Skip to content
NexDefend IT services directory
14 destinations · EN + FR contact@nexdefend.com How listings work
Menu

Guide G15 Email security & incident response

“Make us secure” is not a scope. Name the question first.

Security requests often arrive as one broad, fear-based ask. In practice it breaks into separate, answerable questions: how endpoints are protected, how phishing and malicious mail are filtered, whether staff can recognize an attempt, and what actually happens in the first hour of a suspected incident. This guide keeps those questions distinct instead of folding all of them into one generic technology review, and treats no single email platform or vendor as the whole answer.

G15 · Entry 01 Four different security jobs

Split the fear-based ask into four bounded questions.

Identity controls like MFA and Conditional Access are one of the strongest anti-phishing measures available - see the identity and access guide if that's the missing piece.

Endpoint protection

Is an endpoint tool such as Microsoft Defender, another vendor's product, or nothing consistently deployed, updated, and reviewed across devices?

Phishing and email filtering

Whatever platform mail runs on - Microsoft 365, Google Workspace, or another - is malicious mail actually being caught, and does anyone see what gets through?

Staff awareness

Would a typical employee recognize a convincing phishing attempt, and is that ever tested rather than assumed?

Incident-response readiness

If a mailbox were compromised or a device infected tomorrow, is there a written first step, or would everyone find out together?

G15 · Entry 02 Decision matrix

Match the situation to the right first route.

Observed need Best first route Useful evidence Boundary
An account or device may be compromised right now Existing incident, insurer, or legal process first Timeline, affected accounts, isolation already done Not emergency response; NexDefend does not perform IR
No one can say what endpoint protection is deployed Managed IT or a bounded review Device inventory, current tool (if any), coverage gaps Not a certification of security
Phishing keeps getting through with no visibility Managed IT Mail-filtering configuration, recent incidents Not a guarantee of zero successful phishing
Leadership wants proof staff would recognize an attempt Bounded review or advisory Last awareness activity (if any), role-based risk Not a substitute for an actual test

G15 · Entry 03 Prepare the brief

Bring these facts to a security conversation.

  • Which email and endpoint platforms are actually in use today.
  • Whether endpoint protection is deployed consistently, and who reviews it.
  • Whether this follows an active incident or is a planned readiness review.
  • What staff awareness activity, if any, has happened and when.
  • Who receives and acts on a suspicious-email report today.
  • Keep account credentials, recovery codes, and forwarded phishing samples out of a public enquiry.

G15 · Entry 04 What this covers

What this guide covers, and what it does not.

In scope
Separating endpoint posture, email filtering, staff awareness, and incident-response readiness into distinct, answerable questions.
Out of scope
Performing incident response, replacing legal or insurer breach obligations, or endorsing a specific security product.
Possible next decision
A bounded security review, ongoing managed protection, or a scoped staff-awareness project.

G15 Next

Name the security question before comparing a provider.

Compare specialist review routes for a bounded posture question, or read the identity and access guide if MFA and Conditional Access are the actual gap.

Compare specialist review routes Read the identity & access guide →