July 1, 2026
Microsoft 365 Email Security: What Central NJ Businesses Keep Getting Wrong
A few months ago, a bookkeeper at a contracting business near Freehold got an email from the owner. It matched his writing style, referenced a real project, and asked her to push through a wire to a new supplier before end of day. She did. The money was gone before anyone realized the “owner” was a stranger who had been reading the company’s email for two weeks.
That’s not a rare story. It’s the single most common way small businesses across Monmouth, Middlesex, and Ocean Counties lose real money to cybercrime — and almost every time, the company was running Microsoft 365 with the security settings left exactly the way they came out of the box.
Here’s what actually goes wrong, and what to do about it — in plain English, no fear-mongering.
Why Email Is Still the Front Door
Attackers don’t usually “hack” small businesses in the movie sense. They log in. They get a password from a phishing email or a leaked-password list, sign into Microsoft 365, and quietly watch. This kind of attack — someone impersonating a trusted person to redirect a payment — is called business email compromise (BEC), and it’s one of the costliest crimes online.
The FBI’s Internet Crime Complaint Center has tracked more than $50 billion in exposed losses to business email compromise between 2013 and 2023, including roughly $2.9 billion in a single recent year. Ransomware gets the headlines, but for a typical Central NJ small business, a fraudulent wire transfer is the far more likely way to lose money.
And the businesses that get hit aren’t careless — they’re just running default settings. Microsoft 365 is secure if you configure it. Most companies never do.
The One Setting That Stops Most Attacks
If you do nothing else after reading this, do this: turn on multi-factor authentication (MFA) for every user.
MFA means that even if an attacker steals a password, they still can’t log in without the second factor — a prompt on your phone, a code, a hardware key. Microsoft has reported that MFA blocks over 99.9% of automated account-takeover attempts. It is the highest-impact, lowest-cost security control available to any small business, and it’s included in every Microsoft 365 plan.
The catch: attackers know MFA works, so they’ve adapted. Two things to watch for:
- MFA fatigue — flooding someone with approval prompts at 2 a.m. until they tap “approve” just to make it stop. The fix is number-matching MFA (you type a number shown on screen), which Microsoft now enables by default.
- Weak MFA — text-message codes can be intercepted. An authenticator app or a hardware key is meaningfully stronger.
MFA isn’t optional anymore. Many cyber-insurance policies now require it before they’ll pay a claim.
The Three Email-Authentication Records Nobody Set Up
When someone sends email pretending to be your domain, three behind-the-scenes records decide whether it lands or bounces. Most small businesses have zero of them configured correctly.
- SPF (Sender Policy Framework) — a public list of the servers allowed to send email as your domain. If a message comes from somewhere not on the list, it’s suspect.
- DKIM (DomainKeys Identified Mail) — a tamper-proof digital signature on your outgoing mail that proves it really came from you and wasn’t altered.
- DMARC (Domain-based Message Authentication) — the policy that ties SPF and DKIM together and tells receiving servers what to do with fakes: monitor them, send them to junk, or reject them outright.
In plain terms: SPF and DKIM prove you are who you say you are. DMARC tells the world to throw away anyone who can’t. Setting all three up properly stops criminals from spoofing your domain to your own customers and staff — and it improves the odds your legitimate email actually reaches inboxes instead of spam folders.
What Business Premium Actually Adds
Most Central NJ businesses we work with are on Microsoft 365 Business Standard. Moving to Business Premium is usually the single best security upgrade a small company can make, and it’s a modest step up in price. It adds Microsoft Defender for Office 365, which quietly does the work your users can’t:
- Safe Links rewrites and checks every link at the moment someone clicks it — so a link that was clean when the email arrived but weaponized an hour later still gets blocked.
- Safe Attachments opens attachments in an isolated sandbox before they reach the inbox.
- Impersonation protection flags messages where the display name says “the owner” but the address underneath is a stranger — exactly the pattern in that opening story.
- Conditional Access lets you say “no logins from outside the U.S.” or “require a managed device,” shutting the door on the overseas login attempts that make up most account takeovers.
Business Premium also bundles device management and encryption — so for a growing business, it often replaces two or three separate tools you’d otherwise buy.
The Attacks We See Most Often Around Central NJ
Patterns repeat. If you recognize any of these, it’s worth a look:
- Vendor/invoice fraud — an email “from a supplier” updating their bank details right before a payment is due. Always confirm banking changes by phone, using a number you already had — never the one in the email.
- The lookalike domain — networklabnyc.com instead of networklab.nyc, or a capital-I swapped for a lowercase-l. At a glance, nobody notices.
- Silent forwarding rules — once inside a mailbox, attackers create a hidden rule that auto-forwards financial emails to themselves, then delete the evidence. Worth auditing periodically.
- The “quick favor” text or email — a message “from the boss” asking a junior employee to buy gift cards or move money quietly. Urgency plus secrecy is the tell.
The Bottom Line
You don’t need enterprise-grade paranoia to run a safe business. You need a handful of settings configured correctly and a couple of habits: MFA on every account, email authentication (SPF/DKIM/DMARC) locked down, Defender doing the heavy lifting, and a simple rule that any change to where money goes gets confirmed by phone.
Almost every email breach we’re called in to clean up would have been stopped by controls that were already sitting unused in the company’s existing Microsoft 365 subscription.
Want to know where your Microsoft 365 setup actually stands? We’ll run a security review of your tenant — MFA coverage, email authentication, admin access, and forwarding rules — and give you a plain-English list of what to fix first. No jargon, no scare tactics.
Book a Free Microsoft 365 Security Review →
Network Lab provides managed IT and cybersecurity services for businesses across Manalapan, Freehold, Marlboro, Old Bridge, East Brunswick, Edison, Woodbridge, Toms River, and across Monmouth, Middlesex, and Ocean Counties. Call us at (732) 660-5565.
Want a straight read on your IT?
Book a free assessment — we'll tell you what's working, what's at risk, and what to fix first. No obligation.
Book an assessment →