Buyer's guide · Microsoft 365 email

If a phishing email lands, how long before someone clicks?

Verizon puts it at 21 seconds. Microsoft 365 catches most of what arrives, and for many organizations that is enough. The problem is the small number of messages built to have nothing worth catching. No attachment, no link, only a phone number.

Book a call and we will set it up How this works

Every figure here is traced to a primary source and dated. 7 minute read · Updated .

Why is Microsoft 365 filtering not enough on its own?

Targeted addresses potentially compromised
48%

The Mirage2FA kit reached around 4,500 organizations across the US and EU this year. It defeats two-factor by stealing the session cookie after login, so there is no payload to detect.

Business email compromise losses, 2025
$3.04B

Reported to the FBI in a single year. Phishing losses tripled, from $70M to $216M, while complaint volume stayed flat. Not more mail. Better mail.

Gartner's advice is to layer rather than switch. Their December 2025 research tells buyers to pair a core solution with specialized vendors, and Microsoft is a Leader in that research. This is the second layer, not a replacement.
At enterprise scale it is the same gap, typically in four more places.
  • More tenants than anyone has a current list of
  • Acquired domains still routing mail their own way
  • Shared mailboxes nobody owns
  • Finance teams in several countries, each with its own payment habits

Mirage2FA, The Hacker News, Aug 2026  ·  Losses, FBI IC3 2025 Internet Crime Report  ·  Layering, Gartner Magic Quadrant for Email Security, 1 Dec 2025

Find out which of these applies to you

We attach in read-only monitor mode and show you what your filtering already allowed through. Fifteen minutes to set up, and the findings stay yours.

Book a call

What is the difference between pre and post-delivery email security?

Both are sold as API based email security. The difference is measured in seconds and easy to miss on a datasheet.

Verizon puts the median time to click a phishing link at 21 seconds, and 28 seconds more to submit credentials. Under a minute from delivery to compromise.

Any window between delivery and removal is a window your people are already moving through. The practical difference

Verizon Data Breach Investigations Report. We do not use the 183 second figure that circulates in vendor material, because it does not match the report.

Check Point, on Microsoft
Microsoft, as well as Google, is the training ground. Their point, not ours. Attackers rehearse against a free tenant running the same defenses as the target. Check Point, Essential Guide to Email Security.

Can email security stop phishing with no link or attachment?

This is the case that makes timing decisive. Every control downstream of delivery has nothing to work with.

Over fourteen days in August 2026, Check Point caught 24,700 copies of one campaign across 9,000 organizations. The message offered a hardship program and gave a toll free number. The attack completed on the phone, where the caller was asked for bank details or a payment.

What a filter looks forPresent in the message
MalwareNone
AttachmentNone
Malicious linkNone
Spoofed login pageNone
A phone numberThe entire payload

After someone places the call, sandboxing, URL rewriting and click-time checks no longer apply. Nothing else in the stack can step in. The only control left is the message itself, so it matters whether that control runs before delivery or after.

Check Point, debt relief phishing disclosure, 25 August 2026. No named group was attributed.

How is this different from Abnormal or other API based tools?

Almost every modern email security product connects through the Microsoft 365 API. The difference is what it may do once connected.

 Check PointPost-delivery API tools
When it actsBefore delivery. The message never reaches the mailboxCheck Point product documentationAfter delivery. It reaches the mailbox, then is withdrawn
Against a no interaction attackNever delivered, so never triggeredRemoval after the fact does not undo it

Be fair about where the other approach is strong. Behavioral detection of business email compromise is good in this category, and for many organizations post-delivery removal is fast enough. The argument is timing, not whether these products work.

If your vendor says pre-delivery is coming, ask how. Gartner's December 2025 research says post-delivery vendors add it by taking your MX record or rewriting your mail flow rules. That is the gateway model they spent a decade telling you to leave, and Gartner warns it adds latency and disruption. A retrofit is not an architecture.

Gartner Magic Quadrant for Email Security, 1 December 2025. Deployment behavior from vendor documentation.

Guide to Blocking Attacks Before the Inbox
Published by Check Point. Six pages, no registration.
Read the guide

When do you not need this?

We sell this, so the useful thing we can tell you is when the answer is no. If all four are true, this is not your next spend.

Spend on identity and payment verification instead. Both remove more risk and cost less.

Where it does earn its place

What does the assessment tell you?

It answers the one question almost nobody can answer. What is sitting in your users' inboxes that your filtering already passed.

What comes back
  • →Credential phishing that cleared Microsoft, still in mailboxes now.
  • →Vendor and executive impersonation, including those with no link or attachment to flag.
  • →Accounts showing signs of takeover, and internal mail a gateway never sees.
How it runs
  • →Read-only, in monitor mode. Nothing blocked, quarantined or rerouted.
  • →No MX change, no agents, no downtime. Fifteen minutes to connect, then a week or two.
  • →You keep the findings either way, and can disconnect at any point.

Book a call and we will set it up

Book a call and we will set it up

Questions people ask before connecting

Will this change how our email works?

No. It connects through the Microsoft 365 API in monitor mode, which reads and reports. Nothing is blocked, quarantined or rerouted. No MX change, no agents, no downtime.

Where does our email data go?

Check Point processes mail through its own cloud, like every cloud email security product. Before you connect anything we send you their current security and compliance documentation, including certifications and data residency options.

How is this different from Abnormal or other API based tools?

Timing. Abnormal connects after delivery and removes malicious mail once it has reached the inbox, which Abnormal presents as a design choice rather than a limitation. Check Point blocks before delivery. Against an attack needing no interaction, removing it afterwards changes nothing.

What does Check Point Email Security cost?

It is quoted through partners rather than published, so we scope it against your actual mailbox count. Seat count and module mix both drive it, and the rate moves with volume, so a figure from one size tells you little about yours.

Who is behind this

TechPower is an advisory led technology partner. We evaluate, procure, deploy and support security and infrastructure for enterprise and mid-market organizations, and stay accountable for it afterwards rather than handing it off.

Who does the work

Jarrod Downs, our network architect, runs the technical side of every email engagement, from connecting the assessment through deployment and tuning. You meet him on the first call.

Why Check Point

We carry a deliberately small set of partners rather than a catalog. Check Point earns its place here because it blocks before delivery.

Delivery

Implementation and support run through our own team. We do not subcontract deployment, and the people who scope the work run it.

Connect it read-only, see what your filtering passed, and we will tell you honestly whether this is the right next spend.

Book a call and we will set it up
© 2026 TechPower International Inc. · Sources are cited beside each section.
techpower.com