Skip to content
CISO Marketplace Services

Email Security Assessment

Comprehensive evaluation of your organization's email infrastructure, security controls, and policies to protect against phishing, business email compromise, and data loss. Our assessment identifies vulnerabilities and provides actionable recommendations to enhance your email security posture.

In scope

  • Authentication protocol verification (SPF
  • DKIM
  • DMARC)
  • Anti-phishing control assessment
  • Email gateway configuration review
  • Data loss prevention analysis
  • Email retention policy evaluation
  • Account security assessment
  • Third-party integration review
  • User awareness testing

You receive

  • Email security assessment report
  • Configuration improvement guide
  • Authentication protocol implementation plan
  • Phishing defense roadmap
  • Email security architecture recommendations
  • User awareness training recommendations
  • Policy enhancement guide

Tiers

Choose the depth.

Core Email Security Assessment

$25K

Email security review for up to 500 mailboxes and 3 sending domains on one platform (Microsoft 365 or Google Workspace).

Users
500
domains
3
  • Platform configuration review
  • SPF, DKIM and DMARC review
  • Prioritized hardening plan
  • — Staff email exercises
  • — More than one email platform
Scope Core Email Security Assessment

Advanced Email Defense Program

$45K

Up to 2,500 mailboxes and 10 domains, including one staff email exercise and a review of mail-flow rules and third-party senders.

Users
2500
domains
10
  • Everything in Basic
  • One staff email exercise
  • Third-party sender review
  • — Ongoing DMARC management — see Managed DMARC
Scope Advanced Email Defense Program

Enterprise Email Protection Suite

$75K

Up to 10,000 mailboxes and 25 domains across multiple tenants or platforms; larger estates are scoped at kickoff.

Users
10000
domains
25
  • Multi-tenant or hybrid mail estates
  • Two staff email exercises
  • Executive readout
  • — Migration or implementation work
Scope Enterprise Email Protection Suite

Members: engagement coupons from the CISO Marketplace coupon book apply to services. There is no blanket discount.

What's inside this engagement

Phase by phase.

How a social engineering & physical engagement runs, what happens in each phase and what you see. Exact scope, tier and timeline are fixed in your proposal and SOW.

  1. 01Scoping & authorization

    Targets, pretexts, sites and legal authorization letters agreed before anything is sent or attempted.

    You see · Signed authorization and approved pretexts.

  2. 02OSINT & pretext design

    Public information on staff and sites is used to build believable pretexts.

    You see · Approval of the pretexts.

  3. 03Campaign / on-site execution

    Phishing, vishing or physical entry attempts, run to the agreed plan and stopped on request.

    You see · Real-time escalation if anything goes wrong.

  4. 04Reporting & awareness debrief

    What worked, who reported it, and the controls that failed, without naming and shaming individuals.

    You see · Metrics and a training plan.

Commercials

From first call to final report.

  1. 01

    Scoping call

    A practitioner, not a salesperson, walks through targets, constraints and what a good outcome looks like for you.

  2. 02

    Proposal & rules of engagement

    A fixed-scope proposal with tier, price and deliverables. Rules of engagement, contacts and out-of-bounds systems are agreed in writing.

  3. 03

    Sign, then start

    MSA and SOW are signed electronically and the deposit is paid. Only then does testing begin.

  4. 04

    Execution

    Testing runs to the agreed plan. Critical findings are escalated as they are found; you don't wait for the report.

  5. 05

    Report & debrief

    An executive summary plus technical findings with evidence, reproduction steps and fixes, walked through with your team.

  6. 06

    Retest

    Where the tier includes it, we verify your fixes and reissue the report, so auditors and customers see the issues closed.

Timelines are set per engagement in the SOW.

Related

Research

Latest from the blog

All posts on cisomarketplace.com →
Talk to an advisor
Advisor