Email security procurement in Australia: what to require beyond the gateway

CYBORIUM article header reading Check what you already own, over a concentric ring graphic.

Email remains the most common way an attacker first reaches an organisation, and it is the control most often bought on brand rather than on requirements. The category has also changed shape. The secure email gateway that sat in front of the mail platform is no longer the whole answer, because most Australian organisations now run Microsoft 365 or Google Workspace, both of which include substantial email security in tiers the organisation may already own.

This page sets out what to specify, how to work out whether you need a third-party product at all, and where the commercials in this category mislead. It is written for Australian organisations that already have a mail platform and are deciding what to add to it.

Start by establishing what you already own

The first question is not which vendor. It is which licence tier you are on today, and what email security capability that tier already includes. Organisations routinely buy a third-party product that duplicates protection they are already paying for, because the licensing entitlement sits with a different team from the one running the security evaluation.

Establish the current entitlement in writing before you write requirements. Then the question becomes specific and answerable: what does a third-party product do that the platform tier does not, and is that difference worth its price. That is a far better evaluation than comparing two products in the abstract.

Authentication is configuration, not a purchase

SPF, DKIM and DMARC decide whether someone can send mail that claims to come from your domain. They are DNS records and policy decisions. No product is required to implement them, and no product substitutes for them.

DMARC in particular is where organisations stall. Publishing a policy of none is easy and achieves nothing protective on its own; it only produces reporting. Moving to quarantine and then reject is where the value is, and it is also where the work is, because every legitimate sending service needs to be identified and aligned first. Marketing platforms, ticketing systems, payroll providers and scanners in branch offices all send as your domain and all break loudly if you enforce before you have found them.

If a vendor is selling you DMARC, be clear about what you are buying: a reporting and workflow tool that makes the alignment project tractable, not the protection itself. That can be worth paying for. It is not the same as buying a control.

What to specify beyond the platform

Post-delivery remediation

Threats are often recognised only after delivery. Ask whether the product can retract a message from every mailbox it reached, how long that takes at your mailbox count, and whether it works for messages already forwarded internally.

Impersonation and business email compromise

Domain spoofing is largely solved by authentication. Display-name impersonation, lookalike domains and compromised supplier accounts are not. This is where invoice fraud actually happens, and it is worth specifying separately because detection quality varies far more here than on ordinary spam.

Link and attachment handling

Establish whether links are rewritten and checked at click time, whether attachments are detonated before or after delivery, and what the added latency is at your volume. Time-of-click protection changes every URL in every message, which has implications for archiving and for users who inspect links.

Reporting and the response path

A user-reporting button is only useful if something happens after it is pressed. Specify where reports land, what triage they receive, and whether that is your team’s work or the vendor’s. If it is yours, that is an operating cost the licence price does not show.

Journaling, archiving and retention

Where retention obligations apply, confirm how the product interacts with journaling and archiving, and whether rewritten links are preserved in a form the archive can still resolve later.

Where this sits against Australian obligations

The ASD Essential Eight does not name email security as one of its eight strategies, but several of them exist because of email-borne threats: user application hardening, configuring macro settings, and application control all address what happens when a malicious attachment reaches someone. Treat the maturity model as context for the requirement rather than as the requirement itself.

For APRA-regulated entities, CPS 234 applies the usual proportionality test, and email is worth assessing as a critical channel rather than as commodity infrastructure. Where the product is delivered as a service that sees every message your organisation sends and receives, the provider’s own security and data handling become a due diligence matter, which belongs with your other vendor and supplier risk management work.

How email security is priced

Almost always per mailbox per month, which looks simple and hides three things. Shared and resource mailboxes may or may not count, and at scale that distinction moves the number materially. Feature tiering often places impersonation protection and post-delivery remediation above the entry tier, which is where the actual differentiation lives. And multi-year commitments are frequently discounted against a mailbox count that assumes growth you may not have.

Ask for pricing on your real mailbox count, with shared mailboxes treated explicitly, and ask what happens commercially if headcount falls rather than rises.

Evidence to request

  • Detection results against your own recent threats, not the vendor’s sample corpus.
  • Post-delivery retraction timing at your mailbox count.
  • A clear statement of which capabilities sit in which tier, in writing.
  • Where message content is processed and stored, and for how long.
  • Australian reference customers on the same mail platform as you.
  • What the product does that your current licence tier does not, stated by the vendor and verified by you.

A defensible evaluation sequence

Document the current entitlement, write requirements as the delta beyond it, and weight them before pricing. Then run any trial in detection-only mode alongside production for long enough to see real traffic, and measure false positives as carefully as detections. A product that quarantines legitimate invoices creates a business problem that outlasts the security benefit.

Record the reasoning behind the decision, including the entitlement analysis, because that is the part a finance reviewer will ask about later. The guided vendor evaluation process and the Discover, Evaluate, Engage, Assure method produce that record as part of the work. Where licensing entitlement is the crux, read this alongside software licence renewals.

Sources

Where to read more

See identity and access management, since most business email compromise begins with a credential rather than an attachment, security awareness training for the reporting behaviour this depends on, and incident response and recovery services for what happens after a successful one.

Share this analysis