Email security

Email Security for New Zealand Organisations

Most attacks still start with an email. We screen every message, link and attachment before it reaches your people, inside Microsoft 365, using Check Point Email Security, so your team can open their inbox with confidence.

Why it matters

Your inbox is the front door

Phishing, invoice fraud and impersonation are not clever technical exploits. They are messages designed to look ordinary, arriving on a busy day. Good email security removes those messages quietly, recognises the ones that imitate people you already deal with, and gives your team a simple way to report anything that feels off.

Most days, nobody notices it is there. That is the point.

What it covers

Six things that happen before an email reaches you

Every message is checked on the way in, on the way out, and again at the moment someone clicks.

Phishing and impersonation

Messages that pretend to be your bank, a supplier or your own leadership team are recognised by who they claim to be and how they behave, not just by a blocklist.

Malicious links and attachments

Links are checked at the moment of click, not only on arrival, and attachments are opened in a safe environment before your people ever see them.

Account takeover

Unusual sign-ins, inbox rules that quietly forward mail, and sudden changes in sending behaviour are flagged, so a compromised account is caught early.

Internal and outbound mail

Because the protection sits inside Microsoft 365, mail between colleagues and messages leaving your organisation are covered as well as what arrives.

Teams, SharePoint and OneDrive

Files shared through Teams and SharePoint get the same scrutiny as email attachments, so the protection follows the way people actually work.

Spam and clutter

Ordinary junk is filtered before the inbox, with a simple daily digest and one-click release, so genuine mail is never lost.

How it works

Protection that sits inside Microsoft 365, not in front of it

Traditional email gateways sit outside your mail system and only see what passes through them. Check Point Email Security connects directly to Microsoft 365, so it sees every message, internal and external, and can remove a threat from an inbox even after it has been delivered. There is nothing to change in your mail flow, no new logins for your people, and it is running within hours rather than weeks.

IT Works sets the policies, tunes them to how your organisation communicates, reviews what was caught, and handles the conversation when something needs a human decision.

Why IT Works

Practised on ourselves, not just recommended to you

Every email IT Works sends passes through the same protection we run for clients, which is why you will see a small note about it at the bottom of our messages. Email security is one layer of the security foundation that comes with our managed IT plans, alongside endpoint protection, identity security and managed detection and response.

Our own operations are independently assessed under SOC 2 Type 2 and certified to SMB1001 Gold, so the standards we ask of your environment are ones we already live with in ours. Check Point is one of the platforms on our technologies page, chosen because it was built for Microsoft 365 rather than adapted to it.

Common questions

Questions we get asked about email security

Short answers. Ask us for the longer ones.

Does Microsoft 365 already do this?

Microsoft’s built in filtering is a good baseline and we keep it switched on. Check Point adds a second, specialised layer aimed at the attacks designed to get past a single filter, particularly impersonation and account takeover, and gives us far better visibility of what is happening.

Will it block genuine mail?

Very rarely. The policies are tuned to your organisation over the first few weeks, anything held back appears in a daily digest, and anyone can release a message they recognise in one click.

What happens if something gets through?

Nothing is perfect, so the process matters. A reported or detected message is removed from every inbox it reached, the account is checked, and we tell you what happened in plain English. If your plan includes managed detection and response, the wider environment is checked at the same time.

Do our people need training as well?

Yes, and the two work best together. Technology removes most of the risk; awareness training and simulated phishing help your people handle the small amount that remains. Both are part of our cybersecurity foundation.

Next step

See what your inbox is dealing with today

A short conversation is enough to show you what is arriving, what is being caught, and what a quieter inbox could look like for your team. No pitch, no pressure.