Email security issues, catalogued honestly for a small organisation, are not the exotic attacks on conference slides; they are five mundane failures that recur because email was never designed to prove who is speaking. Account takeover: someone else logs into a mailbox that is yours. Payment redirection: an instruction that moves money arrives looking legitimate and is obeyed. Phishing and its variants: messages that harvest credentials or deliver malware. Sender forgery: mail sent in your name to your customers and suppliers. And misdirection: your own people mailing the wrong data to the wrong place. Each failure has a known shape, a known closing move, and a tendency to be discovered late. This page describes the five as they actually happen, in rough order of damage done, and names the control and the policy line that closes each; the sheet this page hands off to counts those lines into a written set your organisation can actually keep.
Account takeover, the quiet one
The attacker logs in with a real password, usually harvested from an unrelated breach and reused, then reads silently. The damage is patience: they learn the invoice rhythms, then insert a payment redirection at the believable moment, often setting a mailbox rule that hides the replies. It is the issue with the cleanest fix, multi-factor authentication on every mailbox, and the most telling symptom, rules nobody remembers creating. The access policy line, second factor required, no shared mailboxes with shared passwords, is counted into your set by the free sheet on this site.
Payment redirection and phishing, the paired doors
Payment redirection is the fraud that empties accounts: a supplier's new bank details, a boss's urgent transfer, arriving either from a compromised real mailbox or a lookalike domain. Its closing move is procedural, confirmation by voice on a known number before any payment change, because no filter reads intent. Phishing at large is the delivery mechanism for most of the rest: credential pages behind shortened links, attachments carrying loaders. Filtering removes volume; the credential procedure, passwords typed, never clicked, removes the remainder's payoff. Both procedures are sentences in the policy set, not products.
Forgery and misdirection, the reputation pair
Sender forgery turns your name into the weapon: customers receive invoices from you that you never sent, and the cleanup lands on your relationships. The fix is published sender authentication, SPF and DKIM records with DMARC at enforcement, so receiving systems reject the forgeries; the DMARC standard's own documentation walks the rollout. Misdirection is self-inflicted: the spreadsheet of everyone's details autocompletes to the wrong recipient. Data handling rules, restricted files travel by link with access control rather than attachment, blunt it, and the incident procedure says what happens when it occurs anyway. All five issues end as lines in the same short set of documents, which is exactly what the free policy sheet sizes and Hardenvo Pro generates and keeps current.
Questions people ask about email security issues
What are the most common email security issues?
For small organisations: account takeover via reused passwords, payment redirection fraud, phishing for credentials or malware delivery, sender forgery in your domain's name, and misdirected mail carrying sensitive data. Almost every real loss runs through one of the five.
Which email security issue causes the biggest losses?
Payment redirection: a believable instruction to change bank details or transfer urgently, often staged from a quietly compromised mailbox. Its control is procedural, voice confirmation on a known number for any payment change, written into the finance procedure.
How do I know if a mailbox has been taken over?
The signature is mailbox rules nobody created, forwarding, auto-delete of replies, plus sign-ins from unfamiliar places and messages in sent items nobody sent. Reset, revoke sessions, remove rules, and follow your incident procedure; the free sheet counts that procedure into your set.