Email is the front door for most cyber incidents. It is where phishing lands, where invoice fraud plays out, and where one compromised mailbox can quietly cost a business tens of thousands of dollars. Yet for most small businesses, email security is whatever Microsoft 365 happened to switch on by default and nothing more.
An audit will surface the gaps. The value is in closing them in a sensible order rather than trying to fix everything at once. This is a practical 90-day plan to a defended, recoverable email baseline: the controls that block the common attacks, plus the visibility to catch what gets through. None of it requires an enterprise budget. Most of it is tightening settings you are already paying for.
The First 30 Days: Lock the Doors
The first month is about stopping the most common way in. Two things matter most here.
The first is multi-factor authentication on every mailbox, with no exceptions. Most email compromises start with a password that has leaked or been guessed, and MFA means a stolen password alone is not enough to get in. This one control blocks the large majority of account takeovers, so it goes first and it covers everyone, including the owner and any shared or admin accounts that tend to get overlooked.
The second is tuning your email filtering. Microsoft 365 includes solid protection, but the default settings are a starting point, not a finished job. Properly configured filtering catches far more phishing, spoofing, and malicious attachments before they ever reach an inbox. Getting MFA and filtering right inside the first month removes the easiest paths an attacker has into your business.

Days 30 to 60: Prove You Are You, and Train Your People
The second month closes the gap that lets attackers impersonate your business and lets convincing emails slip past your team.
The technical half is authenticating your domain with SPF, DKIM, and DMARC. In plain terms, these are records that prove an email genuinely came from your business and let receiving systems reject ones that do not. Without them, an attacker can send mail that looks like it came from your address, which is the foundation of most business email compromise. Setting these up correctly makes your domain much harder to spoof and improves the chance your legitimate email actually lands.
The human half is staff awareness. Filtering catches a lot, but the cleverest attacks are designed to get past it and land on a person. A team that recognises a dodgy invoice, an unexpected login prompt, or a request to change bank details is your last and often best line of defence. This does not mean a dry annual training video. It means short, practical guidance and a clear rule that anything involving money or credentials gets verified by a known phone number, never by replying to the email. Our guide to phishing protection covers what good awareness looks like.
Days 60 to 90: See What Is Happening and Close the Exits
The final month adds the visibility and process that turn a defended inbox into a recoverable one.
The first piece is alerting on inbox rule changes. When an attacker does get into a mailbox, one of the first things they do is create a hidden rule that quietly forwards or deletes messages, so they can watch invoice conversations without the owner noticing. An alert on new or changed inbox rules is one of the most reliable early warnings of a compromise, and it is exactly the kind of monitoring most businesses do not have switched on.
The second is a proper offboarding process. When someone leaves, their mailbox and access should be dealt with promptly and deliberately: account disabled, sessions revoked, mail handled according to a plan. A forgotten live mailbox belonging to a departed staff member is a standing risk, and tidying offboarding into a repeatable step removes it for good. Together, alerting and offboarding mean you catch trouble early and you do not leave doors open behind you.
A Baseline You Can Maintain
By the end of 90 days you have moved email from a default setup to a defended one: hard to break into, hard to impersonate, monitored for the signs of compromise, and tidied up when people come and go. That significantly reduces the risk of the two patterns that do the most damage, account takeover and invoice fraud.
The point of sequencing it this way is that each month builds on the last, so it never feels like one impossible push. If you want a documented picture of where your email security stands today, our IT maturity assessment gives you a plain-English read in a few minutes, and our Bella Vista team can help you work through the plan from there.