Email Security deep dive
Email is still the #1 way attackers get in. Here's how AMTech closes it.
Roughly nine out of ten cyberattacks start with an email. Phishing, business-email-compromise, malware-laden attachments, ransomware payloads — every category begins with someone clicking a link or opening a file in their inbox. Microsoft 365 and Google Workspace ship native email security that catches the bulk-mail attacks, but the sophisticated, targeted, and compliance-failure-grade incidents slip through default filters. AMTech layers OpenText Email Security Suite on top of native protection — two tiers that map cleanly to AMTech Shield and Total AMTech Shield, so the security baseline you pay for matches the risk profile of your business.
Tier 1 — Baseline
Email Security Suite
OpenText Email Security SuiteIncluded with AMTech Shield.
Safe Links
Every URL in every inbound email is rewritten through OpenText’s URL-protection service. When the recipient clicks, OpenText scans the destination in real time against current threat intelligence — and blocks it if the page has been weaponized since delivery. This catches the most common modern phishing technique: the URL is benign when it lands in the inbox at 9 AM, then turned malicious at 2 PM after the email-filter scan ran. Real-time click-time scanning is the difference between catching a phishing campaign and explaining a breach.
Malware prevention
Every attachment is sandbox-detonated in a controlled environment before delivery. Known-bad signatures are blocked instantly. Unknown files run through behavioral analysis — does the file try to escalate privileges, write to startup, encrypt directories? Suspicious attachments are held and surfaced to AMTech for analysis instead of delivered to the user.
Junk and spam filtering
Multi-layer Bayesian and heuristic filtering reduces inbox noise. Reputation scoring on every sender domain and sending IP. First-time senders are greylisted for verification. Net result: cleaner inbox, less time wasted on bulk-mail, and fewer training-set examples for users to mistakenly mark as legitimate.
Impersonation protection
OpenText watches for two impersonation patterns: domain spoofing (an email "from your CEO" sent from a lookalike domain like am-technology.com instead of amtechserv.com) and display-name impersonation (the From-name reads "John Smith" but the actual sender is attacker@gmail.com). Detected impersonations get a banner warning and a quarantine path before they reach the user.
Tier 2 — Plus
Email Security Suite Plus
OpenText Email Security Suite PlusIncluded with Total AMTech Shield.
Email encryption
Policy-based outbound encryption triggers automatically on sensitive content. Patient health information in the message body, social-security numbers, account numbers, the word "confidential" in the subject line — any match invokes OpenText’s secure-message flow. The recipient gets a portal link to retrieve the encrypted message; nothing sensitive sits in plaintext in transit. HIPAA-compliant encryption at rest and in transit, with auditable proof-of-encryption per message.
Cybersecurity policies inside your email
Data Loss Prevention rules block outbound messages containing patterns that should not leave the company without encryption (PHI, PII, credit-card numbers, financial routing information). Retention policies hold mail for the period your industry requires — seven years for healthcare records, five years for financial communications, sliding for legal — and apply legal-hold preservation when needed. External-forwarding controls block executive accounts from auto-forwarding mail outside the company, a common business-email-compromise attack vector.
Cybersecurity awareness training
Every user completes annual training modules covering phishing recognition, password hygiene, social engineering, business-email-compromise scenarios, and ransomware prevention. Completion is tracked per user and produces audit evidence on demand. Onboarding training fires automatically when a new account is provisioned, so a user is never on the network for a week before they have been trained.
Simulated phishing campaigns
Quarterly simulated phishing emails go out to staff, designed to mimic the techniques actually being used against your industry. Users who click are redirected to a short coaching page — not a "gotcha" — that explains what they missed and reinforces what to look for next time. Aggregate company click-rate is trended over time and reported in your quarterly business review. Most clients see the company-wide click-rate drop 60 to 80 percent over the first year.
The compounding effect
Technical controls catch the easy attacks. Trained users catch the sophisticated ones. Without both, you have a gap.
The Verizon Data Breach Investigations Report has consistently shown that the human element factors into roughly three quarters of breaches. The most damaging email attacks — business-email compromise, vendor-impersonation wire fraud, executive-impersonation from a domain spoof — are specifically engineered to defeat technical filters and exploit human pattern-recognition. Quarterly simulated phishing builds the muscle memory that turns "looks fine to me" into "wait, this domain is wrong." Combined with the automatic audit evidence Total AMTech Shield generates on every encrypted message, training completion, phishing simulation, and DLP block, email security stops being the thing you scramble to document at audit time and starts being the thing where you walk in with the receipts already filed.
60–80%
Click-rate drop year 1
~90%
Of attacks start in email
74%
Of breaches have a human factor
On demand
Audit evidence
- Real-time click-time URL scanning
- Sandbox attachment detonation
- Domain + display-name impersonation
- HIPAA-compliant encryption
- DLP for PHI / PII / financial data
- Annual security training
- Quarterly phishing simulations
- Audit evidence on demand