Skip to content

Cybersecurity Insights

Does Your Email Configuration Actually Follow Your Security Policy?

Posted in IT Policy Development, IT Risk Assessments

Email Configuration Actually Follow Your Security Policy

Most companies have an email security policy.

The policy might tell employees to use company email for work, block forwarding messages to personal accounts, and set rules for handling sensitive information, attachments, passwords, retention, and access.

The policy may look reasonable.

But there is an important question many businesses don’t ask:

“Does your email environment actually enforce the security requirements in your policy?”

Even with a well-written email security policy, a company might still have forwarding rules that send messages outside, former employees who can access mailboxes, shared accounts without clear accountability, employees using personal email for work, or third-party systems sending company information outside the business.

The problem isn’t necessarily the policy.

The problem is the gap between what the company says should happen and what is actually allowed.

This gap is important because email remains one of the main ways attackers target businesses.

Your Security Policy Is Only as Good as Its Implementation

A security policy describes how a company expects employees and the IT environment to operate.

But what actually happens depends on your email system.

These two things should match.

Consider a simple example.

Your company policy says employees should not automatically forward company emails to personal accounts.

That seems simple enough.

But does your Microsoft 365 environment actually prevent forwarding?

If an employee creates an automatic forwarding rule that sends company messages to Gmail, does anyone know?

Does the security team receive an alert?

Can administrators identify every active forwarding rule?

Does the company review those rules on a regular basis?

If you can’t answer these questions, your company might have a policy that says one thing, but your email setup allows something different.

That is a security problem.

The Email Security Policy and Reality Gap

Security policies usually describe an organized and controlled environment.

Employees use company accounts. Business information remains inside approved systems. Access gets removed when employees leave. Sensitive information receives appropriate protection. Email accounts have appropriate security controls.

But real businesses are rarely that simple.

Employees travel. Executives work from home. Contractors need access. Employees create temporary workarounds. Departments establish shared mailboxes. Vendors need to communicate with employees. Someone creates a forwarding rule while on vacation and forgets about it.

None of these actions necessarily involve malicious intent.

This is exactly what makes them hard to notice.

Security problems don’t always begin with someone deliberately trying to circumvent security.

Sometimes they begin with someone trying to do their job.

Email Forwarding Can Create a Blind Spot

Automatic email forwarding deserves particular attention during an IT security review.

An employee may forward company email to a personal account because it is convenient. An executive may want access to messages from another device. A contractor may prefer using an account they already monitor.

The company often can’t see what happens once a message leaves its email system.

Once a sensitive email reaches an external account, the company may lose control over the device, security settings, retention, authentication, and other protections around that account.

This creates a security situation that is very different from what the company’s policy describes.

A review of email security should therefore look beyond whether the policy allows forwarding.

It should determine whether forwarding actually occurs and whether the company has controls around it.

Shared Mailboxes Can Create Accountability Problems

Shared mailboxes create another common disconnect between policy and implementation.

A company might have an address such as billing@company.com, support@company.com, or sales@company.com. Multiple employees need access, so the business creates a shared mailbox.

This setup is not automatically insecure.

The problem occurs when shared access eliminates accountability.

If employees share a password instead of using individually authenticated access, the company may struggle to determine who accessed an account or sent a particular message.

Even when a platform supports proper shared mailbox permissions, you still need to review access.

Who has access today?

Does everyone who had access six months ago still need it?

Does a former employee still have permission?

Does a contractor still have access after the project ended?

A security policy might say only authorized employees should have access, but the only way to verify is to check how everything is actually set up.

Former Employees Can Leave Behind More Than a Laptop

Employee termination procedures often focus on disabling the user’s primary account.

But email access can exist beyond the employee’s mailbox.

A former employee may have access through a shared mailbox, delegated permissions, distribution groups, mobile devices, third-party applications, forwarding rules, or other integrations.

This is where email security ties into the bigger picture of identity and access management.

The question isn’t simply:

“Did we disable John Smith’s account?”

It is:

“Did we remove John’s ability to access company information?”

Those are not always the same thing.

Personal Email Creates Another Security Boundary

Businesses should also consider what happens when employees use personal email accounts for business purposes.

An employee may send a document to a personal account because they need to work from home. An executive may use a personal address to review information while traveling. A contractor may communicate from a personal mailbox because the company’s onboarding process isn’t complete.

The reason may seem harmless.

But the security risks are not always so harmless.

Once business information moves into a personal email environment, the company may lose visibility and control over how that information is stored, accessed, retained, forwarded, or protected.

For companies handling sensitive financial information, customer data, health information, intellectual property, or confidential business information, this risk matters most.

Are Your Email Security Controls Consistent With Your Policy?

A useful email security review should compare the written policy with the actual configuration.

For example, if the policy prohibits external forwarding, the review should verify whether external forwarding is actually restricted or monitored.

If the policy requires strong authentication, the review should examine whether multi-factor authentication applies to the appropriate accounts.

If the policy requires limiting access based on business need, administrators should review mailbox permissions and delegated access.

If the policy requires sensitive information to receive additional protection, the company should determine whether its email platform actually provides the controls needed to enforce that requirement.

This is what separates just reviewing a policy from making sure it actually works.

Reading a policy tells you what the company intends to do.

Testing the environment with regularly scheduled IT Risk Assessments or IT Audits tells you what the company actually does.

Microsoft 365 Makes This Particularly Important

If your business uses Microsoft 365, email security involves more than just turning on spam filters.

Microsoft 365 provides a broad range of security and administrative capabilities, but they still require proper configuration and ongoing management.

A company’s security can be affected by settings related to authentication, mailbox access, forwarding, external sharing, mobile access, administrative privileges, email authentication, threat protection, and other Microsoft 365 controls.

So, a company might have a strong Microsoft 365 security policy but still have weak spots in its setup that put the policy at risk.

That is why a Microsoft 365 security review should evaluate both configuration and governance.

Email Authentication Is Part of the Picture

Businesses should also consider the controls that protect their domain from email impersonation.

Technologies such as SPF, DKIM, and DMARC help businesses establish how email claiming to come from their domain should be handled.

These tools do not replace employee security awareness or other controls, but they can reduce domain spoofing by making unauthorized email activity easier to notice.

A company’s email security policy should match how its domain is actually configured.

If an IT security policy states that the company has controls limiting unauthorized use of its domain, the technical configuration should support that claim.

Don’t Forget Third-Party Applications

Businesses don’t send all of their email directly from their primary email platform.

Marketing platforms, customer relationship management systems, accounting applications, ticketing systems, payroll platforms, calendar systems, and other services may send messages using the company’s domain.

These systems create additional email paths.

That raises several questions.

Does the company know which services are authorized to send email on its behalf?

Are those services configured securely?

Are employees approving new applications without considering email security?

Does the company’s email security policy include third-party services?

Are former vendors still authorized to send messages using the company’s domain?

Email security can become complicated quickly when many different services are used in your company’s IT environment.

Security Policies Should Reflect What You Can Actually Enforce

When a company discovers a difference between its IT security policies and its technology, it has a decision to make.

The first option is to change the technology or business process to comply with the policy.

The second is to change the policy so it accurately describes how the business operates.

Sometimes the policy needs to change.

Sometimes the technology needs to change.

In many cases, both the policy and the technology need review.

Businesses should avoid leaving this gap unresolved.

A policy that says employees cannot forward company email externally doesn’t provide much protection if external forwarding remains unrestricted and nobody monitors it.

Likewise, a policy that requires personal accountability doesn’t accomplish much if employees continue sharing credentials.

The goal is not to create the strictest policy possible.

The real goal is to have a policy that fits your company’s risks and can actually be put into practice.

How to Test Whether Your Email Security Policy Matches Reality

Start with an evidence based IT Risk Assessment rather than make assumptions.

Review your organization’s email configuration and compare it with the requirements in your security policies. Look at forwarding rules, mailbox permissions, shared mailboxes, administrative access, authentication settings, external email activity, and third-party applications that interact with your email environment.

It may help to review the article we wrote on the hidden risks of Microsoft 365 misconfigurations.

Then look at the people using the system.

Do executives, employees, contractors, and temporary workers follow the same requirements? Are exceptions documented? Are those exceptions still necessary?

Finally, determine whether someone is responsible for periodically reviewing the configuration.

Email security is not something you check once and then forget about.

Employees change roles. Vendors change. Microsoft 365 settings change. New applications get connected. New business processes develop.

Your environment can change even if your policy stays the same.

What Happens When Policy and Technology Don’t Match?

A mismatch doesn’t automatically mean your company has suffered a security incident.

It does mean the business has identified a potential control gap.

The appropriate response depends on the gap’s nature and the information involved.

A company may decide to change a technical configuration, improve monitoring, update a policy, provide additional employee training, restrict an application, remove unnecessary access, or formally document an accepted risk.

The important part is that someone identifies the difference and makes a conscious decision about it.

Ignoring these gaps is rarely a good way to manage risk.

Email Security Should Be a Part of the Annual IT Risk Assessment

Email is only one part of a company’s cybersecurity environment.

Still, email is a good example of a bigger security principle:

“Your security policies should describe the security controls your company actually has implemented.”

The same concept applies to all IT security policies (password policies, access control, incident response, vendor management, data protection, remote access, and mobile devices).

A company might have great documentation but still face major security gaps if no one checks that the controls in the documents are actually in place.

That is why security assessments should evaluate both password policies.

Let us know if you need help drafting IT security policies or want to know elements of an effective IT security policy.

Tanner Security Can Help Identify the Gaps

At Tanner Security, we help businesses assess whether their security practices align with their policies, risk requirements, and applicable IT frameworks.

An assessment can examine more than whether a company has the right documents. It can also evaluate whether security controls are implemented and whether they provide the protection the business expects.

For companies using Microsoft 365, this may include reviewing email and identity security configurations alongside broader IT security controls.

The goal is not just to have policies that look good for an audit.

The real goal is to help businesses set up security practices that actually work every day.

Your Security Policy Must Match Your Security Environment

A security policy is a good place to start, but it does not prove that a control is really in place.

If your policy says employees cannot forward company email to personal accounts, verify that forwarding is actually controlled.

If your policy requires individual access, verify that shared credentials aren’t undermining accountability.

If your policy requires sensitive information to remain within approved systems, determine whether employees and third-party applications can move that information outside those systems.

If you have not compared your policies to your actual technology setup recently, now might be a good time.

The question isn’t whether your company has an email security policy.

The question is whether your email environment actually follows it.

Related Cybersecurity Services

Email security is rarely a stand-alone issue. Email policies should fit with the company’s overall security program, and technical controls should support those policies.

IT Risk Assessments: An IT security assessment takes a broader look at your company’s security. Instead of just checking one technology, it reviews controls, policies, access management, vulnerabilities, and other factors that affect your overall cybersecurity risk. If you want to know if your security program works in real life, an IT security assessment or a NIST, ISO 27001, CMMC, HIPAA, PCI, or a NCUA assessment can give you a helpful outside review.

Microsoft 365 Security Review: If your business uses Microsoft 365, an assessment can review your setup and identify potential weak spots in identity, authentication, email, permissions, admin access, and other security controls.

This helps you see if your Microsoft 365 setup matches your company’s written security policies.

IT Policy Development and Review: A security policy should reflect how your company actually operates and the risks it needs to manage. Tanner Security can help businesses create, review, and update IT and cybersecurity policies so they provide real, useful guidance, not just meet paperwork requirements.

Policy reviews can also show when written rules no longer match the company’s technology or business practices.

Governance, Risk, and Compliance Consulting: GRC provides a broader framework for linking cybersecurity policies, business risks, technical controls, and compliance needs.

Reviewing an email policy can uncover a specific security gap, but GRC helps you see the bigger picture. The company can identify who owns the risk, its impact, how to fix it, and how leaders should track it.

IT Audits: An IT audit gives an outside review of your technology controls, policies, procedures, and security practices.

If you are worried your written security rules do not match what is really happening, an IT audit can help you find gaps and give management a clearer view of the company’s technology risks.

Cybersecurity Consulting: Sometimes a business knows its security policies and technology do not match up, but it is not sure where to begin.

Cybersecurity consulting can help you identify the biggest gaps, choose practical solutions, and build a security program that fits your business, technology, and risk needs.

Is Your Email Security Policy Consistent with Reality?

A written policy is important for cybersecurity, but the document alone does not protect your business.

Your technology and employees need to follow the rules in the policy.

If your company bans external email forwarding, can you show that forwarding is controlled? If your policy calls for individual accountability, can you name everyone with access to shared mailboxes? If sensitive information should stay in approved systems, do your technical controls really keep it from leaving?

These questions help turn a security policy from just a document into a working security control.

Tanner Security can help your business check if its cybersecurity policies, technical controls, and real business practices all line up.

Contact Tanner Security to discuss an IT security assessment, Microsoft 365 security review, IT policy review, or GRC consulting.

Tanner Security can help your business find the gap between written security policies and real security controls. Contact us to discuss an IT security assessment, policy review, or Microsoft 365 security assessment.

Contact Form

Name*
Please let us know what's on your mind. Have a question for us? Ask away.

Schedule a Call

Name*
Please let us know what's on your mind. Have a question for us? Ask away.