How to Strengthen Your Email Security: 6 Proven Steps for Small Businesses here in Grand Rapids, Michigan (and beyond!)
Greg Johnson • January 28, 2025

6 Essential Steps to Strengthen Email Security and Protect Your Grand Rapids Business

How to Protect Your Business with Enhanced Email Security


Email remains the backbone of communication for businesses and individuals alike. However, it’s also a the main target for cybercriminals. As cyberattacks become increasingly sophisticated, beefing up your email security is no longer optional—it’s essential - like yesterday!

Did you know that 95% of IT leaders report an increase in advanced cyberattacks, with more than 51% encountering AI-powered threats? These trends show us the importance of taking measures to protect our sensitive information, prevent unauthorized access, and make sure the integrity of your business communications is safe.

You have a small business here in Grand Rapids, Michigan - or anywhere really, implement these six steps to help you fortify your email security.


1. Use Strong, Unique Passwords for All Email Accounts


Passwords are your first line of defense against cyber guys (or gals). Weak or reused passwords (think your pet’s name or your child’s birthday) make it easy for hackers to breach your accounts.


Tips for Creating Secure Passwords

  • Make sure to combine uppercase and lowercase letters, numbers, and special characters.
  • Do not include predictable details like your name, business name, or birthdays.
  • Use a password manager to store and formulate unique passwords for each account, simplifying password management. I like LastPass.  This is not a paid post for LastPass - I just really like it and I’ve been doing this for a long time!


2. Enable Two-Factor Authentication (2FA)


Adding an extra layer of security with 2FA can protect your accounts even if a password has become compromised. This step is critical for safeguarding sensitive business communications.


Popular 2FA Methods

  • Authenticator Apps: Use this when you want to increase the security of your online accounts. This is especially important for accounts that store sensitive data, like your email or banking information. The app will generate time-sensitive codes for secure logins.
  • SMS Verification: Receive a code via text message.
  • Hardware Tokens: Use a physical device for additional authentication.

Make sure to enable 2FA across all email accounts for the most secure protection.


3. Stay Alert to Email Attachments and Links


We see this one probably the most when working with small businesses.  Malware and phishing attacks often arrive via employee’s email attachments and links. Exercise caution before opening any email content.  Here are the best practices we encourage and try to implement when working with our clients:

Best Practices for Handling Email Content

  • Verify Senders: Double-check the sender’s identity, especially if the email was unexpected.  Look at the email from where it came from.  It may say you received an email from Aunt Mary into your work inbox.  Just check to see if it’s really from Aunt Mary.
  • Hover Over Links: Preview URLs before clicking. Suspicious links often lead to fraudulent sites.
  • Use Antivirus Tools: Scan all attachments for malicious content before opening them.


4. Keep Your Email Software Updated


Regular updates for your email software ensure you’re protected against newly discovered vulnerabilities. Outdated software is an easy entry point for hackers.

Update Tips

  • Enable automatic updates for email clients and operating systems.
  • Manually check for updates regularly to ensure nothing is missed.


5. Encrypt Emails with Sensitive Information


Email encryption protects your business communications by encoding messages so only the intended recipient can read them. This step is especially important for transmitting sensitive data.

How to Use Email Encryption

  • Choose an email provider with built-in encryption tools or use third-party solutions for end-to-end encryption.
  • Provide recipients with clear instructions on decrypting messages to avoid confusion.


6. Monitor, Monitor, Monitor Email Activity for Suspicious Behavior


Keeping an eye on your email account activity can help you detect and respond to threats before they get out of hand.

Steps to Monitor Activity

  • Set up account activity alerts to receive notifications about unusual logins or settings changes.
  • Regularly review login history and device access. If you spot unfamiliar activity, act immediately by changing your password and updating security settings.

All these steps are a lot of activity to handle for small businesses.  If these areas all seem like a little too much for you to implement for your business, we’re happy to help.  The tips above will help you stay as safe as possible. 


About us

Why Grand Rapids Businesses Trust IT Systems LLC for Email Security


I’m Greg Johnson, the owner of IT Systems LLC, and for over 20 years, I’ve been helping small businesses in Grand Rapids, Michigan, protect what matters most—their data and their reputation. At IT Systems LLC, we specialize in tailored cybersecurity solutions designed to keep your business one step ahead of phishing scams, unauthorized access, and data breaches. From private healthcare practices to nonprofits and local trade businesses, we understand that no two organizations are the same, and we craft security measures that work for your unique needs. Let’s safeguard your business together—contact IT Systems LLC today and experience the confidence of knowing your systems are secure.

Don’t wait for a cyberattack to compromise your business.


Small Grand Rapids business surrounded by digital threat icons representing AI cybersecurity attacks
By Greg Johnson October 24, 2025
AI-powered cyberattacks are targeting Grand Rapids small businesses. Learn how to protect your data and client trust.
Wooden blocks with text
By Greg Johnson October 10, 2025
Still running on a local server? Cloud might be smarter in 2026. Learn the pros, cons, and how to decide what’s right for your business.
Man unsure, pointing at
By Greg Johnson September 26, 2025
Discover the real cost of hourly IT support vs. managed services. Learn how West Michigan businesses stay secure, compliant, and productive.
Person using laptop, with overlay of a firewall setup guide for small businesses. Blue and white color scheme.
By Greg Johnson September 12, 2025
Protect your West Michigan business with the right firewall. Learn setup steps, best practices, and how IT Systems, LLC keeps local networks secure.
Yellow background with text:
By Greg Johnson August 29, 2025
Stop paying for IT that only makes you a better customer. Learn how IT Systems, LLC helps small businesses use technology to grow, secure, and thrive.
School children using tablets at desks, smiling and engaged in classroom.
By Greg Johnson August 16, 2025
Back-to-school is the perfect time to fix what’s not working. Discover 5 signs your school’s tech needs an upgrade and how to do it without disruption.
By Greg Johnson August 1, 2025
Windows 10 support ends October 2025. Learn how Grand Rapids businesses can upgrade to Windows 11 without the stress, downtime, or big cost.
A woman is sitting at a desk with a laptop and a cell phone and frustrated.
By Greg Johnson July 18, 2025
If your business lost all its data tomorrow, would you be ready? This guide explains how to prepare, recover, and stay protected from digital disasters.
A purple background with gears and the words email phishing
By Greg Johnson July 4, 2025
It looked like a normal email—maybe a shipping update, a password reset, or even a message from “Microsoft” saying your account had suspicious activity. Your office manager clicks the link, logs in to "verify" their account, and suddenly… Boom. Your network’s compromised. And you’re looking at a $150,000 loss —on average. Sound dramatic? It’s not. It’s reality for nearly 2 out of 3 businesses that fall victim to phishing scams every year . And the kicker? These emails don’t even look suspicious anymore. Welcome to cybersecurity in 2025. Phishing emails have grown up, and they’re not wearing hoodies or sending you weird Nigerian prince messages anymore. They look like everyday work emails—and that’s exactly why they’re so dangerous. Let’s walk through what’s happening, how it can impact your small business, and what you can do to avoid becoming the next "oops" story. Not Your Grandma’s Spam Email Remember the good old days when spam emails were laughably bad? Weird grammar. Obvious typos. Strange fonts. You’d read them and think, “Who would fall for this?” Well, the scammers have evolved—and unfortunately, so have their emails. Phishing emails today are polished, professional, and scarily convincing. They look like: A Microsoft 365 login prompt (that’s fake) An invoice from a vendor you actually use A package delivery update from UPS or Amazon A calendar invite from a familiar name—just slightly misspelled Some are so well-crafted, they could pass as internal communications from your own team. And with the help of AI tools, these scammers can personalize, adapt, and automate their deception like never before. Honestly, some of these emails are written better than actual corporate memos. What’s the Big Deal? Just Ask the $150K You might be thinking, “Okay, so someone clicks a bad link… then what?” Well, here’s the “then what”: Hackers gain access to your inbox or shared drives They steal sensitive client data or financial info They launch ransomware and demand thousands to unlock your files They use your compromised email to trick your clients or team They install hidden backdoors to monitor your system for months And then there’s the fallout: Legal liability Client trust erosion Fines (especially if you’re in healthcare or finance) Business downtime A massive dent in your bank account The average financial loss from a phishing attack sits around $150,000 . For most small businesses, that’s not just a bump in the road—that’s a potential shutdown. And all of it can happen from one innocent click. Because Antivirus Can’t Fix Poor Judgment Here’s the truth: Your firewall can’t stop Becky in accounting from clicking a link she thought was from FedEx. Technology helps—but your people are the front line . They’re the human firewall. And if they’re not trained, they’ll leave the digital door wide open. That’s why training is not optional anymore. Your team needs to know: What phishing emails look like (and how sneaky they’ve gotten) What red flags to look for Why urgency is often a sign of a scam What to do if they accidentally click something they shouldn’t Let’s put it this way: if your employees can spot a fake handbag on Facebook Marketplace, they can absolutely learn to spot a fake Microsoft alert. Cybersecurity Instincts Are a Thing Phishing training isn’t about turning your staff into cybersecurity experts. It’s about developing a little thing we like to call “cyber instincts.” You know that feeling in your gut when something seems off? Like when your Uber driver looks nothing like the profile picture? That’s what we want to cultivate—digitally. Here’s how: Teach your team to pause before clicking Encourage them to hover over links to preview URLs Show them how to verify sender addresses Remind them: if it smells like panic, it’s probably a trap That’s why we offer hands-on cybersecurity training for teams right here in Grand Rapids. Whether you’ve got five employees or fifty, we help your staff build habits that stick and instincts that protect. It’s practical, judgment-free, and tailored to the real threats your business faces every day. You don’t need high-tech tools to stop phishing. You need a team that’s paying attention and trusting their gut. Introducing the “Better Safe Than Sorry” Call This is where we come in. At IT Systems, LLC, we offer a free, no-pressure consult we call the Better Safe Than Sorry Call . It’s exactly what it sounds like—a short conversation to help you: Understand where your team might be vulnerable Get practical, non-technical tips you can implement right away Learn about tools and training to keep your business safer Ask us anything you’ve always wondered about email security (yes, even the dumb questions—especially those) No jargon. No scare tactics. No sales pitch. Just a step-by-step walkthrough to help you breathe a little easier. 🛡️ Book your Better Safe Than Sorry Call here → Your Quick-Check Phishing Survival Guide Need something you can screenshot and send to your team right now? Here’s our cheat sheet: 🚩 5 Red Flags of a Phishing Email: Urgent or threatening language (“Your account will be closed!”) Unfamiliar sender or strange email addresses Generic greetings (“Dear Customer” instead of your name) Links that don’t match the sender’s domain Attachments you weren’t expecting Train your team to stop and check before they click. It’s the cheapest insurance policy you’ll ever invest in. You Don’t Need to Be a Cybersecurity Expert—Just a Little Paranoid The bad guys are counting on you to be too busy to notice. Too trusting to question it. Too distracted to double-check. But you don’t have to fall for it. Train your team. Slow down. Think twice. And when in doubt? Don’t click. Need help getting started? That’s what we’re here for. 👇 📞 Book your free “Better Safe Than Sorry” call now Because protecting your business shouldn't be a gamble.
A bat is smashing a wifi router on a table.
By Greg Johnson June 20, 2025
Discover how your office layout might be to blame for slow Wi-Fi and poor connectivity. Learn how to fix it with tips from IT Systems, LLC in Grand Rapids, MI.
Show More