Skip to content
TRILOGY

Protect the inbox. Verify the message. Reduce account risk.

Design email protection around your actual mail platform, users and threat exposure. TRILOGY scopes the delivery architecture, configures the selected policies and verifies protection without assuming that every capability is included in one license.

When this solution is relevant

  • Phishing and impersonation

    Review protection for malicious links, attachments and deceptive sender identities.

  • Business email compromise

    Address payment-change requests, executive impersonation and suspicious conversation patterns.

  • Cloud mail protection

    Select gateway, API-based or native controls suited to Microsoft 365 or another supported platform.

  • Investigation and remediation

    Define message tracing, quarantine ownership and supported post-delivery actions.

Technology options

Technology options to evaluate against your requirement. Product capabilities, editions and integrations are confirmed in the agreed configuration.

  • Abnormal AI

    Abnormal AI — Inbound Email Security / Account Takeover Protection

    • Behavioral analysis detects impersonation and business email compromise
    • Inbox remediation removes detected malicious messages
    • Account takeover protection is scoped as a distinct capability
    Official product reference
  • Microsoft

    Microsoft — Defender for Office 365 — Plan 1 / Plan 2

    • Plan 1 provides Safe Links, Safe Attachments and anti-phishing protection
    • Plan 2 adds automated investigation, response and attack simulation training
    • Plan 1 is included in Office 365 E3 and Microsoft 365 E3 from 1 July 2026; confirm tenant entitlements
    Official product reference
  • Mimecast

    Mimecast — Advanced Email Security

    • Gateway-based protection for inbound email traffic
    • API-based options for cloud email deployment
    • BEC defense and targeted-user visibility within the selected package
    Official product reference
  • Proofpoint

    Proofpoint — Core Email Protection / Targeted Attack Protection

    • Email threat protection across the selected delivery architecture
    • Targeted Attack Protection adds specialized protection against targeted threats
    • Related collaboration, awareness and data-protection modules are separately scoped
    Official product reference
  • Barracuda

    Barracuda — Email Protection

    • Layered email protection with gateway and API-based components
    • Impersonation and account-takeover protection for supported cloud environments
    • Incident remediation and additional services depend on the selected plan
    Official product reference
  • TrendAI

    TrendAI — Trend Micro enterprise business — TrendAI Vision One Email and Collaboration Security

    • Protection for email and supported collaboration services
    • Centralized detection insights within Vision One
    • Packages and credits determine the enabled protection capabilities
  • Broadcom

    Broadcom — Symantec — Email Security.cloud / Messaging Gateway

    • Email Security.cloud provides cloud-delivered email filtering
    • Messaging Gateway supports appliance-based deployment
    • DLP, encryption and advanced response require the appropriate modules
    Official product reference

Names and trademarks belong to their owners.

What we verify

  • Protection coverage

    Users, domains and mail flows included in the agreed configuration.

  • Authentication alignment

    Observed SPF, DKIM and DMARC results for approved sending sources.

  • Test outcomes

    Safe phishing and attachment scenarios, including false positives.

  • Remediation evidence

    Recorded quarantine, release and post-delivery remediation outcomes.

How the technical work is scoped

01

Scope and architecture

Define the assets, integrations, ownership and acceptance criteria before selecting the configuration.

02

Implementation and change

Configure the agreed controls through an approved change plan, with rollback steps and assigned responsibilities.

03

Verification and handover

Test agreed scenarios, record exceptions and hand over the configuration, operating procedures and test evidence.

An employee at a laptop beside a printed invoice and an orange sticky note

Technical scope in detail

Mail-flow architecture

The design documents MX records, connectors, APIs and existing controls. Changes are staged to preserve legitimate mail delivery. Acceptance tests cover inbound, outbound and relevant internal traffic.

Domain authentication

Authorized sending services are inventoried before SPF, DKIM or DMARC changes. Policy enforcement is introduced after reviewing alignment and reporting. Authentication reduces specific spoofing paths; it does not eliminate every impersonation technique.

People-targeted threats

Policies account for executives, finance teams and other exposed roles. Test scenarios use approved safe content. Exceptions and false positives are reviewed with the business owner.

Microsoft 365 licensing

Defender for Office 365 Plan 1 and Plan 2 provide different capabilities. Tenant entitlements are checked before enabling automation or simulation. Microsoft Purview data-protection requirements are scoped separately.

Operational handover

Quarantine permissions, escalation and message-remediation procedures are documented. Tests record the actions available for the chosen deployment. Retention and privacy requirements govern the investigation data.

Licensing and sizing

Review protected users, domains, mail platform, deployment model and selected modules. Confirm the tenant’s existing entitlements before adding licenses; advanced response, awareness, archive and DLP may have separate requirements.

What to share with us

Mail platform; domains and user counts; sending services; existing subscriptions; investigation owner.

What you receive

  • Agreed scope and architecture

  • Selected configuration and integration record

  • Approved change and rollback plan

  • Test record and documented exceptions

  • Operating procedures and technical handover

Frequently asked questions

Will changing protection interrupt email?

The change plan includes mail-flow tests and a rollback path. The required maintenance arrangements depend on the existing architecture.

Does Microsoft protection cover Gmail in the same way?

Do not assume equivalent coverage. Native Office 365 controls and supported cross-platform integrations are reviewed against the actual mail system.

Is data loss prevention automatically included?

No. DLP, archiving, awareness and advanced response are checked separately against the selected subscription.

Discuss the requirement

Tell us what you need to protect, change or recover. We will use the details to define the next technical discussion.

Prefer to talk? Call +966591909277

We use the information you provide to respond to your request. Read our privacy notice for details.