwarding rules have been reviewed.
- Spam, phishing and malicious attachment protection is active and monitored.
- Staff know how to report suspicious messages and verify payment changes by phone.
- Devices are updated, encrypted and protected by managed security software.
- SPF, DKIM and DMARC are configured for your company domain.
Email security is not a one-off job completed after a settings change. New starters join, suppliers change details, staff work from different devices and criminals adjust their tactics. A regular review keeps the basics working and identifies gaps before they become an urgent callout.
If your office needs help checking Microsoft 365 settings, securing user accounts or responding to a suspicious email, A2z Computer Solutions can provide practical business IT support without unnecessary jargon. The right support should leave your team able to work normally, with fewer risks hiding in the inbox.