Email is the front door for most attacks on a small business. Not because email is uniquely weak, but because it is where the money conversations happen, where staff are busy and distracted, and where one wrong click opens a path to everything else.
Most owners assume email is handled. It came set up with Microsoft 365, it has a spam filter, and nothing bad has happened yet. Then we look properly, and the same gaps appear again and again. They are rarely the result of carelessness. They are the things that quietly never got switched on, got left on defaults, or fell out of date. If you want to understand where real businesses actually fall short, this is the list.
Gap 1: MFA Is Missing on Some Mailboxes
Almost every business has multi-factor authentication on something. Very few have it on every mailbox. We routinely find it enforced for most staff but missing from a shared inbox, a director who found the prompts annoying, or an old account nobody thinks about anymore.
Attackers look for the one door without the second lock, and a single mailbox without MFA is enough to get inside the conversation. The fix is to confirm MFA is enforced on every account that can send or receive mail, with no exceptions. Our guide to MFA for small business walks through why this one control does so much of the work.
Gap 2: SPF, DKIM, and DMARC Are Not Configured
These three are the technical records that prove an email genuinely came from your domain. When they are missing or half-configured, it becomes far easier for an attacker to send mail that looks like it came from you, to your staff, your clients, or your suppliers.
Most businesses have never touched these settings. The result is that your domain can be impersonated, and you have no way to see it happening. The fix is to configure all three correctly and then monitor the reports, so spoofed mail in your name gets blocked rather than landing in a client’s inbox.
Gap 3: Filtering Is Left on the Defaults
Microsoft 365 ships with email protection turned on, but the default settings are deliberately permissive so that legitimate mail is rarely blocked. Out of the box, plenty of phishing and malicious attachments still get through.
The defaults are a starting point, not a finished configuration. The fix is to tighten the policies that match how your business actually works: stricter handling of risky attachments and links, protection against lookalike domains, and rules that catch the messages most likely to be an attack. Done properly, staff barely notice the change. Attackers do.

Gap 4: Staff Have Never Had Phishing Awareness
Filtering catches a lot, but no filter catches everything. The messages that get through are designed to look real, and the last line of defence is a staff member recognising that something is off.
The common gap is that nobody has ever shown the team what a modern phishing email actually looks like. The fix is not a lecture. It is short, regular awareness so people know to pause on a payment request, a login prompt, or an urgent message from the boss. You can read more on phishing protection for business and the patterns worth teaching.
Gap 5: Shared Mailboxes Have No Controls
Most businesses run shared mailboxes for accounts, sales, or info. They are convenient, and they are often the least protected accounts in the building. We regularly find shared inboxes with a simple password, no MFA, and several people who all know the login.
A shared mailbox usually handles invoices and enquiries, which makes it a high-value target. The fix is to remove the shared password entirely, give staff access through their own protected accounts, and treat the shared inbox with the same controls as any other mailbox.
Gap 6: No Alerting When Inbox Rules Change
This is the gap that quietly does the most damage. When an attacker gets into a mailbox, one of the first things they do is create a hidden forwarding or filing rule. It silently copies or hides certain messages, so the attacker can watch invoice conversations while the real owner sees nothing unusual.
This is the engine behind business email compromise, where a client pays a real invoice into a fake account. The fix is alerting that flags when new forwarding or inbox rules appear, so a quiet change gets noticed rather than running unseen for weeks.
Gap 7: Ex-Staff Mailboxes Are Left Active
When someone leaves, the priority is the handover, not the cleanup. So their mailbox stays live, sometimes for months, still able to receive mail and still a valid login if that password ever leaks.
Every active account that nobody is watching is a risk. The fix is a simple offboarding step: when a staff member leaves, their account is disabled the same day, mail is redirected where it needs to go, and the licence is reclaimed. Unglamorous, but it closes a door that is easy to forget.
Closing the Gaps
None of these are exotic. They are the everyday shortfalls that turn a busy inbox into the way an attacker gets paid. Most of them are configuration and process, not expensive new products, and several use protections you are already paying for in Microsoft 365.
The hard part is knowing which ones apply to you, because most are invisible until someone looks. That is the value of an honest assessment.
Where to Start
If you recognised your business in more than one of these, you are normal, and you are also in a good position, because every gap on this list has a clear fix.
Start by getting a clear picture of where you stand. Our IT maturity assessment takes a few minutes and shows you which controls need attention first.
We are a Sydney-based team in Bella Vista. We help businesses across the metro area lock down email and keep it that way, with managed IT that treats security as ongoing rather than a one-off. No jargon, no scare tactics, just the basics done properly.