The attack that actually empties accounts
Forget Hollywood hacking — the email that costs businesses real money says: 'Hi Sarah, it's Mike. Can you pay this invoice today? I'm in meetings.' It arrives from mike.smith.md@gmail.com, or a lookalike domain one letter off yours, or — worst — genuinely from a supplier whose mailbox was compromised, with 'updated bank details' on a real invoice. Finance teams pay because everything looks right. Impersonation protection exists for precisely this: scoring inbound mail for display-name tricks, lookalike domains and first-time senders claiming authority, and flagging or quarantining before Sarah ever sees it.
The layers, in order
Inbound: impersonation scoring and banner warnings ('this sender is external and claims to be your MD') on Microsoft 365 or dedicated filtering. Outbound — protecting your name: enforced DMARC (on SPF and DKIM) tells the world's mail servers to reject mail forging your domain, so criminals can't defraud your customers as you — most SMEs haven't done this; ours have, as standard. Process: the one non-negotiable rule — bank-detail changes verified by phone on a known number, always — which we help you make policy. Deployed inside email security, live within days.
Related: Managed IT (pillar) · Microsoft 365 · Email security · Cyber security
Frequently asked questions
We already have spam filtering — isn't that enough?
No — impersonation attacks contain no malware and pass basic filters by design. They're social attacks needing behavioural scoring, which is a distinct layer.
What is DMARC in one sentence?
A published policy that lets receiving mail servers verify mail claiming to be from your domain really is — and reject what isn't.
What if a real supplier's account is compromised?
Technology flags anomalies (new bank details, unusual sending); process catches the rest — phone verification on known numbers before any payment change. We help you install both.