This guide explains the ten essential Microsoft 365 security controls we recommend for charities to reduce cyber risk, improve governance and strengthen long-term resilience.

Control 6 of 10 Next Control >

Bunker Snapshot - Email Security at a glance

Estimated reading time 🕒 45 seconds

Everything you need to know about this security control in under 60 seconds.

Business impact

🔴 Security improvement
🔴 Risk reduction
🟢 Operational impact

Very High
Very High
Low

Related Controls

Next Steps

Review your Microsoft 365 email security settings, enable anti-phishing and Safe Links policies, and ensure users are protected against malicious email threats.

What it does

Protects your organisation against phishing, malware, spam and business email compromise by securing inbound and outbound email across Microsoft 365.

Why it matters

Email is the most common route for cyber attacks. Effective email security helps prevent malicious messages from reaching users and reduces the risk of account compromise and data loss.

Time to implement

2–4 hours

(Depending on existing Exchange Online and Microsoft Defender for Office 365 configuration.)

Who it affects

All Microsoft 365 users who send and receive email, particularly finance teams, trustees, leadership and staff handling sensitive information.

Implementation difficulty

Medium

Licensing

Basic email protection is included with Microsoft 365. Advanced phishing protection and threat investigation require Microsoft Defender for Office 365 Plan 1 or Plan 2, available with selected Microsoft 365 licences.