Guide G15 Email security & incident response
“Make us secure” is not a scope. Name the question first.
Security requests often arrive as one broad, fear-based ask. In practice it breaks into separate, answerable questions: how endpoints are protected, how phishing and malicious mail are filtered, whether staff can recognize an attempt, and what actually happens in the first hour of a suspected incident. This guide keeps those questions distinct instead of folding all of them into one generic technology review, and treats no single email platform or vendor as the whole answer.
G15 · Entry 01 Four different security jobs
Split the fear-based ask into four bounded questions.
Identity controls like MFA and Conditional Access are one of the strongest anti-phishing measures available - see the identity and access guide if that's the missing piece.
Endpoint protection
Is an endpoint tool such as Microsoft Defender, another vendor's product, or nothing consistently deployed, updated, and reviewed across devices?
Phishing and email filtering
Whatever platform mail runs on - Microsoft 365, Google Workspace, or another - is malicious mail actually being caught, and does anyone see what gets through?
Staff awareness
Would a typical employee recognize a convincing phishing attempt, and is that ever tested rather than assumed?
Incident-response readiness
If a mailbox were compromised or a device infected tomorrow, is there a written first step, or would everyone find out together?
G15 · Entry 02 Decision matrix
Match the situation to the right first route.
| Observed need | Best first route | Useful evidence | Boundary |
|---|---|---|---|
| An account or device may be compromised right now | Existing incident, insurer, or legal process first | Timeline, affected accounts, isolation already done | Not emergency response; NexDefend does not perform IR |
| No one can say what endpoint protection is deployed | Managed IT or a bounded review | Device inventory, current tool (if any), coverage gaps | Not a certification of security |
| Phishing keeps getting through with no visibility | Managed IT | Mail-filtering configuration, recent incidents | Not a guarantee of zero successful phishing |
| Leadership wants proof staff would recognize an attempt | Bounded review or advisory | Last awareness activity (if any), role-based risk | Not a substitute for an actual test |
G15 · Entry 03 Prepare the brief
Bring these facts to a security conversation.
- Which email and endpoint platforms are actually in use today.
- Whether endpoint protection is deployed consistently, and who reviews it.
- Whether this follows an active incident or is a planned readiness review.
- What staff awareness activity, if any, has happened and when.
- Who receives and acts on a suspicious-email report today.
- Keep account credentials, recovery codes, and forwarded phishing samples out of a public enquiry.
G15 · Entry 04 What this covers
What this guide covers, and what it does not.
- In scope
- Separating endpoint posture, email filtering, staff awareness, and incident-response readiness into distinct, answerable questions.
- Out of scope
- Performing incident response, replacing legal or insurer breach obligations, or endorsing a specific security product.
- Possible next decision
- A bounded security review, ongoing managed protection, or a scoped staff-awareness project.
G15 Next
Name the security question before comparing a provider.
Compare specialist review routes for a bounded posture question, or read the identity and access guide if MFA and Conditional Access are the actual gap.