Cyber Security & Compliance
Anti-phishing and spam
Email remains the way most attacks arrive. Filtering stops the volume; the targeted ones are designed to pass a filter and convince a person.
The technical layer
- Filtering and sandboxing on inbound mail, including link rewriting and attachment detonation
- SPF, DKIM and DMARC configured and monitored, so your domain cannot be trivially spoofed — this is also what stops your invoices landing in customers' spam
- Impersonation protection for your executive and finance addresses, which is where the expensive attacks are aimed
- External-sender marking, so a lookalike domain is visibly not internal
- Mailbox rule auditing — attackers add forwarding rules to stay hidden, and almost nobody checks
The attack that actually costs money
Bulk phishing is a filtering problem and largely solved. Business email compromise is not: a single convincing message to the person who pays invoices, referencing a real supplier and a real amount, arriving from a domain one character different from the genuine one.
No filter reliably stops that, because there is nothing technically wrong with the message. What stops it is a payment-verification process that does not rely on email, plus staff who have been shown the pattern — which is why awareness training sits alongside this rather than instead of it.
Sector note
Clubs are an attractive target for invoice fraud because they run real supplier volume through small finance teams. Practices and care providers attract credential phishing aimed at clinical systems and Medicare or payroll portals. The technical controls are the same; the training examples should not be, and ours are drawn from the sector.
Common questions
Will this stop all spam?
No, and a filter aggressive enough to try will start eating legitimate mail — including referrals, member correspondence and invoices. We tune for a balance and review it.
Related
Book a Technology Review.
One to two hours onsite, across support, cyber posture, backup and recovery, infrastructure, Microsoft 365 and where the organisation is heading. You receive a written findings report within five days — prioritised risks, quick wins and gaps, in writing.
$1,500 including GST. Credited in full against your engagement if you proceed.
The report is yours to keep regardless of what you decide to do next.
The 90-day guarantee. Give us 90 days. If you're not satisfied with our service in that time, cancel and we'll refund our fees. You keep the audit, the report and every improvement we've made. Third-party hardware, licences and subscriptions purchased on your behalf are excluded. Full terms
