An email security lunch for IT and security leaders in supply-chain-heavy industries. We look at the attacks that arrive through suppliers and contractors you already trust, and whether your stack can tell them apart from the real thing.
The attack increasingly comes from a legitimate, trusted source: a hijacked vendor thread, a compromised contractor mailbox, an AI-written invoice inside a real conversation with a supplier you’ve worked with for years. The sender is real, the account is real, and the request looks normal. Most of your suppliers are nowhere near your security level.
The old “we’d spot a dodgy supplier email” no longer holds, because AI-written lures and deepfaked voice notes make a compromised partner completely convincing. If you run plants, sites or physical operations, the knock-on isn’t only data. It’s a route toward the floor and the lines you can’t afford to stop. This is a small, invitation-only lunch to work through whether your email security can contain what your partners can’t prevent.
Hijacked reply chains, account takeover on a supplier’s tenant, and invoice fraud from a real, authenticated sender. No malware, no bad link, nothing for a filter to flag.
SPF, DKIM and DMARC can all pass, because the mail genuinely is from the domain. AI-written lures and voice deepfakes remove the tells your users were trained to spot.
Where Exchange Online Protection and Defender for Office 365 hold, where they don’t on post-delivery and social-engineering attacks, and what API-based controls and DMARC enforcement add.
The specifics we’ll work through:
Not a webinar and not a pitch. A small table, a good lunch, and a working conversation you can take straight back to your environment. You’ll leave with a clear read on where your current email security stops, and what closes the gap.
IT and security leaders in businesses where a supplier or contractor compromise would actually hurt.
We run networking and security together for multi-site and industrial businesses across Ireland and the UK. That means we see the traffic, the topology and the mailboxes as one picture, which is exactly where supplier-borne attacks hide, and exactly where a security-only provider is blind.
Whether or not 24 September works for you, here is where we’ve written and talked about the exact problem this lunch is built around.
How layered email security sits on top of Microsoft 365 to catch phishing and business email compromise.
Read the overview →The 2025 threat landscape: business email compromise, AI-generated phishing and supplier impersonation.
Read the article →An episode of Cyber Insights, our podcast, on how AI is reshaping both sides of the email security battle.
Listen on Spotify →The room is kept deliberately small, so the discussion stays useful. Tell us where to send the details and we’ll hold you a seat.
Thanks, your request is in. We’ll reply personally with the details and hold you a seat. The room is kept small, so we’ll be in touch shortly.