A message that gets obeyed.
The most expensive attacks on small businesses are rarely technical. A supplier you deal with sends new bank details. A colleague asks for the payroll file. An invoice matches a job you really are doing. Each of those reads as an ordinary request, down an ordinary channel, from an address that looks entirely correct.
Nothing was hacked, in the way people mean it. Somebody was persuaded. That is the threat this rung is built for.
In the mailbox itself, not ahead of it.
Ironscales does not stand in front of your mail as a gateway. It attaches to Google Workspace or Microsoft 365 through the interface those platforms publish. Two consequences follow, and both are worth grasping before you buy.
The first is deployment: nothing about your mail routing changes, there are no records to repoint, and there is no cutover evening. The second matters far more. Because it works inside the mailbox, a message that turns out to be malicious can be pulled back out of every inbox that received it, including inboxes where it has already been opened. A gateway has no way to do it: by the time anyone knows, the message is long past it.
Practice, not a lecture.
Training that consists of an annual video changes nothing. What works is regular, safe imitation: a realistic message arrives, and the people who click get a short lesson at the exact moment the mistake is fresh.
Just as usefully, staff get a button that reports anything suspicious, and those reports are worked rather than filed. Over a few months you get a report showing which teams have improved, which is the only measure of this that means anything.
What you should expect.
Somebody with administrative rights on your mail platform has to approve the connection. It takes minutes, but it needs the right person, and that is worth lining up in advance of the purchase rather than afterwards.
Expect the first weeks to include a few messages held that should not have been. Report them and the behaviour adjusts. Expect, too, that some of your staff will fail the first drills. That is the point of running them privately rather than finding out during a real attempt.
Lines on this rung
2 lines · rates per unit, per monthMailbox Defense with Training
Protection that lives in the mailbox itself instead of standing ahead of it. Your mail routing is untouched and there are no records to repoint. A message later judged malicious is retracted from the inboxes already holding it, opened copies included. Phishing drills and lessons come with the same mailbox.
- Attaches to Google Workspace or Microsoft 365 through the interface those platforms publish.
- Messages already delivered can be pulled back out of every mailbox that has one.
- Impersonation of your own staff is caught by how the sender actually behaves.
- Staff report a suspicious message with a button, and reports are worked.
| Model | Mailbox level, through the mail platform API. Not a gateway |
|---|---|
| Deployment | No mail exchanger record changes and no routing change |
| Removal | Delivered mail retracted wherever it landed, opened copies included |
| Impersonation | Detected from sender behaviour rather than a static list |
| Training | Phishing drills and lessons included for each licensed mailbox |
| Priced by | Mailbox, monthly |
monthly, taken in advance QTY
Phishing Drills and Training
Training on its own, for people who need the practice without a licensed mailbox on the same platform. Safe imitation phishing lands in the inbox on a schedule, and the people who click get a short lesson rather than a scolding.
- Campaigns run on a schedule so it becomes routine rather than an event.
- Lessons are minutes long and given at the moment of the mistake.
- Reporting shows movement over time, by team.
- A reporting button teaches the habit of flagging rather than deleting.
| Content | Simulated phishing plus short remedial lessons |
|---|---|
| Cadence | Scheduled campaigns, difficulty raised over time |
| Reporting | Per team results tracked across months |
| Best fit | Staff without a licensed mailbox on the covered platform |
| Priced by | User, monthly |
monthly, taken in advance QTY
Where this rung stops
This rung covers mailboxes on Microsoft 365 and Google Workspace, and the training of the people using them. Some things sit outside it.
- Mail hosted somewhere without a supported interface cannot be protected this way. If you are on an older on premises mail server, tell us and we will be straight about the options.
- Text messages and messaging applications are outside this line. Phones themselves are covered on rung 04.
- A payment made from a genuine account by a person who was persuaded is not something any mail product reverses. Training lowers the odds; a second human check on bank detail changes lowers them further.
- Training results describe behaviour, not certainty. Somebody who passes every drill can still have a bad Friday.
- A live break in is worked by the operations team through support, not by adding a subscription line. Say what you are seeing and we will tell you what happens next.
One more thing, stated where you can see it before you buy. Everything on this page is protective coverage bought in advance. It is not an emergency incident response retainer, and it does not put a responder on your site tomorrow because you subscribed today. An engagement of that kind is arranged directly with the Fortify 24x7 operations team. If something is under way as you read this, the quickest route to us is support@cyberthreat.help, or a case raised from your client portal.