BUSINESS SECURITY
Why email security Sydney businesses rely on needs more than a spam filter
Email is still the first thing an attacker tries. Most Microsoft 365 and Google Workspace plans include basic spam and malware filtering, and that catches a lot of junk. What it does not catch is a well-crafted spear phishing message targeting your accounts team, or a spoofed email that looks like it came from your own domain.
Business Email Compromise, or BEC, is one of the most financially damaging attack types for Australian small and medium businesses. An attacker impersonates a supplier, a director, or a staff member and tricks someone into paying a fake invoice or changing bank details. Some BEC messages contain no malware attachment or suspicious link and instead rely on social engineering. Others may include malicious links or files, so both behavioural detection and technical controls matter.
Milnsbridge provides email security Sydney businesses need through our managed email security service. That includes layered filtering, policy configuration, domain protection, and ongoing management with reporting. For businesses that need stronger spoofing protection, we also offer Managed DMARC to implement and maintain SPF, DKIM, and DMARC records.
This guide covers the main email threats targeting Sydney businesses, the technical controls that stop them, and what a managed email security service actually does beyond the baseline filtering included in standard cloud mail plans.
Attackers often exploit gaps between default filtering and managed controls.
EMAIL THREAT TYPES
Four email threats Sydney businesses face right now
Phishing and spear phishing
Mass phishing casts a wide net with generic messages. Spear phishing targets specific staff members using their names, roles, and internal details gathered from LinkedIn or your website. Both aim to steal credentials through fake login pages.
Business Email Compromise
Attackers impersonate executives, suppliers, or finance staff to request urgent payments, invoice redirections, or gift card purchases. BEC messages often rely on social engineering rather than malware, so malware-focused filtering alone may not stop them.
Domain spoofing
Without DMARC enforcement, attackers can send emails that appear to come from your own domain. Your customers and partners receive messages that look legitimate, damaging your reputation and potentially redirecting payments.
Ransomware payloads
Email is one common delivery method for ransomware. Malicious attachments and links, including those sent from compromised accounts, can lead to serious disruption if a user opens them.
DOMAIN PROTECTION
SPF, DKIM, and DMARC explained for business owners
These three DNS records work together to prove that emails sent from your domain are legitimate. Without them, anyone can spoof your domain. Microsoft and Google include some baseline support, but configuration and ongoing enforcement require manual setup and monitoring.
Without managed domain protection
Default settings may log spoofing attempts but rarely block them. SPF records cover authorized senders but do not specify action on failure. DKIM signs messages but does not enforce rejection of unsigned mail. DMARC often stays in monitoring mode indefinitely with no policy applied.
With Milnsbridge Managed DMARC
We configure SPF, DKIM, and DMARC records, move the policy from monitoring to enforcement, identify all legitimate sending sources including third-party platforms, and maintain the records as your email environment changes. Reporting shows what is being blocked and what passes.
DMARC enforcement is one of the most effective steps a business can take against domain spoofing. Moving from monitoring to quarantine or reject policy requires identifying every system that sends mail on your behalf, which is where most businesses get stuck without managed support.
EMAIL SECURITY LAYERS
What a managed email security service actually includes
Default filtering in Microsoft 365 and Google Workspace catches known spam and malware. What it does not do well is detect novel BEC patterns, enforce domain protection, or provide reporting that a business owner can act on. Milnsbridge layers additional controls on top of your existing mail platform.
Layered filtering
Additional filtering policies tuned to your environment that catch phishing, malware, and risky attachments before they reach the inbox. Rules are aligned to your risk profile and adjusted as threats evolve.
Domain protection
Managed DMARC implementation including SPF and DKIM alignment, policy enforcement, and ongoing monitoring. Spoofing attempts are blocked at the receiving server before delivery.
Account protection
Email security works alongside multi-factor authentication and conditional access policies. Compromised accounts are the most common source of internal phishing and BEC attacks.
Reporting and alerting
Regular reporting on blocked threats, spoofing attempts, and policy actions. Managers can see what was caught, what was allowed, and whether exceptions need attention.
THE NUMBERS
The cost of email-based attacks on Australian businesses
6 min
Average frequency of a cybercrime report to ASD's ACSC in 2024-25 (ASD Annual Cyber Threat Report 2024-25)
59%
Share of data breaches in the first half of 2025 caused by malicious or criminal attacks (OAIC NDB statistics, Nov 2025 release)
$4.26M
Average cost of a data breach for Australian organisations in 2024 (IBM Cost of a Data Breach Report 2024)
84,700+
Total cybercrime reports to ASD's ACSC in 2024-25 (ASD Annual Cyber Threat Report 2024-25)
PRACTICAL STEPS
What Sydney businesses can do right now
Check your DMARC status
Send an email from your domain to a DMARC monitoring address or use an online checker. If you have no DMARC record or it is set to monitoring mode (p=none), your domain does not have an enforced DMARC quarantine or reject policy. Receiving services may still apply other checks, so this is not the same as saying every spoofed message will be accepted.
Enable MFA for every email user
Enable MFA for every user who signs into email. Shared mailboxes should normally be configured without direct sign-in. Service accounts should be assessed separately, with interactive sign-in removed where possible and workload identities, certificates, managed identities, or equivalent non-interactive controls used where appropriate. This follows Essential Eight guidance without assuming every non-user account can complete an MFA prompt.
Review mail forwarding rules
Attackers create hidden inbox rules that auto-forward emails to external addresses. Audit your mailboxes for unexpected forwarding rules, especially on finance and executive accounts.
Brief staff on BEC patterns
The most effective defence against BEC is staff who know the pattern. Urgent payment requests, supplier bank detail changes, and requests for gift cards should always be verified by phone using a known number.
COMMON QUESTIONS
Email security questions Sydney businesses ask
Is the email filtering in Microsoft 365 enough?
Microsoft 365 includes Exchange Online Protection and optional Defender for Office 365. These catch most known spam and malware. The gap is in BEC detection, domain spoofing enforcement, and ongoing tuning. Managed email security adds policies, monitoring, and reporting on top of what the platform provides.
What is the difference between SPF, DKIM, and DMARC?
SPF lists which servers are authorised to send mail from your domain. DKIM adds a cryptographic signature to each message. DMARC ties them together and tells receiving servers what to do when a message fails SPF or DKIM checks. All three are needed for effective domain protection.
How does email security relate to Essential Eight?
Email security supports Essential Eight implementation, but email filtering is not a standalone Essential Eight strategy. Relevant controls can include application control, patching applications, restricting administrative privileges, multi-factor authentication, and user application hardening. The exact mapping depends on the control being implemented.
How long does it take to implement DMARC enforcement?
Typically 4 to 8 weeks depending on the number of sending systems. The process starts with monitoring to identify all legitimate mail sources, then moves to quarantine, then reject. Rushing to reject without identifying all senders can block legitimate business email.
WHY IT MATTERS
Why email security matters for Sydney businesses
Sydney businesses operate in a threat environment where cybercrime is reported every 6 minutes. Email is a common attack route because it reaches every staff member every day and a single mistake can lead to serious consequences.
Professional services firms in the Sydney CBD handle sensitive client data daily. Finance teams process payments that BEC attackers target directly. Legal firms manage confidential communications protected by conduct rules. Healthcare providers hold patient data covered by the Privacy Act. Every industry has a specific email risk profile.
A layered approach is what works. Filtering catches the volume threats. Domain protection stops spoofing. MFA blocks account takeover. Staff awareness catches the social engineering that technology cannot. And managed reporting ties it together so business owners can see what is happening and make informed decisions.
Milnsbridge supports Sydney businesses with offices in the CBD at 15/225 George Street and in Penrith at Suite 10, Level 2/295 High Street. We assess your current email setup, identify gaps, and implement managed controls with clear reporting.
EXPLORE MORE
Related Milnsbridge guides
Managed email security
See how Milnsbridge scopes, configures, and manages email filtering, domain protection, and reporting for Sydney businesses.
Read moreManaged DMARC
Domain protection with SPF, DKIM, and DMARC enforcement to stop spoofing and protect your sender reputation.
Read moreMicrosoft 365 management
Configuration, security policies, and ongoing management for Microsoft 365 environments including Defender and Conditional Access.
Read moreCyber security services
The full range of Milnsbridge security capabilities including endpoint protection, MFA, network security, and compliance support.
Read moreNEXT STEP
Ready to secure your business email?
Milnsbridge supports Sydney businesses from our Sydney CBD and Penrith offices, with a 20-second average answer time and 87% first-call resolution. We will assess your current email setup, identify gaps in filtering and domain protection, and recommend the right combination of managed controls for your environment.
Talk to a SpecialistAbout the Author
Adrian Weir
Adrian Weir is the Managing Director and founder of Milnsbridge Managed IT Services, with over 30 years of global IT experience spanning Telstra, Citibank, Unilever, and hundreds of Sydney SMBs. A Microsoft Partner since 2002, Adrian leads a team of IT specialists delivering responsive, business-focused managed IT support across Greater Sydney.
Meet the Milnsbridge Team
