Managed servicesEmail & phishing
Keep phishing from becoming a tenant takeover — mail and login defended together
Mailbox protection plus identity checks on every sign-in — so a convincing fake invoice or QR lure is less likely to become stolen credentials and firm-wide access
Most breaches still start with an email or text that looks routine — a vendor update, a wire request, a QR code on a PDF. Spam filters catch a lot, but BEC, credential harvesting, and quishing often slip through because they look like normal work. Manage IT NY combines mailbox inspection with identity policies that block sign-ins even when a password was typed into a fake login page — alongside backups and endpoint controls, not instead of them.
Technology partners
Why spam filters alone are not enough — and how phishing, BEC, and quishing differ
A spam filter (often built into Microsoft 365 or Google Workspace) blocks known bad senders and obvious junk. A secure email gateway (SEG) sits in the mail path and adds link rewriting and attachment scanning — but many firms still rely on the cloud filter alone. Neither stops a text-only executive impersonation (business email compromise, or BEC) or a QR code hidden inside an image (quishing) the same way API-level mailbox protection can. Multi-factor authentication (MFA) and Conditional Access answer a different question: "Should this login succeed on this device from this location?" — even when the password is correct. Security awareness training helps staff spot lures; it does not replace technical controls when someone is rushed or distracted.
Microsoft 365 and Google Workspace keep your tenant online — that is shared responsibility, not the same as you owning recoverable mail backups or immutable copies of critical data. Manage IT NY designs mailbox defense, identity policies, and backup posture as complementary layers partners can explain without vendor jargon.
Four phishing shapes leaders should recognize
Select a threat type to see what it looks like in plain language, what traditional filters often miss, and how mailbox plus identity controls change the outcome — without assuming you already speak SEG or API jargon.
Credential harvesting
A fake login page — often mimicking Microsoft 365, QuickBooks, or a bank — tricks someone into typing a password. The attacker captures credentials immediately. Gateway filters may miss it if the link was clean at delivery and turned malicious later, or if the lure arrived via text or personal email outside the corporate filter.
Assess mailbox postureBusiness Email Compromise (BEC)
No attachment, no link — just a convincing note from a 'partner' or 'managing partner' asking finance to change wiring instructions or approve a payment. Because the message is plain text, many spam rules never flag it. Defense combines sender-pattern baselining, finance-team verification habits, and identity controls so a stolen mailbox cannot silently approve transfers.
Talk about BEC controlsSpear phishing & whaling
Highly targeted mail built from public information — your firm name, a real conference, a colleague's title — aimed at partners, CFOs, or program managers. It feels personal because it is. Technical controls include behavioral baselining on display names and domains; human controls include out-of-band verification before sending money or credentials.
Review targeted-risk exposureQuishing (QR code phishing)
A malicious URL is embedded inside a QR code in an image or PDF — so text-based scanners never see a plain link to block. Staff scan with a phone camera and land on a credential page outside the corporate browser protections they expect. Defense uses optical character recognition (OCR) and time-of-click sandboxing on the extracted destination.
Ask about OCR defenses1 / 4
What mailbox and identity protection cover
Four layers that work together — not four disconnected product toggles
Manage IT NY maps email security from lure types to sign-in outcomes — so partners and ops leaders know which control stops which failure mode.
API-native mailbox inspection
Stops this failure mode: malicious mail delivered because the gateway only saw a clean link at send time
Connects into Microsoft 365 or Google Workspace via APIs to analyze headers, attachments, and URLs without MX record changes — quarantining anomalies before staff treat them as routine.
Time-of-click URL sandboxing
Stops this failure mode: delayed-payload links that look safe when scanned but turn malicious later
Links are rewritten and re-checked when someone clicks — blocking pages that were benign at delivery but weaponized hours afterward.
Conditional Access on sign-in
Stops this failure mode: stolen password used from an attacker's device or country
Every login is evaluated for device health, location, and risk — deny or step up when context does not match how your staff actually work.
Phishing-resistant MFA
Stops this failure mode: MFA fatigue or push prompts accepted on a lookalike site
FIDO2 passkeys and number-matched prompts bind authentication to the real tenant — so harvested passwords and replayed sessions fail at the door.
Credential harvesting
Fake login pages
Attackers copy your cloud sign-in screen. Staff enter real passwords; attackers use them immediately. Conditional Access and phishing-resistant MFA limit what a stolen password alone can do.
BEC
Business Email Compromise
Impersonation aimed at wire transfers and payment changes — often no malware attached. Combines mailbox baselining, finance verification habits, and locked-down identity for accounts that can move money.
Quishing
QR code phishing
Malicious URLs hidden in images or PDFs. Phone cameras bypass corporate link protection unless OCR and sandboxing extract and test the destination.
MFA + Conditional Access
Blocking stolen passwords
MFA adds a second factor. Conditional Access adds context — managed device, approved location, compliant patch level. Together they fail closed when a phished password arrives from the wrong machine.
What good looks like
A short buyer checklist before you trust the program — not a vendor feature list, a readiness scan.
MFA on mail and admin?
Every mailbox and admin portal requires MFA — preferably phishing-resistant methods, not SMS alone.
Conditional Access enforced?
Unmanaged devices and risky sign-in locations are blocked or stepped up — not silently allowed because the password matched.
Dangerous mailbox rules watched?
Auto-forward and inbox rules that exfiltrate mail are monitored and restricted — a common post-compromise move.
Quishing and OCR covered?
URLs embedded in images or QR codes are extracted and sandboxed — not only plain-text links in the body.
Travel and remote policies documented?
Executives on the road use managed devices and approved paths — with written rules finance and IT can follow.
Mail backed up separately?
Microsoft 365 or Google uptime is not the same as you owning recoverable mail — shared responsibility still applies.
Defense in depth: mailbox content plus identity on every sign-in
Two pillars answer different questions. The content layer asks: 'Should this message or link reach the inbox?' The identity layer asks: 'Should this login succeed on this device?' Most firms need both — a filtered inbox reduces lures; identity policy limits damage when someone still clicks.
Content layer — inspect mail without MX latency
API-native protection connects directly into Microsoft 365 or Google Workspace via Graph or Admin APIs — analyzing inbound mail without rerouting MX records or adding gateway delay.
Learns normal sender patterns — display names, domains, and frequency — to flag subtle spoofing before finance treats a message as routine.
Rewrites and re-scans links when clicked, blocking delayed-payload threats that looked clean at delivery.
Unknown files run in an isolated sandbox first — so zero-day attachments are less likely to reach the inbox unchecked.
Identity layer — gate every sign-in, even with a stolen password
Conditional Access evaluates risk before granting access — device compliance, location, sign-in risk, and MFA method — even when credentials were harvested minutes ago.
Sign-ins from unmanaged or non-compliant devices are blocked or required to enroll — shrinking the window for attacker-controlled laptops.
Sign-ins from unapproved countries or impossible travel patterns are denied — with documented exceptions for executives on managed hardware.
FIDO2 passkeys and number-matched prompts resist lookalike pages that trick users into approving a push notification.
How a credential-harvesting attempt is usually interrupted
A teaching sequence from lure to blocked sign-in — what mailbox inspection and Conditional Access do when both layers are already in place. Times are an example; real clocks vary by tenant size, policy strictness, and whether the user clicked from a managed device.
A message mimics a legitimate vendor — urgent QuickBooks or payment-portal language, link to a credential page. BEC-style urgency is designed to bypass calm verification habits.
How email and identity controls map to your industry
Privileged matter files, taxpayer PII, and CUI each raise different questions about mailbox risk and sign-in policy. Here is how Manage IT NY explains the controls each vertical actually needs — in language partners and ops leaders can follow.
Law firms & client confidentiality
ABA competence expectations include understanding technology risks — including how quickly a phished partner credential could reach matter files and client portals. Mailbox baselining plus Conditional Access supports the reasonable-efforts story partners explain to clients, without promising that spam filters catch everything.
Law firm cybersecurityAccounting firms & taxpayer data
IRS Publication 4557 and written information security plans expect safeguards for taxpayer PII — including phishing-resistant access to tax software and mail. BEC wire-fraud lures often target preparers during peak season; finance verification habits and identity lockdown matter as much as filtering.
Accounting firm cybersecurityManufacturing & finance-adjacent roles
Plant and ops leaders may not live in email daily — but AP clerks and executives do. Vendor impersonation and invoice fraud target payment teams. Scoped Conditional Access for roles that approve wires reduces blast radius when a mailbox is compromised.
Manufacturing cybersecurityDefense industrial base (CMMC & NIST)
CMMC and NIST SP 800-171 expect phishing-resistant authentication and monitoring on systems handling CUI. Mail and identity policies should align with enclave boundaries — so a phished office account is less likely to become a path into controlled environments.
CMMC enclave pathFrequently asked questions
Straight answers on stolen credentials, spam filters vs layered protection, quishing, SaaS backup responsibility, rollout timing, and travel access.
Stolen passwords are common — the goal is to make them useless alone. Manage IT NY enforces Conditional Access with phishing-resistant MFA and device compliance checks. The attacker's machine typically lacks a managed device certificate and fails location and health rules — so the sign-in is denied and sessions are revoked while the account is reset. Speed matters; so does having the policies already enabled before the click.
Built-in filters catch a lot of bulk spam — but BEC messages are often plain text with no attachment, and quishing hides URLs inside images. API-level mailbox protection adds behavioral baselining, time-of-click sandboxing, and OCR on QR codes. It complements — not replaces — awareness training and identity policies that block stolen credentials.
Text scanners cannot read URLs embedded in images or QR codes. Our mailbox engine uses OCR and computer vision to extract hidden links, then routes destinations through time-of-click sandboxing before delivery — so scanning a code on a phone does not bypass corporate protections.
Platform uptime and basic retention are the vendor's responsibility — recoverable, long-term mail archives and immutable copies are yours under shared responsibility models. Deleted mail, ransomware encryption, and malicious mailbox rules can outrun default retention. We pair mailbox defense with backup strategies documented in our data protection practice — so mail is defensible, not only filtered.
API mailbox integration typically connects in days without MX changes — mail flow stays uninterrupted. We usually run in read-only baseline mode first to learn communication patterns, then enable quarantine and Conditional Access enforcement on a phased schedule. Full policy tuning depends on tenant size, exception count, and how many legacy sign-in paths exist today — plan for measured weeks, not a same-day hard cutover.
Yes — with planning. Policies can allow managed devices on approved VPN or mobile device management profiles while blocking personal laptops and high-risk geographies. Traveling executives should use firm-managed hardware and documented exception paths — not shared passwords and implicit trust because they are on a hotel Wi-Fi.








