Setting Up Microsoft 365 Isn't Just an IT Checkbox
Getting Microsoft 365 running for a business usually looks simple on paper. Point a few DNS records at Microsoft, activate the licenses, hand out passwords, and call it done in an afternoon. That's how a lot of setups actually happen, and it's exactly the gap attackers count on. The tenant works, mail flows, and nobody configured the security features already sitting in the admin centre. Nobody notices the gap until something goes wrong, and by then the cost is no longer hypothetical.
That gap rarely announces itself. A tenant with default settings sends and receives mail exactly the same as a properly hardened one, right up until someone tests it. Conditional access policies that were never turned on, admin roles that were never reviewed, and MFA that was enabled but never configured against real-world bypass techniques all look identical from the inbox. The difference only shows up the day an attacker goes looking for it, and the data below makes clear they are looking, constantly and at scale.
Business Email Compromise Is Not a Scare Tactic
In 2024 alone, the FBI's Internet Crime Complaint Center logged 21,442 complaints tied to Business Email Compromise, reporting $2,770,151,146 in losses in the United States. BEC is the fraud where an attacker gets inside, or convincingly impersonates, a business email account and uses that access to redirect payments, request wire transfers, or manipulate invoices. It depends entirely on getting into, or looking like they've gotten into, an email system that isn't locked down properly.
That's not a one-year spike, either. Cumulative global BEC losses reported to the IC3 from October 2013 through December 2023 reached $55,499,915,582 across 305,033 incidents. The FBI describes the pattern directly, noting the crime targets "small local businesses to larger corporations." This isn't a threat reserved for enterprise organizations with dedicated security teams. It goes after whoever is reachable, and a loosely configured Microsoft 365 tenant is reachable.
The Attacks Targeting Microsoft 365 Are Accelerating Right Now
This is also actively getting worse, not settling into some steady baseline. Phishing activity aimed specifically at Microsoft 365 users surged 1,380% between late 2025 and early 2026, driven by a growing ecosystem of AI-powered phishing-as-a-service kits. Tools like Jalisco, OmegaLord, EvilTokens, and Kali365 are part of that wider toolkit ecosystem, not isolated causes of the surge on their own. Some of these kits bypass multi-factor authentication through OAuth device-code flows. Others harvest phone numbers so they can intercept MFA codes directly. Turning MFA on used to feel like the finish line. It's now closer to the starting point, because the kits actively targeting Microsoft 365 tenants right now were built specifically to get around it.
Small and Mid-Sized Businesses Are the Ones Getting Hit
None of this data points at large enterprises as the primary target. Ransomware was present in 88% of breaches affecting small and medium-sized businesses in 2024, compared with 39% for large organizations, according to the Verizon 2025 Data Breach Investigations Report. The median ransom payment in that same dataset was $115,000, down from $150,000 the year before, and 64% of victim organizations did not pay. For SMBs specifically, social engineering made up 13% of breaches and was "almost exclusively of the Phishing variety." Put together, the businesses closest in size to the one reading this are the ones absorbing the worst of it.
Hiring Cheap, Unvetted Setup Help Is Its Own Risk
The share of breaches involving a third party doubled to 30% in the 2025 Verizon DBIR. That number matters directly for how a lot of Microsoft 365 tenants get set up in the first place. Many small businesses hand the job to whoever is available and cheapest, a freelancer, a generalist contractor, sometimes a well-meaning employee, without ever checking how that person handles security configuration once the setup is finished. If the person who configured the tenant didn't vet their own practices, they've become part of the business's attack surface, and the data shows that exposure is growing rather than shrinking.
What a Breach Actually Costs
Phishing remains the top initial attack vector, responsible for 16% of all breaches tracked in IBM's 2025 Cost of a Data Breach Report, which puts the global average cost of a breach at $4.44 million and the average time to identify and contain one at 241 days. In Canada specifically, businesses lost an average of CA$6.98 million per data breach in 2025, up 10.4% from CA$6.32 million in 2024, and breaches caused specifically by phishing cost Canadian organizations an average of CA$7.91 million, a 24% increase year over year. Those aren't distant global figures. They're what happens in Canadian businesses when a phishing email gets through an email system that wasn't configured properly.
This Affects Most Businesses Now
This isn't a niche concern limited to companies running complex cloud infrastructure. Statistics Canada found 48% of Canadian businesses used cloud computing in 2023, up from 45% in 2021. Microsoft 365 setup used to be a fringe IT decision. It's now close to a default one, and default decisions deserve more scrutiny than they usually get.
What Proper Setup Actually Looks Like
None of this means Microsoft 365 is unsafe to run. It means the setup has to go further than switching features on and calling the job finished. Multi-factor authentication needs to be configured against the methods attackers are actually using right now, not just enabled and left at default, because the phishing kits accelerating over the past several months were built specifically to slip past MFA that wasn't configured with that in mind. Admin accounts need real hygiene too, separate credentials, limited standing access, and regular review of who still actually needs elevated permissions. And someone needs to be watching the tenant on an ongoing basis, monitoring sign-in activity and configuration drift, rather than confirming the security toggles got flipped once during onboarding and never checking again.
None of that is exotic. It's also not something most businesses have the internal bandwidth to keep up with alongside everything else running the company day to day. The gap isn't a knowledge problem so much as an attention problem, someone has to actually own the configuration, watch for drift as staff and devices change, and stay current as attackers keep adapting the way they target Microsoft 365 tenants specifically. That's ongoing work, not a one-time setup task, and treating it as the latter is how a technically functioning tenant quietly turns into an unmonitored one.
That's the gap between a Microsoft 365 tenant that technically works and one actually set up to hold up against the kind of attacks described above. If your setup was handled as a quick checkbox item, or nobody has independently verified how it's configured since, our email hosting team can walk through what's actually in place versus what only looks like it's in place. Properly configured email hosting is one of the few security investments with a direct, traceable line to the losses in the numbers above, and it's worth treating that way from the start.




