Guide1 min readPublished Sep 13, 2026
The five email security controls that stop 90% of incidents
Ranked by the incidents we have actually responded to, not by how they are usually marketed.
We have run incident response for companies between 20 and 500 people for five years. When we tally what actually stopped the incidents that did not happen, versus what vendors market hardest, the two lists do not match. This is the ranked list from our own case files.
1. Enforced MFA on email and the identity provider
Every account compromise we have investigated involved an account without MFA, or with MFA that could be bypassed via a legacy protocol still enabled on the tenant. This alone accounts for the largest share of incidents we no longer see.
2. DMARC enforcement
Covered in more depth elsewhere, but it deserves its place on this list: enforced DMARC stops the majority of impersonation attempts before an employee ever sees them.
3. Conditional access on login location and device
Blocking or challenging logins from unexpected countries or unmanaged devices catches credential theft even when MFA is technically satisfied through a fatigue attack.
4. A tested incident response runbook
Companies with a written, rehearsed runbook contained incidents in a median of 6 hours. Companies without one took a median of 3 days, mostly spent deciding who was allowed to make decisions.
5. Phishing simulation with real follow-up
Simulations without follow-up training barely move click rates.
Simulations paired with a 5-minute follow-up for anyone who clicked cut repeat clicks by more than half in our data.
Frequency matters less than consistency — monthly beats quarterly even at lower realism.
None of these are novel. What is notable is how far down the list things like advanced endpoint detection and dedicated security headcount fall, for a company this size. Get the boring five right first.
Continue exploring
Detecting phishing before it reaches your employees
Most phishing that gets through is not sophisticated. It is fast. A practical layered setup for a 50-person company.
What a tabletop incident response exercise actually looks like
A step-by-step walkthrough of the two-hour exercise we run with clients, including the scenario we use and where teams usually get stuck.
Why your MFA rollout probably has a gap
We have audited over 60 companies that believed MFA was fully enforced. Fewer than ten actually were.
The phishing simulation email that got the best (and worst) results
We ran the same simulation across 40 client companies. The results changed how we design every simulation since.
Explore this topic
Cybersecurity
Related experts
Sebastian Terri
Making Complex Technology Easier to Understand
1 article
