Skip to content

Services

MIR · Managed Identity Resilience MCR · Managed Cloud Resilience MER · Managed Email Resilience MBR · Managed Brand Resilience MAR · Managed AI Resilience

Company

Resources Company Contact Get my Exposure Score →
MERNew PROTECT → CONTAIN → HARDEN → REPORT

Stop email threats before they become breaches.

MER stops the phishing and BEC your gateway was never built to catch, and triages what gets through — so your team is not the first line of defence.

90 secondsNo signup to startRead-only, no agents

ManagedTRIAGE, NOT ALERTS
24/7CONTAINMENT
MonthlyRE-SCORED

The problem

Everyone breached by email already owned an email security tool.

The gap is almost never detection capability. It is authentication left half-finished, a triage queue nobody owns, and takeover discovered days late.

// p=none

DMARC configured to watch spoofing, not stop it

Below p=reject, anyone can send mail that appears to come from your domain — to your staff, customers and suppliers. Parked and secondary domains are the ones always forgotten, and the ones attackers pick.

// the queue

Quarantine releases and phishing reports eating the week

Slow releases train users to route around security. Unread phishing reports mean live campaigns sit in a queue while they are still running. This is the workload that quietly consumes a small security team.

// hours, not minutes

Account takeover found after the inbox rules were created

A compromised mailbox becomes an internal phishing platform within hours, and internal mail never passes your gateway. Containment measured in hours instead of minutes is the difference between one victim and a supplier-wide incident.

The programme

What MER actually does

Six capabilities delivered as one managed outcome.

01

Email threat protection

AI-driven detection in front of and inside the mailbox — phishing, business email compromise, spoofing, malicious links and attachments.

  • Phishing, BEC and spoofing prevention
  • Safe links and safe attachments
  • AI-driven detection across internal and inbound mail
  • Hybrid support for cloud and on-premises Exchange
02

Identity protection at the email layer

Account compromise detected and contained without waiting for an analyst.

  • Account takeover detection
  • Automatic containment of compromised accounts
  • Impossible-travel, forwarding-rule and OAuth-grant signals
03

Email data protection

Data loss prevention enforced where data actually leaves — the outbound message.

  • DLP policy enforcement
  • Encryption and sensitivity handling
  • Outbound anomaly detection
04

Email posture management

The configuration layer that most organisations never finish.

  • SPF, DKIM and DMARC lifecycle — p=none → quarantine → reject
  • Anti-phishing and anti-malware policy hardening
  • Continuous misconfiguration audit via SaaS security posture management
  • Sending-source validation and forensic DMARC reporting
05

Threat monitoring & response

Visibility plus the operational work, not just the dashboard.

  • Consolidated quarantine view
  • Monthly threat and posture reporting
  • Threat triage and incident visibility
06

SaaS & collaboration security

Protection extended past the inbox to where payloads are actually shared.

  • Teams, SharePoint and OneDrive coverage
  • Detection of compromised users and business partners
  • Collaboration-layer file and link inspection

Add-ons

Extend MER where it matters most to you

Added to the core programme, priced separately, and only worth taking if they solve something you actually have.

Incident Response as a Service (IRaaS)

Vendor analysts handle every end-user quarantine restore request and phishing report on your behalf, 24/7. This exists specifically to remove the ticket queue from your team.

Security awareness assessment & training

AI-driven realistic phishing simulation with training targeted by measured user risk — who clicks, who reports, who is high-risk — rather than distributed evenly across a population where risk is not.

Threat intelligence — credentials & domains

Dark-web and breach-database monitoring for exposed emails, passwords and tokens, plus lookalike domain detection and alerting on newly registered suspicious domains.

Email archiving (up to 10 years)

Business continuity, regulatory records management, legal discovery and chain-of-custody — plus recovery of mail deleted by users or lost to technical failure.

At a glance

What’s included

The commercial and technical shape of the programme, before you talk to anyone.

Platform coverageMicrosoft 365, Google Workspace, hybrid and on-premises Exchange
DeploymentAPI-based. No MX record change, no mail-flow cutover
BaselineEmail Exposure Assessment — scored report within 48 hours of access
Trial path30-Day Email Protection Activation with before/after scoring
CadenceContinuous protection, monthly reporting, monthly posture improvement
Ideal size100–1,000 users on Microsoft 365 or Google Workspace
Guarantee90% reduction in measured email exposure score in 90 days — see terms

Who MER fits

This is a good fit if…

  • 100–1,000 users on Microsoft 365 or Google Workspace
  • Phishing or BEC attempts already reaching people
  • A security or IT team absorbing quarantine and phishing-report triage manually
  • DMARC stuck at p=none, or configured on the primary domain only

If none of these describe you, MER probably is not your priority — and we would rather tell you that than sell it. Run the free assessment on a different surface and see where your score is actually worst.

Objections

The fair questions

No. MER deploys through API integration with Microsoft Graph or the Google API using read and enforcement permissions. There is no mail-flow cutover, which means no delivery risk during rollout and no rollback plan required.

E5 gives you capable filtering. MER adds three things E5 does not: internal mail visibility for already-compromised mailboxes, completed authentication posture across every sending domain including parked ones, and the human operational work — triage, releases, containment — that consumes your team’s week.

Read-only API access for a scored review of your email security configuration, anti-phishing policy strength, authentication records across all domains, data-protection controls and high-level audit signals. Data collection takes 0–4 hours, analysis 24–36 hours, and findings are delivered within 48 hours as a 45–60 minute executive session — risk, impact, fix. Not a technical dump.

Start with MER

Find out where you stand on email — in 90 seconds.

Eight questions, a score, and your top three exposure factors. If you want the real number, the full assessment reads your actual environment: read-only, no agents, 48 hours to a report.

90 secondsNo signup to startNo agents, read-onlyNo obligation

Get my Exposure Score — free →