Your spam filter
reads mail coming in and blocks known-bad senders and attachments. A BEC message arrives from a real account your filter already trusts — so it sails straight through. Keep the filter; it just can’t see this.
Noetis is continuous Business Email Compromise monitoring for Microsoft 365. It watches for the signs that someone has gained — or is abusing — access to your company’s email accounts, and puts a plain-English alert in front of a real person while there’s still time to act.
Business Email Compromise (BEC) is when a criminal gets into a real email account and uses it to redirect a payment. Not a virus. Not spam. A login.
Book a monitoring assessmentThe email looked exactly right. Same sender, same signature, same thread you’d been on for weeks. It just had updated wiring instructions. The payment went out on a Friday. By Monday it was gone — and money sent this way is usually gone for good.
A criminal obtains a single employee’s Microsoft 365 password — phished, reused from another breach, or simply bought.
They sign in and just watch. No files, no damage, nothing to notice. They learn how you talk and who pays whom.
They let a genuine, expected invoice or closing come up in conversation — one nobody will question.
From the real, trusted account, they send updated wire or ACH details (ACH — the bank transfers used for payroll and vendor payments). It looks completely legitimate, because it comes from inside.
The funds go to the criminal and are rarely recovered.
The businesses most exposed are the ones that move large payments with small teams: homebuilders and contractors, title and real estate, law firms, accounting practices, and medical and dental groups.
The FBI’s Internet Crime Complaint Center (IC3) has for years ranked Business Email Compromise among the costliest cybercrimes in the country. Its 2025 Internet Crime Report attributed $3 billion in reported losses to BEC — second only to investment fraud.
Each one does an important job. None of them is watching for this particular attack.
reads mail coming in and blocks known-bad senders and attachments. A BEC message arrives from a real account your filter already trusts — so it sails straight through. Keep the filter; it just can’t see this.
watches the files and programs on your computers (this is sometimes sold as “endpoint protection”). In a BEC attack nothing is downloaded and nothing is installed — there’s simply no malware for it to find.
MFA — the extra code or phone prompt at sign-in — guards the front door, and it matters. But it doesn’t watch what happens once someone is inside, and it won’t notice a hidden forwarding rule or a new app quietly granted access to a mailbox.
The gap isn’t better technology. It’s that in a 20-person company, nobody is watching the identity layer — the record of who is signing in, from where, and what they change. That’s the one thing Noetis does.
Everything here is live today. In plain terms:
Logins from countries you don’t do business in, two sign-ins so far apart they’re physically impossible (“impossible travel”), sign-ins Microsoft itself flags as risky, and devices no one recognizes.
Automated password-guessing — trying many passwords, or one password across many accounts — and slow, patient campaigns, gathered into a single incident instead of hundreds of separate alerts.
When an account signs in through developer or automation tools — the kind attackers script — that a bookkeeper or office manager would never touch.
Rules that quietly forward, redirect, delete, or file away mail — the classic way an intruder reads your email without you noticing.
Copies of mail being sent out of the building, set at the account level — separate from inbox rules, and just as quiet.
A new phone or authenticator app added or removed — matched to the session that did it, so an employee setting up a new phone reads differently from an attacker adding a back door.
When someone approves an outside app to read their email (this is called an “OAuth consent”) — a common way attackers keep access even after a password is changed.
New computers or phones added to your Microsoft 365, and new sign-in credentials created on them.
Any account promoted to an administrator role — the level of access that can change settings for everyone.
Meeting invites carrying payment language, fake or lookalike organizers, or bulk sends to outsiders.
Newly registered domains built to look like yours — an extra letter, a swapped word — scanned daily.
A tool you can trust is one that’s honest about its edges. Here’s what Noetis deliberately does not do.
It doesn’t vacuum up logs from everything you own (that’s a “SIEM”). It’s a focused, high-signal layer aimed at one thing: email-account fraud.
It doesn’t run on your computers and doesn’t hunt for malware.
It doesn’t scan or quarantine incoming mail. (Checking whether one specific message is malicious is a separate product — see below.)
No firewall, no traffic inspection.
Noetis never changes anything on its own. Every corrective step requires a person to review and confirm it. This is deliberate — more on why below.
It watches for the failure and abuse of those controls (“Conditional Access” = the rules that decide who may sign in and under what conditions). It doesn’t replace them.
answers “Has someone gained or is someone abusing access to an account?” — it watches the accounts themselves.
a separate product, answers “Is this one specific message malicious?” — you submit a suspicious email and get it analyzed.
Visit phish.noetis.us →Noetis connects to Microsoft 365 and reads. By default it changes nothing at all.
There’s no software to install on staff machines — no new login, no plugin, no slowdown. Your team won’t know it’s there, and their day doesn’t change.
It authenticates with a cryptographic certificate instead of a shared password, with three separate least-privilege connections: one to read, one to send alerts, one for confirmed fixes. No standing admin credentials left lying around.
An automated tool that locks the wrong account in the middle of a workday causes its own damage. So Noetis never acts by itself. When it sees something, it brings a person a clear explanation and a recommended step — and a human decides what happens next. Onboarding is typically same-day.
For anything urgent — written in plain language, with what we saw and a recommended action.
A short, ordinary-language recap of what happened, so nothing important sits unread.
Volume, trends, most-targeted accounts, notable incidents, and the actions actually taken — suitable to hand to ownership, an insurer, or a client doing due diligence.
What monitoring actually surfaces. Over one week on a live client tenant, Noetis recorded 165 failed break-in attempts against a single employee’s account — every one through Microsoft administrative tooling that user has no reason to touch, from 165 different internet addresses disguised to look US-based. None succeeded.
Noetis didn’t stop those attempts — the account’s own password and lockout controls did. What Noetis did was make a sustained, targeted attack visible, so it could be acted on. Without monitoring, no one would have known the account was under attack at all.
Essentials — we watch and tell you. · Managed — we watch, investigate, and walk you through the fix.
Microsoft 365 connection and certificate setup, appliance provisioning, baselining your tenant, tuning alerts, and a documented monitoring scope. Includes the first 30 days of tuning.
Monitoring & alerting
Best for organizations with internal IT who’ll handle the response themselves.
Scope EssentialsMonitoring, triage & response
Everything in Essentials, plus:
Best for organizations without dedicated security staff that move significant payments.
Scope ManagedA “mailbox” is one email account. Microsoft licensing (for example, Entra ID P1 for Conditional Access) isn’t included and is billed at cost where it’s needed. A multi-entity discount is available where several related companies share monitoring. Prepaid annually runs about ten months’ cost.
Noetis detects and alerts. It does not guarantee that an incident will never happen — no honest monitoring service can. Its value is catching intrusion and abuse early, so a person can act.
No — they do different jobs. Your spam filter screens mail coming in. Noetis watches the accounts themselves for signs of intrusion or abuse. Keep your spam filter; Noetis sits alongside it.
No. Noetis is read-only by default and never acts on its own. It won’t lock accounts, block sign-ins, or interrupt anyone’s work. Any corrective step happens only after a person reviews it and you confirm.
MFA is important; please keep it. But it guards the moment of sign-in. It doesn’t watch what happens after someone is inside, and attackers have ways around it — a stolen active session, a hidden forwarding rule, or a new app quietly granted access to a mailbox. Noetis watches that layer.
Noetis is built to watch the signals around your accounts — sign-ins, rules, forwarding, app grants — not to sit and read your correspondence. Its access is read-only, least-privilege, and certificate-based. On the Managed tier, a person reviews the alerts Noetis raises.
On Essentials, you get a real-time, plain-English alert with a recommended action, and your team acts. On Managed, a person investigates first, confirms whether it’s real, contacts you when it matters, and walks you through the fix — revoking the session, resetting the password, removing a malicious rule — carried out only with your confirmation.
No — and any tool that claims to isn’t being straight with you. Noetis detects and alerts so a person can act quickly. Prevention comes from the controls it helps you watch, like MFA and Conditional Access, and from catching an intrusion early rather than after the money has moved.
We’ll look at your Microsoft 365 setup, map where the money-movement risk actually sits, and scope the monitoring that makes sense for your team — a straightforward scoping call, no obligation.
Book a scoping callPrefer email? info@mycoastaltech.com
Part of the Noetis product suite — noetis.us