Email filtering
Spam and phishing filtering on the mailbox, plus the domain-level records that make it harder for someone to send email pretending to be your business.
Cybersecurity essentials / The layers behind security basics
Maintenance and security rhythm names practical security hygiene as part of managed IT without listing what it actually contains. This page names the layers - email filtering, endpoint protection, sign-in habits, and the phishing recognition employees can actually learn - plus the honest line about what still needs a specialist.
Read this page in FrenchFour ordinary layers
No single tool stops every attack. A realistic security posture layers several ordinary pieces of work on top of each other, so a missed patch, a clicked link, or a reused password does not become the only thing standing between an employee and a serious incident.
The layers, named
Spam and phishing filtering on the mailbox, plus the domain-level records that make it harder for someone to send email pretending to be your business.
Antivirus and malware protection running on every managed laptop and desktop, kept current the same way any other software gets updated.
Multi-factor authentication and the access habits covered in more depth on its own page - the two topics overlap constantly in practice. See identity and access as its own rhythm
Specific, practical habits employees can actually learn - checking the sender address, hovering before clicking, and knowing the one number to call when something looks wrong - not a generic reminder to “be careful.”
What's real / what is not claimed
What's realMailbox filtering, endpoint protection, sign-in security, patch discipline, and staff-facing phishing habits, applied consistently across the devices and accounts actually in scope.
What is not claimedA dedicated security operations centre, a guaranteed detection or response time, or a specific compliance certification. Exact tools and coverage are confirmed in writing, not on this page.
A real baseline, tested
Routine versus urgent
Catching and cleaning up an ordinary phishing attempt is routine work. A confirmed compromise - an account actively being used by someone else, files already encrypted - needs an incident-response conversation with its own scope and its own urgency, not a ticket in the regular queue. See how incident readiness connects to Law 25 and PIPEDA
Next step
The service map turns your context into a short, copyable list: people, devices, Microsoft 365, vendors, and decisions to clarify.
Build the service map