Skip to main content

Audit to Action: A 90-Day Email Security Plan

24 September 2026 | By Birender Chahal

Email is the front door for most cyber incidents. It is where phishing lands, where invoice fraud plays out, and where one compromised mailbox can quietly cost a business tens of thousands of dollars. Yet for most small businesses, email security is whatever Microsoft 365 happened to switch on by default and nothing more.

An audit will surface the gaps. The value is in closing them in a sensible order rather than trying to fix everything at once. This is a practical 90-day plan to a defended, recoverable email baseline: the controls that block the common attacks, plus the visibility to catch what gets through. None of it requires an enterprise budget. Most of it is tightening settings you are already paying for.

The First 30 Days: Lock the Doors

The first month is about stopping the most common way in. Two things matter most here.

The first is multi-factor authentication on every mailbox, with no exceptions. Most email compromises start with a password that has leaked or been guessed, and MFA means a stolen password alone is not enough to get in. This one control blocks the large majority of account takeovers, so it goes first and it covers everyone, including the owner and any shared or admin accounts that tend to get overlooked.

The second is tuning your email filtering. Microsoft 365 includes solid protection, but the default settings are a starting point, not a finished job. Properly configured filtering catches far more phishing, spoofing, and malicious attachments before they ever reach an inbox. Getting MFA and filtering right inside the first month removes the easiest paths an attacker has into your business.

Email warning notification on a laptop
Most email incidents start at the front door. That is where to begin.

Days 30 to 60: Prove You Are You, and Train Your People

The second month closes the gap that lets attackers impersonate your business and lets convincing emails slip past your team.

The technical half is authenticating your domain with SPF, DKIM, and DMARC. In plain terms, these are records that prove an email genuinely came from your business and let receiving systems reject ones that do not. Without them, an attacker can send mail that looks like it came from your address, which is the foundation of most business email compromise. Setting these up correctly makes your domain much harder to spoof and improves the chance your legitimate email actually lands.

The human half is staff awareness. Filtering catches a lot, but the cleverest attacks are designed to get past it and land on a person. A team that recognises a dodgy invoice, an unexpected login prompt, or a request to change bank details is your last and often best line of defence. This does not mean a dry annual training video. It means short, practical guidance and a clear rule that anything involving money or credentials gets verified by a known phone number, never by replying to the email. Our guide to phishing protection covers what good awareness looks like.

Days 60 to 90: See What Is Happening and Close the Exits

The final month adds the visibility and process that turn a defended inbox into a recoverable one.

The first piece is alerting on inbox rule changes. When an attacker does get into a mailbox, one of the first things they do is create a hidden rule that quietly forwards or deletes messages, so they can watch invoice conversations without the owner noticing. An alert on new or changed inbox rules is one of the most reliable early warnings of a compromise, and it is exactly the kind of monitoring most businesses do not have switched on.

The second is a proper offboarding process. When someone leaves, their mailbox and access should be dealt with promptly and deliberately: account disabled, sessions revoked, mail handled according to a plan. A forgotten live mailbox belonging to a departed staff member is a standing risk, and tidying offboarding into a repeatable step removes it for good. Together, alerting and offboarding mean you catch trouble early and you do not leave doors open behind you.

A Baseline You Can Maintain

By the end of 90 days you have moved email from a default setup to a defended one: hard to break into, hard to impersonate, monitored for the signs of compromise, and tidied up when people come and go. That significantly reduces the risk of the two patterns that do the most damage, account takeover and invoice fraud.

The point of sequencing it this way is that each month builds on the last, so it never feels like one impossible push. If you want a documented picture of where your email security stands today, our IT maturity assessment gives you a plain-English read in a few minutes, and our Bella Vista team can help you work through the plan from there.

Birender Chahal
Founder, CIO Tech

Birender founded CIO Tech and holds an IT degree from the University of Technology Sydney. He has delivered IT projects across hotels and serviced offices, covering property management systems, guest networks, and Essential Eight hardening. More about CIO Tech.

Stop putting off IT that works

Book an IT Audit

$990 one-off. 90-day deep dive into your IT environment with a prioritised action plan.

Book IT Audit

Free IT Health Check

Takes 3 minutes. See where your IT stands and what to fix first.

Free IT Health Check

Cyber Posture Snapshot

Your details 1 / 10

How exposed is your business?

Six quick questions, two short ones to tailor the result, and you'll see where your business stands. About two minutes. Plain English, no jargon.

We'll use your email to send a copy of your result. No spam, no pushy sales calls.

Question 1 of 9

When your team logs in to email and business apps, do they need a code from their phone as well as a password?

Question 2 of 9

If a ransomware attack locked all your files tomorrow, could you restore them from a backup?

Question 3 of 9

When Microsoft or Apple release a critical security update, how fast does it land on your computers?

Question 4 of 9

How many people in your business can install software or change system settings on any work computer?

Question 5 of 9

If a staff member got a fake invoice or "urgent" email pretending to be from you right now, what would happen?

Question 6 of 9

When a staff member leaves, when does their access to email, files, and apps actually get cut off?

Question 7 of 9

How many people work in your business?

Question 8 of 9

Who looks after your IT today?

Question 9 of 9

What sort of business are you?

Tailoring your result...

Hi there, here's where your business stands.

Your Cyber Posture
Critical gaps Critical
Notable exposure Notable
Mixed picture Mixed
On the right track On track

Notable exposure

Your two biggest gaps

  1. 1
  2. 2

Where this leaves you on Essential Eight

  • MFA Multi-factor authentication
  • Backups Regular backups
  • Patching Covers 2 of 8: Patch applications + Patch operating systems
  • Admin access Restrict administrative privileges

This snapshot covers 5 of the 8 Essential Eight controls. The full IT Maturity Assessment covers all 8, plus Microsoft 365 hardening, device management, and staff training.