What You Actually Get: The Free Email Security Assessment and Your First 90 Days


The question that comes up when we describe the year-end offer is not about price. It is "what are you actually going to do inside my Microsoft 365 or Google Workspace?" Handing an outside company admin approval is a real decision, so this post walks through it in order: what the free two-week email security assessment includes and what it does not, and then what a new customer gets from us in the first 90 days, including a tenant posture report that we have now defined and put a date on. The posture report is for customers; the free assessment is email only.
The free two-week assessment: email only, no obligation
It starts with a 15-minute call and one working session with whoever holds admin rights. For Microsoft 365, that person clicks Accept on a consent screen; per Check Point's admin guide the account needs the Privileged Role Administrator role or higher, which for most small organizations means the Global Administrator account. That consent connects Check Point Email Security, the platform we run, to your tenant through Microsoft's own API. There is no appliance, nothing installed on computers, and your MX records do not change, during the assessment or after you sign. Google Workspace onboarding has more steps, and we say so up front: per Check Point's guide, the automatic setup creates a super admin account, mail routing and relay settings, two user groups, and five content compliance rules in your Workspace, and we walk the admin through each one before the setup runs.
For the two weeks, the platform runs in what Check Point calls Monitor only mode, its default for a newly connected tenant. It reads mail through the API and journaling and reports what it sees. In this mode the platform reports what it finds and quarantines nothing unless an administrator sets up a quarantine rule, and during the assessment we do not quarantine, move, or delete messages; your current filter keeps doing whatever it does today. Per Check Point, the platform first spends anywhere from a few minutes to 72 hours in a learning period, mapping communication patterns before it flags phishing or spam, while the malware and other engines run from the start. Plan on at least eleven clean days of data.
Here is our part, because a platform produces alerts, and someone has to work them. Each business day, we go through what it flagged and compare it with what your current filter let through: phishing that reached inboxes, impersonation attempts aimed at specific people, malicious attachments and links, and the noise. We separate real threats from false positives and write both down, because the false positives tell us how the policy would need to be tuned for your organization. We note the patterns: which senders, which departments, which lures. The platform runs what Check Point calls unauthorized applications detection, or Shadow IT, from the first day: it spots the sign-up and notification emails that cloud apps send to your company addresses, so the report also lists which services are in use. That list is yours; during the assessment we do not approve or dismiss anything, we report it. At the end of the two weeks you get a written report and a walkthrough session where we show you the examples, what your current setup caught, what it let through, and what we would change.
What the assessment does not include: beyond the connection itself, and on Google Workspace the routing objects described above, we do not change your tenant settings; we do not install anything; we do not read mail beyond what the review requires; and if you decide not to proceed we disconnect the platform and walk your admin through removing its application from your tenant. You keep the report either way. It is email only, phishing and Shadow IT included; the tenant posture work described below is for customers who sign, delivered within the first 90 days.
If you sign: your first 90 days
If you came through the assessment, day one is the switch from monitoring to protection; if not, day one is the connection and the switch together. We move the policy to Prevent (Inline), which per Check Point scans email before delivery. Where a specific mail flow requires it, we use Detect and Remediate instead, which scans after delivery and pulls threats out of the inbox. We set up the quarantine, route spam and bulk mail to Junk, and bring in your existing block and allow lists so senders you rely on are not caught.
From then on, the daily work is ours. We run the quarantine, handle email restore requests, investigate anything a staff member reports, and adjust the block and allow lists as your vendors and contacts change. When Check Point ships a new protection, we read it, test it, enable it, and ask your admin to approve any new permissions it needs. When a new phishing pattern shows up in one inbox, we tune the policy so the rest of your organization is covered, not just the person who reported it. About two weeks in, we hold the second session and walk you through what got flagged since day one, so you see the service working rather than take our word for it.
Within the first 90 days, you also get a written SaaS security posture report on the tenant itself, at no charge. This is the complimentary tenant review we have mentioned in earlier posts, now defined. Similar reviews are sold on their own elsewhere: publicly listed prices for a one-time Microsoft 365 or Google Workspace security assessment for a small business run from about $1,000 to $3,500 or more depending on user count and scope, per providers' own pricing pages as of September 2026. For our customers it is included. It covers multi-factor authentication coverage and conditional access or context-aware access rules; the number of admin accounts and whether emergency access accounts exist, since Microsoft's own guidance is to limit admin accounts because "too many admin accounts provide attackers with more opportunities to compromise your organization"; automatic external forwarding rules, which Microsoft notes users can create "deliberately or as a result of a compromised account"; external sharing and link settings; the allow lists in your mail platform, looking for broad entries such as whole domains; third-party app permissions granted to your tenant; and email authentication (SPF, DKIM, DMARC), which we check and give you the exact records to publish. Where the tenant's own tooling exists, such as Microsoft Secure Score in the Defender portal, we use it; where it does not, as on Google Workspace Business Starter, Standard, and Plus, we work from Google's own security checklist by hand. The report says what we found, what we changed with your approval, and what we recommend you leave alone. We change settings where the organization needs it, with your approval, rather than turning on everything we could.
And each month you get a summary of what was blocked and what we changed. No console to babysit.
What this is not
It is not a penetration test or a vulnerability scan, and it is not a compliance certification. We do not offer those. The controls we put in place support frameworks like HIPAA, the FTC Safeguards Rule, and NIST 800-171 and CMMC, and the posture report is a record of what is configured on the tenant, but a framework assessment is a different engagement with a different firm.
Why the two weeks are worth it
Microsoft's 2025 Digital Defense Report says more than 97% of identity attacks are password attacks, and that identity-based attacks rose 32% in the first half of 2025; a mailbox with a weak sign-in setup is the front door. Check Point's Q2 2026 brand phishing report found Microsoft was the single most impersonated brand, at 23% of brand phishing attempts, which is a vendor figure, but it matches what we see. And the FBI's IC3 counted 24,768 business email compromise complaints in 2025 with $3.05 billion in reported losses. The assessment shows you, with your own mail, how much of that kind of message is reaching your people today.
The offer, in full
Managed Email Security is $8 per user per month, license plus fully managed service. Through December 31, 2026, new customers who sign a 12-month agreement get 20% off, which is $6.40 per user per month; registered 501(c)(3) nonprofits get 30% instead, $5.60, as described in our nonprofit post. New customers only, no onboarding fee, and the posture report and monthly summary are included. The full terms are in the year-end offer post, and the service itself is described on our services page.
We work with small and medium businesses and nonprofits nationwide, including Washington DC, Northern Virginia, and Maryland. To start the free two-week assessment, book a free 15-minute call and we will schedule the admin session from there.
Sources: Check Point Email Security administration guide (Office 365 activation and prerequisites, Google Workspace activation and footprint, Email Protection modes, Learning Mode, Shadow IT Analytics); Microsoft Learn, Microsoft Secure Score, Microsoft 365 for business admin account security, and outbound spam and external email forwarding; Google Workspace Admin Help, security checklist for small businesses; Microsoft Digital Defense Report 2025 (Oct 2025); Check Point Q2 2026 Brand Phishing Report (Jul 2026); FBI IC3 2025 Internet Crime Report (2026); provider pricing pages for standalone Microsoft 365 and Google Workspace security assessments (Adelia Risk, Bond Consulting Services, TenantShield, Steegle) and Brocent's 2026 audit pricing guide, checked September 2026.
Comments