SECURE COLLABORATION

Email & Teamwork Tools

Your work email, shared files and office apps — set up properly and looked after. Microsoft 365, Google Workspace, or private alternatives you control.

Safe access

Only the right people can reach your data. Two-step login on every account, and when someone leaves the company, one switch turns off all their access.

One account per person

Where it helps, we connect your tools so staff sign in once with one company account instead of juggling separate passwords — one account to create when someone joins, one to disable when they leave.

Email security

Spam, phishing and fake-invoice emails filtered out. We also set up the technical records that stop criminals from sending email pretending to be your company.

IN DETAIL

Email is where businesses actually get attacked

Most Mauritian businesses that lose money to an attack do not lose it to a dramatic breach. They lose it to an invoice. Someone receives what appears to be a payment request from a supplier they genuinely use, with the account details changed, and pays it. By the time the real supplier chases the invoice, the money is gone.

This works because email was designed to be trusting. Nothing in the original protocol prevents a stranger putting your supplier's name — or your managing director's — in the From field. The defence is not vigilance, because a convincing fake is convincing. The defence is technical.

We filter spam, phishing and fake-invoice email before it reaches an inbox, and we configure the records that stop criminals sending mail that appears to come from your domain in the first place.

SPF, DKIM and DMARC, in plain words

These three DNS records are the reason a forged email either lands in your customer's inbox or does not. They are unglamorous, frequently misconfigured, and cost nothing but attention.

SPF publishes a list of the servers allowed to send email for your domain. DKIM signs your outgoing mail so a recipient can verify it was not altered in transit. DMARC ties the two together and tells receiving servers what to do when a message fails — and, importantly, asks them to report back who is sending mail as you.

The common failure is having all three set to permissive values that make no difference: an SPF record ending in a soft fail that no one enforces, a DMARC policy set to 'none' and left there since setup. It looks configured on an audit and stops nothing. Getting to an enforcing policy without silently blocking your own invoices is the actual work.

  • Records set to enforce, not merely to exist
  • Legitimate senders — accounting systems, your ERP, marketing tools — identified before enforcement, so nothing of yours is caught
  • Reporting turned on, so you can see who is attempting to send as you

One account per person, and one switch to turn it off

The identity question sounds administrative and turns into a security problem the day someone leaves. In most businesses an employee accumulates logins across a dozen systems over several years. When they resign, someone tries to remember them all. Some are always missed, and those accounts stay live indefinitely.

Where it helps, we connect your tools so staff sign in once with a single company account instead of juggling separate passwords. That is convenient on any ordinary day. On the day someone leaves it is the whole point: one switch turns off all their access, and there is nothing to remember.

Two-step login on every account closes the other common route in, which is a password reused from a personal service that was breached years ago and posted publicly. Passwords leak constantly and there is nothing you can do about it — the fix is making a leaked password insufficient on its own.

Microsoft 365, Google Workspace, or something you control

We are not committed to one of these, and that is deliberate — we recommend what fits, not what pays us. All three are defensible choices for different businesses.

Microsoft 365 tends to win where Excel is load-bearing, where Teams is already how people talk, or where a client or regulator expects it. Google Workspace tends to win where the business lives in a browser and wants simpler administration. Self-hosted alternatives win where data residency, cost at scale, or plain independence from a subscription matters more than convenience.

The honest trade-off: self-hosting means you own the uptime. That is a real commitment, and it is the right one for some businesses and the wrong one for others. What matters is choosing deliberately rather than inheriting whatever the previous provider happened to resell — and knowing that whichever you pick, the data still needs backing up, because a provider's retention window is not a backup.

COMMON QUESTIONS

Email & workplace tools — the questions we get asked

What happens to a leaver’s access?

One switch turns off all of it. Accounts are set up so access can be revoked centrally rather than chased across separate tools.

Can staff use one login across our tools?

Where it helps, yes. We connect your tools so staff sign in once with a single company account instead of juggling separate passwords.

How do you stop fake-invoice and phishing email?

Spam, phishing and fake-invoice email is filtered out, and we set up the technical records that stop criminals sending email that appears to come from your domain.

Do we have to use Microsoft 365?

No. We work with Microsoft 365, Google Workspace, or self-hosted alternatives you control — whichever fits how you operate.