Phishing is any message built to look legitimate so you will hand over a password, wire money, or open something that installs malware. It usually arrives by email — and increasingly it does not. The single most important thing to understand is this: you cannot judge a phishing attempt by how professional it looks. Attackers now write clean, well-formatted, personalized email, spoof real brands convincingly, and often send it from an account that genuinely belongs to someone you know. What still gives them away is the request — and a handful of checks anyone can learn in a few minutes.
This guide covers how to spot phishing in every form it now takes: the classic phishing email, the fake IT support message in Microsoft Teams, the follow-up phone call, the sudden flood of spam that turns out to be a setup, and the counterfeit Microsoft sign-in page that defeats multi-factor authentication. It is written for the people in your business who actually receive these things. Read it, share the link with your team, and bookmark it for onboarding. If you would rather not rely on human judgment alone, skip ahead to managed email security and browser protection — the layers that catch what training misses.
If you remember nothing else, remember these six steps. Run them on any email, chat message or call that asks you to do something.
If any one of these fails, stop and report it. You do not need to be certain an email is malicious. You only need to be unsure. Reporting a legitimate email by mistake costs a minute of someone’s time. The other mistake costs considerably more.
The same six checks apply to a Teams message, a text or a phone call. One of the most effective attacks running right now arrives that way instead — see fake IT support and Teams phishing below.
People are often surprised that a phishing email reached them at all. The reason is that there is frequently nothing technically wrong with it. Anyone can register an address like [email protected] and send a link or a file, and no filter can reliably distinguish that from a colleague sending a funny link from [email protected]. The message is well-formed, the sending domain is real, the link may point to a page that was harmless when the email was delivered. The malice lives in the intent, and intent is not a header value.
This is why the most damaging attacks — the ones that redirect a wire transfer or drain a payroll run — frequently contain no link and no attachment at all. Just a sentence in an email from a real account. Basic filtering was never designed to catch that, which is exactly the gap dedicated email security is built to close.
Anyone can put any name they like on an email account. Nobody can fake the domain after the @ symbol on a real, uncompromised account. Consider these two senders:
They display an identical name. Only one of them is actually coming from Microsoft. On a phone, many mail apps show only the display name by default — tap it to expand the full address before you act on anything.
Attackers register domains built to survive a glance and fail a second look:
The habit worth building is reading a domain backwards — find the .com or .net, then read the word immediately to its left. That is the organization you are actually dealing with.
This is the point most training programs undersell. An email can come from the genuine, correctly spelled domain of a client, vendor or coworker and still be an attack — because that person’s account has been compromised. Compromised-account phishing is among the hardest kinds to detect precisely because every technical signal checks out.
If a request does not make sense, do not reply to the email to ask whether it is legitimate. If the account is compromised, the attacker controls the reply and will simply tell you yes, that is really me. Instead, call a phone number you already have for that person or company — from your own records, a signed contract, or the company’s website that you navigated to yourself. Never use a phone number supplied in the suspicious email. If you cannot reach anyone, do nothing: don’t reply, don’t click, don’t open the attachment.
Phishing is often sent to people who have never done business with the sender. Treat outreach from unfamiliar companies and contacts with extra caution, especially when it involves money, credentials or a file.

Bad grammar is no longer a reliable indicator. Poor spelling and awkward phrasing used to be one of the best tells available. AI writing tools have ended that. Attackers now produce flawless, professional, correctly localized email at scale. Grammar mistakes are still worth noticing when present, but their absence tells you nothing at all. Do not rely on this one.
Microsoft does send security emails. The old advice that Microsoft never emails you about your account is out of date — legitimate notices about password expiration, mailbox storage and sign-in activity are routine. The better test is this: a legitimate Microsoft email will never contain a link that takes you straight to a page asking for your password. Whenever you need to act on one, open a browser yourself and sign in at an address you typed or bookmarked. Never through the link in the email.
Most phishing awareness material still describes attacks from a decade ago. These are the patterns actually costing Colorado businesses money right now.
Business email compromise (BEC) frequently involves no link and no attachment. It is a spoofed or genuinely compromised account — an executive, a vendor, a title company, a lender — asking someone in accounting to send a payment, change banking details, or buy gift cards, urgently. The FBI’s Internet Crime Complaint Center consistently reports BEC among the costliest categories of cybercrime, far exceeding ransomware in dollars lost, because a successful one moves real money in a single transaction.
The defense is procedural, not technical: verify every unusual or changed payment instruction by phone, on a number you already had, before acting. No exceptions for urgency, and no exceptions for the CEO. Build it into your accounting process so nobody has to make a judgment call under pressure.
If you receive repeated multi-factor approval prompts you did not trigger, that is somebody attempting to log in with your stolen password, hoping you will tap Approve out of annoyance, confusion or habit. Never approve a prompt you did not personally start, and report it immediately — a burst of prompts means your password is already known to an attacker and needs to change.
Instead of stealing your password, this attack asks you to sign in with Microsoft or Google and then grant a third-party app permission to read your mail and files. The sign-in screen is genuine. Your password is never captured. But the app keeps standing access to your mailbox — and because no password was stolen, changing your password does not revoke it. Be deliberate about granting permissions to any app you do not recognize, and have your IT provider restrict which apps users can authorize.
An attacker inside a compromised mailbox replies within a real, ongoing email thread — correct history, correct participants, correct subject line, appropriate tone — and attaches the malicious file or changed invoice there. Everything about the context is authentic, which is why this pattern succeeds so often. The only reliable check is the request itself: does this payment, this file, this change actually make sense?
The same tactics arrive by text message (smishing) and phone call (vishing), and increasingly in combination: an email that prompts you to call a number, or a text that follows up on a fake invoice. AI voice cloning now makes a short call from a familiar-sounding executive plausible. Treat urgent voice and text requests with the same skepticism, and verify through a channel you initiated.
This one deserves its own section, because it is currently among the most successful attacks in circulation and because it defeats almost everything traditional phishing training teaches. There is no suspicious link to hover over. There is no attachment. Frequently there is no email at all. It arrives as a Microsoft Teams message or call from someone presenting themselves as your IT help desk — and they are not threatening you. They are offering to help.
Nearly all phishing awareness training is built around one emotion: fear. Watch for threats. Watch for deadlines. Watch for pressure. This attack inverts that entirely. Nobody is threatening you, nothing is being suspended, and the person on the other end is solving a problem you genuinely have. Relief is a far more disarming emotion than panic, and no amount of link-hovering practice prepares someone for it.
It also borrows credibility from the platform. Teams is an internal tool, so a message inside it feels internal by default — most people have no mental model for the fact that an outside organization can message them there at all. And because everything the attacker uses is legitimate software operated by a consenting user, endpoint protection sees an employee installing a support tool and getting help. Which is precisely what it looks like.
Close the chat, hang up the call, and reach IT yourself using the contact method you already have. Not a number or link they gave you, not a reply in the same conversation, and not a callback you agreed to. Your own path, initiated by you.
That rule only works if the path is obvious and everyone knows it, which is why we establish it with clients up front: how North Star will contact you, how you reach us, and the standing commitment that we will never object to being verified. Any real support technician will wait while you check. Anyone who pushes back on verification has told you what they are.
Training is the last line here, not the first. Most of this attack can be removed as an option through configuration your users never see:
The Teams settings and application control described here are configured and maintained as part of our managed Microsoft 365 services and managed security services. If you are not certain whether outside organizations can currently message your staff in Teams, that is a five-minute check and worth making today.
Speed matters far more than embarrassment. Almost every serious incident we respond to was made worse by a delay caused by someone hoping it was nothing.
One more thing that catches Colorado businesses off guard: if personal information was exposed, Colorado law (C.R.S. § 6-1-716) requires notifying affected residents within 30 days of determining a breach occurred, with notice to the Attorney General when 500 or more residents are involved. That is half the time HIPAA allows, and it is nearly impossible to meet without logging already in place — you cannot notify accurately if you cannot determine whose data was reached. This is one reason a single clicked link becomes a legal timeline, not just an IT ticket.
Everything above makes your team meaningfully harder to fool. None of it makes them perfect, and it is not reasonable to expect it to. A well-trained employee reading a hijacked thread from a real vendor account, at 4:45 on a Friday, on a phone, is going to be wrong sometimes. The purpose of email security is to make being wrong survivable.
North Star deploys and manages advanced email security for businesses across the Denver metro area, Colorado Springs and Fort Collins. We describe it here by capability rather than by product name, because what protects your business is what the controls actually do — not whose logo is on them.
Traditional email filtering inspects mail at the perimeter, before delivery, and stops there. We add inspection that operates inside your mail platform, after native filtering has had its turn. That matters for three reasons: it catches what the built-in filters passed, it can inspect internal messages sent from one compromised colleague to another, and it can act on mail that has already landed in an inbox.
The attacks that cost the most contain no malicious payload to scan for. Detection instead models normal communication — who emails whom, in what tone, about what, with what banking details — and flags the message that breaks the pattern: a first-time sender requesting a payment, a vendor whose account details changed, an executive’s display name paired with an unfamiliar address, a reply routed somewhere new. This is the layer that stops wire fraud, and it is precisely the layer standard filtering does not have.
A common evasion is to send a link that is harmless on arrival and weaponized hours later, after scanning has passed. We rewrite and re-evaluate URLs at the moment someone clicks, so the destination is checked against its current state rather than its state at delivery — and blocked with a warning page if it has turned.
Unknown attachments are opened in an isolated environment and observed for malicious behavior instead of being matched against a list of known-bad signatures. Where speed matters, a sanitized copy — active content stripped out — can be delivered immediately while the original completes analysis, so nobody waits on a legitimate contract.
Because a QR code is an image rather than a link, most filtering cannot see where it points. We extract the encoded destination from images and PDF attachments and evaluate it the same way a link is evaluated, closing the quishing gap that has grown quickly for exactly that reason.
When a campaign is identified after delivery, matching messages are removed from every affected inbox automatically — including the ones already read. This single capability changes an incident’s shape: instead of an urgent all-staff warning and a race against whoever clicks first, the mail is simply gone.
Compromised accounts announce themselves if anyone is watching: a sign-in from an impossible location, a newly created rule that forwards or hides mail, an unusual sending burst, a mailbox suddenly searching for the word invoice. We monitor for those behaviors and can disable an account and revoke its sessions before it is used to attack your clients and vendors — which is how reputational damage usually happens.
SPF, DKIM and DMARC records, correctly configured and then actually monitored, prevent outsiders from sending email that appears to come from your domain. Most organizations we assess have these partially implemented, in permissive mode, or quietly broken by a marketing platform added years ago. Fixing it protects your clients from being phished in your name, and it improves the deliverability of your legitimate mail as a side effect.
Attackers follow the conversation, so protection extends to chat, file sharing and cloud storage rather than stopping at the inbox. Outbound data loss prevention watches the other direction, catching sensitive information leaving by mistake — the wrong recipient, an unencrypted attachment of client records, a spreadsheet that should never have left the building.
We run realistic phishing simulations, deliver short targeted training to the people who need it, and track whether risk is actually falling over time — useful for insurers and auditors as well as for you. A report button in your mail client sends suspicious messages straight to our analysts for review, so employees get a clear answer instead of a guess, and we get early warning of a campaign in progress.
Email security is one layer of several. It works alongside phishing-resistant multi-factor authentication and conditional access through our managed Microsoft 365 services, continuous monitoring through managed threat protection and MDR, identity-based access control through our SASE and Zero Trust solutions, and tested, immutable cloud backup so a bad outcome is a restore rather than a negotiation. The whole program is described on our managed security services and cyber security pages, and delivered as part of managed IT services. For organizations that need documented policy and an audit trail behind all of it, our vCISO and compliance-as-a-service program supplies the governance. For organizations that need to close the adversary-in-the-middle gap specifically, we also offer an optional phishing-resistant browser layer, described in the next section.

Everything described so far happens before a page loads. This layer covers what happens after — and it exists because of one specific attack that has become the endgame for serious credential theft: the adversary-in-the-middle attack, sometimes called man-in-the-middle or AiTM phishing. It is the technique that defeats multi-factor authentication, and it is the reason “we have MFA” is no longer a complete answer to “are we protected against phishing.”
You click a link and a Microsoft sign-in page appears. It is not a counterfeit. It is the real page, being relayed to you through a server the attacker controls, sitting invisibly between you and the genuine service. Here is what happens next:
Two things make this worse than it first sounds. Changing your password does not evict them — a stolen session stays valid until it is explicitly revoked, which someone has to know to do. And the toolkits that run this attack are packaged and resold, so it requires no real skill to operate. It is no longer an advanced technique.
Email security is very good at the mail it inspects. The problem is that the link to an adversary-in-the-middle page frequently never travels through email at all. It arrives in a Microsoft Teams chat, a text message, a scanned QR code, a search advertisement, a social media message, or from a legitimate website that has been compromised. None of those pass through your mail platform, so none of them are inspected.
And even when the link does come by email, the decisive moment has moved. The browser is where the page renders, where the password is typed and where the session token is issued. That is the point of loss — and on most networks it is the one place nothing is watching. It is also the layer that still applies when someone is working from a personal laptop or phone that your company does not manage, which is exactly where a lot of quiet compromises begin.
North Star can add a browser security layer that moves the decision point to where the risk actually lives — a managed add-on inside the browser itself, which spots a counterfeit Microsoft sign-in page and stops the user from entering credentials on it.
This is the capability worth understanding before any of the others, because it addresses the exact moment everything is lost. The protection is a managed add-on that runs inside the browser your staff already use — any browser, on any device — and it inspects the sign-in page itself rather than trusting the address bar. When it determines that a page impersonating a Microsoft sign-in is not genuinely Microsoft, it blocks credential entry outright. The password cannot be typed or submitted, and the user gets a clear warning instead of a silent mistake.
Think about what that removes. Every other control on this page asks a person to make a correct judgment call — read the domain backwards, notice the lookalike character, question the urgency. This one does not. An employee can be fully convinced, at the end of a long day, looking at a pixel-perfect copy of the Microsoft sign-in page or a live relay of the real one, and the browser simply refuses to hand over the credential. The judgment call is taken off the employee’s plate and handled at the point of loss.
It matters that this happens in the browser rather than in the mail platform, for two reasons. First, it works no matter how the link arrived — email, Teams, text message, scanned QR code, search advertisement, or a colleague pasting it into a chat. Second, because it is a managed browser add-on rather than a full system agent, it can be deployed and policy-controlled centrally across managed workstations, personal laptops, contractor machines and BYOD alike. That last group is normally invisible to security tooling, and it is where a great many quiet compromises begin.
Around that core function sit several supporting capabilities. Described by capability, as always:
Because it genuinely is. This is an additional layer at additional cost, and plenty of organizations are adequately covered by hardened identity, managed email security and monitoring. We would rather tell you that than sell you everything. It becomes clearly worth the money when one or more of the following is true:
One honest qualification. The strongest single defense against adversary-in-the-middle attacks is phishing-resistant multi-factor authentication — hardware security keys and passkeys, which are cryptographically bound to the real site and cannot be relayed — paired with conditional access policies that reject unfamiliar devices and locations. We deploy that through our managed Microsoft 365 services, and it should be in place first. Browser protection complements it and covers the accounts, applications and unmanaged devices that phishing-resistant MFA cannot always reach. Anyone selling you the browser layer as a substitute for fixing identity has the order backwards.
A quick reference for the vocabulary you will encounter in security training, insurance questionnaires and incident reports.
| Term | What it means |
|---|---|
| Phishing | A message impersonating a trusted source to obtain credentials, money or system access. |
| Spear phishing | Phishing tailored to a specific person using researched details about their role, employer and relationships. |
| Whaling | Spear phishing aimed at executives and other high-authority targets. |
| Business email compromise (BEC) | Fraud using a spoofed or compromised business account to redirect payments or data, usually with no link or attachment involved. |
| Quishing | Phishing delivered through a QR code, which most filters cannot read because it is an image. |
| Smishing | Phishing delivered by SMS or text message. |
| Help desk / IT support impersonation | An attacker posing as internal or outsourced IT support, usually by chat or phone, to talk a user into granting remote access or approving a login. |
| Teams phishing | Phishing delivered through Microsoft Teams chat or calls, typically from an external tenant using a role-based display name such as Help Desk. |
| Email bombing | Deliberately flooding a mailbox with thousands of harmless signup confirmations to create a pretext for a fake IT support call. |
| Remote access tool abuse | Using legitimate remote support or screen-sharing software, installed by a deceived user, to gain hands-on control of a machine without triggering antivirus. |
| Vishing | Phishing conducted by phone call, increasingly assisted by AI voice cloning. |
| Thread hijacking | Replying inside a genuine, ongoing email conversation from a compromised mailbox so the attack inherits real context. |
| MFA fatigue / push bombing | Flooding a user with repeated multi-factor approval prompts until one is accepted out of annoyance or habit. |
| OAuth consent phishing | Tricking a user into granting a malicious app standing permission to their mailbox and files, without ever stealing a password. |
| Adversary-in-the-middle (AiTM) | Also called man-in-the-middle phishing. A relay server sits between the victim and the real sign-in page, capturing the password, passing the multi-factor challenge through, and stealing the resulting session token — bypassing MFA entirely. |
| Session hijacking / token theft | Using a stolen session token to act as an already-signed-in user. A password change does not revoke it; the session must be explicitly terminated. |
| Phishing-resistant MFA | Authentication using hardware security keys or passkeys, cryptographically bound to the genuine site so it cannot be relayed through an attacker. |
| Browser isolation | Opening an untrusted page in a restricted or read-only session so scripts cannot reach the device and credentials cannot be submitted. |
| Credential harvesting | Capturing usernames and passwords through a counterfeit sign-in page. |
| Account takeover (ATO) | An attacker operating a legitimate user account as if it were their own. |
| Lookalike / typosquatted domain | A registered domain designed to resemble a real one closely enough to pass a glance. |
| Display name spoofing | Putting a trusted person’s name on an account whose actual address is unrelated. |
| Payload-less attack | An attack carried entirely by text, with nothing to scan — the reason content and context analysis is necessary. |
| Post-delivery remediation | Automatically removing a malicious message from inboxes after it has already been delivered. |
| SPF, DKIM, DMARC | Email authentication records that let receiving systems verify mail genuinely came from your domain. |
North Star provides email security, phishing defense, security awareness training and complete managed IT for organizations of 5 to 300 endpoints across Colorado’s Front Range — Denver, Aurora, Lakewood, Arvada, Westminster, Thornton, Northglenn, Broomfield, Commerce City, Brighton, Centennial, Greenwood Village, Englewood, Littleton, Highlands Ranch, Parker, Castle Rock, Golden, Wheat Ridge, Colorado Springs, Monument, Fort Collins, Loveland, Windsor, Greeley and Longmont, along with the surrounding communities.
Phishing risk looks different by industry, and the money moves through different doors. We tailor email security for the sectors where a single redirected payment or exposed record does the most damage — including law firms, financial services firms such as accounting and tax practices and investment advisors, healthcare and medical practices, real estate, property management and HOA firms facing closing wire fraud, construction firms and contractors, manufacturers, nonprofits, special districts and local government, dealerships and automotive businesses, and defense contractors pursuing CMMC compliance. Every program we run is listed on our industries page.
Check the domain after the @ symbol rather than the display name, ask whether you were expecting the message, look for urgency or secrecy in the request, preview any link before clicking it, and never approve a multi-factor prompt or app permission you did not personally start. If a request involves money, credentials or a banking change, verify it by phone on a number you already have. You do not have to be certain an email is malicious to report it — being unsure is reason enough.
Simply opening and reading an email is very rarely harmful on its own with a modern, updated mail client. Risk begins when you click a link, open an attachment, enter credentials, approve a prompt or reply. Remote images in an email can confirm to the sender that your address is live and being read, which typically means more targeted attempts. Opening one is not a crisis, but it is worth reporting.
Built-in filtering catches high-volume spam and known-bad senders, and it is a genuine baseline. It is weakest against exactly the attacks that cost the most: a payload-less request from a real, compromised account; a link weaponized after delivery; a QR code it cannot read; internal mail from one compromised colleague to another. Dedicated email security adds inspection inside the mailbox, impersonation and BEC detection, click-time link evaluation, attachment sandboxing and the ability to pull malicious mail back out of inboxes after delivery.
No, and this is one of the most important updates to make to older training. AI writing tools let attackers produce flawless, professional, correctly localized email at scale. Grammar mistakes are still worth noticing when they appear, but their absence tells you nothing. Judge the request and the sender domain instead of the prose.
Report it to your IT team or provider immediately — speed matters more than embarrassment. Change the password from a different device and change it anywhere you reused it, and have active sessions revoked, because an attacker holding a valid session may not need the password again. Deny any multi-factor prompts that follow. If you opened an attachment, disconnect the device from the network but leave it powered on. If money moved, call your bank about a wire recall and file a report at ic3.gov, because recovery odds drop sharply after the first 24 to 72 hours. Don’t delete the email; it is evidence.
Business email compromise is a targeted fraud that uses a spoofed or genuinely compromised business account to redirect money or data, and it usually contains no link and no attachment at all — just a plausible request to wire funds, change banking details or buy gift cards. That absence of a payload is what makes it so hard for conventional filtering to catch, and why it consistently ranks among the costliest categories of cybercrime. The most effective control is a firm rule that unusual or changed payment instructions are verified by phone, on a known number, before anything is sent.
Treat an unexpected QR code exactly like an unverified link. Because a QR code is an image rather than clickable text, many email security tools cannot read or evaluate where it leads, and scanning it moves you onto a personal phone that your company may not protect. Attackers have adopted them heavily for that reason. If you did not expect it, don’t scan it — navigate to the site yourself instead.
Because someone already has your password and is trying to log in, hoping you will eventually tap Approve out of annoyance or habit. This is called MFA fatigue or push bombing. Never approve a prompt you did not start, and report it right away — the password needs to be changed and the account reviewed, and stronger, phishing-resistant authentication methods should replace simple approval prompts on accounts that matter.
Yes, meaningfully — particularly training paired with realistic simulations and a frictionless way to report suspicious mail. It does not get you to zero, and no honest provider will claim otherwise. The point of training is to reduce how often people are fooled; the point of technical email security is to make it survivable when they are. Programs that rely on only one of the two are the ones that produce expensive surprises.
Be very skeptical, particularly if they contacted you first about a problem you never reported. A widespread attack uses Microsoft Teams messages and calls from external organizations, with display names like Help Desk or IT Support, to talk employees into granting remote access to their computer. Check whether Teams has labeled the sender as external and expand it to see the actual organization — an unfamiliar tenant name or an address ending in .onmicrosoft.com is not your IT department. Then close the chat and reach your IT provider through the contact method you already have. A real technician will always wait while you verify.
Treat it as a security incident and report it right away, before anyone contacts you. Attackers deliberately flood a mailbox with harmless newsletter and subscription confirmations to manufacture a problem, then follow up by phone or Microsoft Teams posing as IT support offering to fix it. The flood is the setup; the call is the attack. If someone reaches out about it and asks to remote into your machine, install software, read a code aloud or approve a login prompt, end the conversation and contact IT yourself.
By default, in many tenants, yes — external chat and calling is often left open to any other organization, and most businesses have no idea it is enabled. That setting is what makes help desk impersonation in Teams possible in the first place. It can be disabled outright, or restricted to an allow-list of the partner domains you genuinely collaborate with, which removes the attack path without affecting legitimate work. We check and configure this as part of managing Microsoft 365, and it is worth verifying today if nobody has looked.
It stops a lot of it, and it remains one of the highest-value controls you can have — but no, not entirely. Adversary-in-the-middle attacks, also called man-in-the-middle phishing, defeat most forms of MFA. The attacker relays the real sign-in page through a server they control, so your password is captured, your multi-factor challenge is passed through and completed legitimately, and the session token issued at the end is stolen in transit. The attacker then holds an authenticated session and needs neither your password nor your second factor again. Changing your password does not evict them; the session has to be explicitly revoked. The defenses that do work are phishing-resistant MFA using hardware keys or passkeys, conditional access, and browser-level protection that blocks credential entry on a relayed page.
It is a phishing page that acts as a live relay in front of the genuine login page rather than a static counterfeit. Because you are looking at the real page, nothing appears wrong: the branding is correct, the URL may be close enough to pass, and your multi-factor prompt works normally. Behind it, the attacker records your password and copies the session token the service issues once you authenticate. Ready-made toolkits have made this commodity rather than advanced, and it is now the standard endgame for credential theft against organizations that have MFA enabled.
Because it evaluates the destination at the moment the browser navigates there, regardless of how the link arrived. Email security only inspects email — it cannot see a link sent in a Microsoft Teams chat, a text message, a scanned QR code, a search advertisement or a compromised legitimate website. Browser-level protection also sits at the point where the loss actually occurs: the page render, the password entry and the session token. It can refuse to let work credentials be typed into any site that is not a sanctioned sign-in destination, isolate pages on newly registered domains, and detect a relayed login page. It also covers personal and unmanaged devices, where no corporate mail client is involved at all.
Often, yes. Colorado breach-notification law (C.R.S. § 6-1-716) requires notifying affected Colorado residents within 30 days of determining a breach occurred, with notice to the Attorney General when 500 or more residents are affected — half the time HIPAA allows. Industry rules may add obligations on top, including HIPAA for healthcare, GLBA and the FTC Safeguards Rule for financial services, and DFARS reporting for defense contractors. This is general information rather than legal advice; confirm your specific obligations with counsel. North Star handles the technical and documentation side, including the logging that makes accurate notification possible in the first place.
Send this page to your team — it is written to be shared, and it is a reasonable part of onboarding. Then let’s talk about the layer underneath it. North Star will review how mail actually reaches your organization, test whether your domain can be spoofed, show you what your current filtering is and is not catching, and put managed email security in place alongside the rest of a layered managed security program.
Bottom line: trust no email until you have verified it. Contact North Star to make sure the ones that get through can’t cost you.