BEC monitoring for Microsoft 365

Noetis (pronounced “notice”)

Noetis is continuous Business Email Compromise monitoring for Microsoft 365. It watches for the signs that someone has gained — or is abusing — access to your company’s email accounts, and puts a plain-English alert in front of a real person while there’s still time to act.

Business Email Compromise (BEC) is when a criminal gets into a real email account and uses it to redirect a payment. Not a virus. Not spam. A login.

Book a monitoring assessment

The email looked exactly right. Same sender, same signature, same thread you’d been on for weeks. It just had updated wiring instructions. The payment went out on a Friday. By Monday it was gone — and money sent this way is usually gone for good.

How it actually happens

A BEC attack in five quiet steps

  1. 1

    They get one password

    A criminal obtains a single employee’s Microsoft 365 password — phished, reused from another breach, or simply bought.

  2. 2

    They read quietly, for weeks

    They sign in and just watch. No files, no damage, nothing to notice. They learn how you talk and who pays whom.

  3. 3

    They wait for a real payment

    They let a genuine, expected invoice or closing come up in conversation — one nobody will question.

  4. 4

    They change the instructions

    From the real, trusted account, they send updated wire or ACH details (ACH — the bank transfers used for payroll and vendor payments). It looks completely legitimate, because it comes from inside.

  5. 5

    The money lands in their account

    The funds go to the criminal and are rarely recovered.

The businesses most exposed are the ones that move large payments with small teams: homebuilders and contractors, title and real estate, law firms, accounting practices, and medical and dental groups.

The FBI’s Internet Crime Complaint Center (IC3) has for years ranked Business Email Compromise among the costliest cybercrimes in the country. Its 2025 Internet Crime Report attributed $3 billion in reported losses to BEC — second only to investment fraud.

The blind spot

Why the tools you already pay for don’t see this

Each one does an important job. None of them is watching for this particular attack.

Your spam filter

reads mail coming in and blocks known-bad senders and attachments. A BEC message arrives from a real account your filter already trusts — so it sails straight through. Keep the filter; it just can’t see this.

Your antivirus

watches the files and programs on your computers (this is sometimes sold as “endpoint protection”). In a BEC attack nothing is downloaded and nothing is installed — there’s simply no malware for it to find.

Your MFA

MFA — the extra code or phone prompt at sign-in — guards the front door, and it matters. But it doesn’t watch what happens once someone is inside, and it won’t notice a hidden forwarding rule or a new app quietly granted access to a mailbox.

The gap isn’t better technology. It’s that in a 20-person company, nobody is watching the identity layer — the record of who is signing in, from where, and what they change. That’s the one thing Noetis does.

What it watches

The signals of an account being taken over

Everything here is live today. In plain terms:

Where sign-ins come from

Logins from countries you don’t do business in, two sign-ins so far apart they’re physically impossible (“impossible travel”), sign-ins Microsoft itself flags as risky, and devices no one recognizes.

Break-in attempts

Automated password-guessing — trying many passwords, or one password across many accounts — and slow, patient campaigns, gathered into a single incident instead of hundreds of separate alerts.

Software using your email that shouldn’t

When an account signs in through developer or automation tools — the kind attackers script — that a bookkeeper or office manager would never touch.

Hidden inbox rules

Rules that quietly forward, redirect, delete, or file away mail — the classic way an intruder reads your email without you noticing.

Secret forwarding

Copies of mail being sent out of the building, set at the account level — separate from inbox rules, and just as quiet.

Changes to how accounts prove who they are

A new phone or authenticator app added or removed — matched to the session that did it, so an employee setting up a new phone reads differently from an attacker adding a back door.

New apps granted access to a mailbox

When someone approves an outside app to read their email (this is called an “OAuth consent”) — a common way attackers keep access even after a password is changed.

New devices joining

New computers or phones added to your Microsoft 365, and new sign-in credentials created on them.

Someone being handed the keys

Any account promoted to an administrator role — the level of access that can change settings for everyone.

Calendar invitations used as bait

Meeting invites carrying payment language, fake or lookalike organizers, or bulk sends to outsiders.

Copycat web addresses

Newly registered domains built to look like yours — an extra letter, a swapped word — scanned daily.

Clear edges

What Noetis is not

A tool you can trust is one that’s honest about its edges. Here’s what Noetis deliberately does not do.

  • Not a SIEM

    It doesn’t vacuum up logs from everything you own (that’s a “SIEM”). It’s a focused, high-signal layer aimed at one thing: email-account fraud.

  • Not antivirus or endpoint protection

    It doesn’t run on your computers and doesn’t hunt for malware.

  • Not a spam filter

    It doesn’t scan or quarantine incoming mail. (Checking whether one specific message is malicious is a separate product — see below.)

  • Not network monitoring

    No firewall, no traffic inspection.

  • Not automated remediation

    Noetis never changes anything on its own. Every corrective step requires a person to review and confirm it. This is deliberate — more on why below.

  • Not a replacement for MFA, Conditional Access, or backups

    It watches for the failure and abuse of those controls (“Conditional Access” = the rules that decide who may sign in and under what conditions). It doesn’t replace them.

Noetis

answers “Has someone gained or is someone abusing access to an account?” — it watches the accounts themselves.

phish.noetis.us

a separate product, answers “Is this one specific message malicious?” — you submit a suspicious email and get it analyzed.

Visit phish.noetis.us →
How it works

Watchful, quiet, and never acting on its own

Read-only by design

Noetis connects to Microsoft 365 and reads. By default it changes nothing at all.

Nothing on anyone’s computer

There’s no software to install on staff machines — no new login, no plugin, no slowdown. Your team won’t know it’s there, and their day doesn’t change.

Connected securely

It authenticates with a cryptographic certificate instead of a shared password, with three separate least-privilege connections: one to read, one to send alerts, one for confirmed fixes. No standing admin credentials left lying around.

A person is always in the loop

An automated tool that locks the wrong account in the middle of a workday causes its own damage. So Noetis never acts by itself. When it sees something, it brings a person a clear explanation and a recommended step — and a human decides what happens next. Onboarding is typically same-day.

What you get

Alerts in plain English — and a record you can hand to ownership

Real-time alerts

For anything urgent — written in plain language, with what we saw and a recommended action.

Daily & weekly summaries

A short, ordinary-language recap of what happened, so nothing important sits unread.

Quarterly written report

Volume, trends, most-targeted accounts, notable incidents, and the actions actually taken — suitable to hand to ownership, an insurer, or a client doing due diligence.

What monitoring actually surfaces. Over one week on a live client tenant, Noetis recorded 165 failed break-in attempts against a single employee’s account — every one through Microsoft administrative tooling that user has no reason to touch, from 165 different internet addresses disguised to look US-based. None succeeded.

Noetis didn’t stop those attempts — the account’s own password and lockout controls did. What Noetis did was make a sustained, targeted attack visible, so it could be acted on. Without monitoring, no one would have known the account was under attack at all.

Pricing

Two ways to run it

Essentials — we watch and tell you.  ·  Managed — we watch, investigate, and walk you through the fix.

One-time setup · required

Microsoft 365 connection and certificate setup, appliance provisioning, baselining your tenant, tuning alerts, and a documented monitoring scope. Includes the first 30 days of tuning.

$995
Essentials

Monitoring & alerting

$249/mo · up to 25 mailboxes
$399/mo · 26–75 mailboxes
+$8 per mailbox / month beyond 75
  • All monitoring above, running continuously
  • Real-time alerts with recommended actions
  • Daily & weekly plain-English summaries
  • Quarterly written report
  • Email support

Best for organizations with internal IT who’ll handle the response themselves.

Scope Essentials
Managed

Monitoring, triage & response

$649/mo · up to 25 mailboxes
$1,049/mo · 26–75 mailboxes
+$18 per mailbox / month beyond 75

Everything in Essentials, plus:

  • Every alert reviewed by a person — you’re contacted when something is real, not for every event
  • Investigation and written findings for confirmed incidents
  • Guided remediation — session revocation, password resets, removing malicious rules — done with your confirmation
  • Conditional Access and identity-hardening recommendations
  • Quarterly review call
  • 3 hours / month of incident response included (more at the standard hourly rate)

Best for organizations without dedicated security staff that move significant payments.

Scope Managed

A “mailbox” is one email account. Microsoft licensing (for example, Entra ID P1 for Conditional Access) isn’t included and is billed at cost where it’s needed. A multi-entity discount is available where several related companies share monitoring. Prepaid annually runs about ten months’ cost.

Noetis detects and alerts. It does not guarantee that an incident will never happen — no honest monitoring service can. Its value is catching intrusion and abuse early, so a person can act.

Questions

Straight answers

Does this replace my spam filter?

No — they do different jobs. Your spam filter screens mail coming in. Noetis watches the accounts themselves for signs of intrusion or abuse. Keep your spam filter; Noetis sits alongside it.

Will it lock my staff out of anything?

No. Noetis is read-only by default and never acts on its own. It won’t lock accounts, block sign-ins, or interrupt anyone’s work. Any corrective step happens only after a person reviews it and you confirm.

We already have MFA — isn’t that enough?

MFA is important; please keep it. But it guards the moment of sign-in. It doesn’t watch what happens after someone is inside, and attackers have ways around it — a stolen active session, a hidden forwarding rule, or a new app quietly granted access to a mailbox. Noetis watches that layer.

Who can see our email?

Noetis is built to watch the signals around your accounts — sign-ins, rules, forwarding, app grants — not to sit and read your correspondence. Its access is read-only, least-privilege, and certificate-based. On the Managed tier, a person reviews the alerts Noetis raises.

What happens when you find something?

On Essentials, you get a real-time, plain-English alert with a recommended action, and your team acts. On Managed, a person investigates first, confirms whether it’s real, contacts you when it matters, and walks you through the fix — revoking the session, resetting the password, removing a malicious rule — carried out only with your confirmation.

Does Noetis prevent BEC?

No — and any tool that claims to isn’t being straight with you. Noetis detects and alerts so a person can act quickly. Prevention comes from the controls it helps you watch, like MFA and Conditional Access, and from catching an intrusion early rather than after the money has moved.

Start with a monitoring assessment

We’ll look at your Microsoft 365 setup, map where the money-movement risk actually sits, and scope the monitoring that makes sense for your team — a straightforward scoping call, no obligation.

Book a scoping call

Prefer email? info@mycoastaltech.com

Part of the Noetis product suite — noetis.us