A Fortify 24x7 brand. Managed protection for businesses rebuilding after a security incident.Client sign insupport@hacked.help
Hacked.Help
Home / The board / Email security
Step 02 · Close the door they used

Email security

Ask any business that has just had a bad month how it started. The answer is usually a message that looked entirely reasonable at four in the afternoon.

Inbound and outboundIronscalesSandboxed attachmentsUnlimited phishing tests
Controls in this family2 lines · live rates
Email SecurityFortify-FES+SAT
per mailbox, per month
Loading
QTY
Awareness TrainingFortify-SAT
per user, per month
Loading
QTY
Per unit, per month · billed in advance by Fortify 24x7 Review the full board
Technical specification 2 lines
PlatformIronscales, authorized against your mail tenant and operated by Fortify 24x7
FilteringAnti-spam and anti-virus with custom content filtering rules
Imposter protectionDisplay-name and lookalike-domain detection for messages impersonating staff or suppliers
URL defenceRewriting and time-of-click inspection, plus predictive analysis of links not yet weaponised
Attachment defenceReputation scoring and full sandbox detonation of attachments before delivery
BEC detectionAdvanced business email compromise analysis on messages carrying no payload at all
Warning tagsIn-message banners flagging external, first-contact, and suspicious senders
Message pullOne-click retraction of a delivered message across every mailbox that received it
Outbound filteringEgress inspection so a compromised account does not turn your domain into the next campaign
TrainingUnlimited phishing security tests, automated campaigns, and security hints and tips
Training toolingPhish Alert button, phishing reply tracking, directory integration, industry benchmarking
ReportingMonthly email exposure check, social engineering indicators, and per-user reporting
Billing unitFortify-FES+SAT per mailbox; Fortify-SAT per user, per month
01Problem

The inbox is the only door you deliberately leave open

Every other route into a business is something you try to close. Mail is a route you advertise, publish on your website, and instruct strangers to use. That asymmetry is why it remains the opening move in the overwhelming majority of the cases we are called into.

The successful messages are rarely crude. They are an invoice with the account number changed, a shared document notification from a supplier whose account was taken over last week, or a password expiry warning that arrives on the afternoon you actually changed your password. Nobody clicked because they were careless. They clicked because it was plausible.

02Operation

Layers, in the order a message meets them

Ironscales is the platform underneath this line. It authorizes against your mail tenant rather than sitting in front of it as an MX gateway, which means it inspects what has already landed and can reach back into a mailbox after delivery. That single architectural fact is what makes the retraction control below possible.

  • Reputation and content. Anti-spam and anti-virus remove the volume, and custom content rules handle the patterns specific to your business.
  • Imposter analysis. Display names and lookalike domains are checked against your real staff and suppliers, which is the control that catches the message from your own finance director that did not come from your own finance director.
  • URL defence. Links are rewritten and inspected when clicked, not only when delivered, because a link that was harmless at delivery is a standard technique. Predictive analysis flags destinations that fit the shape of a campaign before they are armed.
  • Attachment defence. Files are scored on reputation and detonated in a sandbox, so the behaviour is observed rather than assumed from the extension.
  • Warning tags. Messages carry a banner where the sender is external, writing for the first time, or otherwise unusual. It is a small control that changes reader behaviour measurably.
03After the fact

One-click message pull is the control that matters at 09:00

Something gets through. It always eventually does. The question is how long it stays reachable in three hundred mailboxes while you work out what to do.

Message pull retracts a delivered message everywhere it landed, in one action, including from the people who have not opened it yet. That is the difference between an incident and an anecdote, and it is the single feature we most often watch a new client use in their first month.

Outbound filtering covers the reverse case. When one of your accounts is compromised, egress inspection stops your own domain being used to send the next wave to your customers, which is the part that damages the relationships you spent years building.

04People

Training is a control, not a compliance chore

The awareness line runs unlimited phishing security tests against your own staff, with automated campaigns that adapt to who needs them. Results are measured per person and benchmarked against your industry, so the conversation stops being a feeling and starts being a number that moves.

The Phish Alert button matters more than the tests. It converts a suspicious employee into a reporting sensor with one click, and phishing reply tracking shows where somebody engaged with a campaign rather than only where they clicked. A workforce that reports in ninety seconds is a detection capability you already employ.

Fortify-SAT is sold separately from the mail security line so the training can be extended to people who hold no filtered mailbox at all, such as contractors and shared-account staff.

Business email compromise

The most expensive messages carry no malware whatsoever

There is nothing to sandbox in an email that simply asks for the bank details on an invoice to be updated. No attachment, no link, no payload. Filtering built around finding something bad in a message has nothing to find.

BEC detection works on the conversation rather than the contents: who normally writes to whom, from where, about what, and in what register. Combined with imposter protection and warning tags, it targets the category of loss that most often arrives with no technical intrusion at all, and that most insurers treat as a separate and expensive line item.

Where this stops

This is prevention and detection, not forensics. If a fraudulent payment has already left your account, the controls here reduce the chance of the next one and do not recover the last one. Fund recovery is a matter for your bank and your insurer, and we will say so rather than sell you something that implies otherwise.

No filter reaches one hundred percent, and any figure quoted to that effect should be treated as marketing. Training reduces click rates substantially and never to zero, which is precisely why message pull and detection sit behind it.