
Protect the inbox. Verify the message. Reduce account risk.
Design email protection around your actual mail platform, users and threat exposure. TRILOGY scopes the delivery architecture, configures the selected policies and verifies protection without assuming that every capability is included in one license.
When this solution is relevant
Phishing and impersonation
Review protection for malicious links, attachments and deceptive sender identities.
Business email compromise
Address payment-change requests, executive impersonation and suspicious conversation patterns.
Cloud mail protection
Select gateway, API-based or native controls suited to Microsoft 365 or another supported platform.
Investigation and remediation
Define message tracing, quarantine ownership and supported post-delivery actions.
Technology options
Technology options to evaluate against your requirement. Product capabilities, editions and integrations are confirmed in the agreed configuration.
- Abnormal AI
Abnormal AI — Inbound Email Security / Account Takeover Protection
- Behavioral analysis detects impersonation and business email compromise
- Inbox remediation removes detected malicious messages
- Account takeover protection is scoped as a distinct capability

Microsoft — Defender for Office 365 — Plan 1 / Plan 2
- Plan 1 provides Safe Links, Safe Attachments and anti-phishing protection
- Plan 2 adds automated investigation, response and attack simulation training
- Plan 1 is included in Office 365 E3 and Microsoft 365 E3 from 1 July 2026; confirm tenant entitlements

Mimecast — Advanced Email Security
- Gateway-based protection for inbound email traffic
- API-based options for cloud email deployment
- BEC defense and targeted-user visibility within the selected package

Proofpoint — Core Email Protection / Targeted Attack Protection
- Email threat protection across the selected delivery architecture
- Targeted Attack Protection adds specialized protection against targeted threats
- Related collaboration, awareness and data-protection modules are separately scoped
- Barracuda
Barracuda — Email Protection
- Layered email protection with gateway and API-based components
- Impersonation and account-takeover protection for supported cloud environments
- Incident remediation and additional services depend on the selected plan

TrendAI — Trend Micro enterprise business — TrendAI Vision One Email and Collaboration Security
- Protection for email and supported collaboration services
- Centralized detection insights within Vision One
- Packages and credits determine the enabled protection capabilities

Broadcom — Symantec — Email Security.cloud / Messaging Gateway
- Email Security.cloud provides cloud-delivered email filtering
- Messaging Gateway supports appliance-based deployment
- DLP, encryption and advanced response require the appropriate modules
Names and trademarks belong to their owners.
What we verify
Protection coverage
Users, domains and mail flows included in the agreed configuration.
Authentication alignment
Observed SPF, DKIM and DMARC results for approved sending sources.
Test outcomes
Safe phishing and attachment scenarios, including false positives.
Remediation evidence
Recorded quarantine, release and post-delivery remediation outcomes.
How the technical work is scoped
01
Scope and architecture
Define the assets, integrations, ownership and acceptance criteria before selecting the configuration.
02
Implementation and change
Configure the agreed controls through an approved change plan, with rollback steps and assigned responsibilities.
03
Verification and handover
Test agreed scenarios, record exceptions and hand over the configuration, operating procedures and test evidence.

Technical scope in detail
Mail-flow architecture
The design documents MX records, connectors, APIs and existing controls. Changes are staged to preserve legitimate mail delivery. Acceptance tests cover inbound, outbound and relevant internal traffic.
Domain authentication
Authorized sending services are inventoried before SPF, DKIM or DMARC changes. Policy enforcement is introduced after reviewing alignment and reporting. Authentication reduces specific spoofing paths; it does not eliminate every impersonation technique.
People-targeted threats
Policies account for executives, finance teams and other exposed roles. Test scenarios use approved safe content. Exceptions and false positives are reviewed with the business owner.
Microsoft 365 licensing
Defender for Office 365 Plan 1 and Plan 2 provide different capabilities. Tenant entitlements are checked before enabling automation or simulation. Microsoft Purview data-protection requirements are scoped separately.
Operational handover
Quarantine permissions, escalation and message-remediation procedures are documented. Tests record the actions available for the chosen deployment. Retention and privacy requirements govern the investigation data.
Licensing and sizing
Review protected users, domains, mail platform, deployment model and selected modules. Confirm the tenant’s existing entitlements before adding licenses; advanced response, awareness, archive and DLP may have separate requirements.
What to share with us
Mail platform; domains and user counts; sending services; existing subscriptions; investigation owner.
What you receive
Agreed scope and architecture
Selected configuration and integration record
Approved change and rollback plan
Test record and documented exceptions
Operating procedures and technical handover
Frequently asked questions
Will changing protection interrupt email?
The change plan includes mail-flow tests and a rollback path. The required maintenance arrangements depend on the existing architecture.
Does Microsoft protection cover Gmail in the same way?
Do not assume equivalent coverage. Native Office 365 controls and supported cross-platform integrations are reviewed against the actual mail system.
Is data loss prevention automatically included?
No. DLP, archiving, awareness and advanced response are checked separately against the selected subscription.
Discuss the requirement
Tell us what you need to protect, change or recover. We will use the details to define the next technical discussion.
Prefer to talk? Call +966591909277
