MSG / MSG-01
Email and anti-phishing protection — Proofpoint
Deploying and tuning protection against malicious email, dangerous attachments and impersonation, with alert handling.

WHEN IT HELPS
A focused response
to a defined need.
CIO or CISO; repeated phishing, poorly tuned email protection or a need to strengthen Microsoft 365 or Google Workspace.
SCOPE & OUTCOMES
What the engagement covers.
Scope
- Architecture and licence selection
- pilot and policies
- false-positive handling, quarantine, reporting and SOC integration where included
Deliverables
- Architecture document
- configured protection
- handling guide and email acceptance tests
Acceptance evidence
Legitimate test flows are delivered and agreed threat scenarios are handled; escalation is tested.
DELIVERY
How the work is structured.
Approach
Map domains and senders; select controls; test in pilot/observation mode; enable gradually; organise exceptions, alerts and support.
Prerequisites & responsibilities
Customer: email/DNS administrators, sending teams and sender approval. Provider: configuration and tests. For financial fraud, involve payment owners.
Scope factors
Mailboxes, domains, volume, connectors, third-party senders and operating scope. Proofpoint or other licenses, storage and recurring service are separate from the project.
Questions to clarify
How many mailboxes and domains? Which application-mail flows? Who handles quarantine and alerts?
IMPORTANT BOUNDARIES
Features depend on editions and deployment models; distinguish licensing, vendor support and ongoing operations.
No solution blocks every fraud attempt. Overly strict policies can block legitimate messages; pilots, exceptions and business procedures remain essential.
IN PRACTICE
Illustrative situations.
These examples describe possible engagements and target outcomes. They are not customer references or achieved results.
Scenario 01
A 150-person firm receives fake document-sharing messages. Project: Proofpoint pilot and targeted policies. Target outcome: route suspicious messages appropriately and enable user reporting without promising to block everything.
Scenario 02
A group’s aggressive filtering blocks supplier orders. Project: analyse false positives and refine exceptions. Target outcome: workable protection and validated business flows without broadly allowlisting entire domains.
Technology and reference context
Proofpoint Core Email Protection; confirm integrations and options with the vendor.
The final technology set is agreed during scoping, based on interoperability, licensing, access rights and operating requirements.
CONNECTED SERVICES
Build the next step.
These services can complement the engagement. They are not automatically included.
START A CONVERSATION
Make the scope clear.
We will clarify the objective, dependencies and responsibilities of this service before proposing delivery.
