Skip to main content
Home/Services/Email Security
Security Testing

Email Security

Defend the #1 phishing and BEC target in your environment

SOC 2 ISO 27001 HIPAA PCI-DSS GDPR
engagement log Email Security testing
day 01scopetargets confirmed · rules of engagement signedagreed
day 01reconattack surface mappedcomplete
day 02findingDMARC in monitor mode onlycritical
day 03findingMissing DKIM on key domainshigh
day 04triagereviewed and countersigned by a Lorikeet pentesterpublished
day 04delivertickets opened in your tracker201
afterretestfixes verified · included in scopeno charge
retest included human countersigned report your auditor accepts
4-8 weeks initial + ongoingtypical duration $7,500 + $1,200/monthfixed scope, from 6deliverables 6methodology stages
Scope

What this engagement covers

The service

Assessment, deployment, and ongoing management of email security controls - DMARC, SPF, DKIM, secure email gateway tuning, BEC prevention, and user-reporting workflow.

What we test

Email authentication records, secure email gateway (Proofpoint, Mimecast, M365 Defender, Google Workspace) policy, user reporting flow, simulated phishing efficacy, and third-party sender posture.

Method

How we run it

Baseline assessment, hardening, policy deployment, DMARC enforcement rollout, and quarterly tuning against current phishing trends.

01

Current-state assessment

02

Authentication record remediation

03

Gateway policy hardening

04

DMARC enforcement staging

05

User reporting workflow

06

Continuous tuning

Deliverables

What you receive

Findings land in your tracker as you go, not only in a PDF at the end. Retest is in scope, not a change order.

  • Email authentication assessment (SPF/DKIM/DMARC)
  • DMARC enforcement rollout (reject mode)
  • Gateway policy hardening
  • User reporting workflow integration
  • Quarterly phishing trend tuning
  • Brand impersonation monitoring
Typical results

What we usually find

The issues this engagement surfaces most often. Yours will differ, but this is the shape of it.

DMARC in monitor mode only Missing DKIM on key domains Overly permissive SPF (+all) Unprotected subdomains Gateway bypasses for "safe senders" No user-facing reporting workflow
Fit

Who this is for

Organizations getting heavily phished
Companies preparing for SOC 2 / ISO
Post-BEC hardening engagements
Brand-protection programs
Standards this supports

Findings are mapped to SOC 2, ISO 27001, HIPAA, PCI-DSS, GDPR, so the report drops into an audit package rather than needing to be translated first. If you need the readiness work behind one of those, that is a separate engagement.

Next

Scope it in one call

Tell us what is in scope and we come back with a fixed price and a start date. No discovery-call maze, no hourly estimate that moves.

Lory waving

Hi, I'm Lory! Need help finding the right service? Click to chat!