leadforensics

Microsoft 365 Costs Are Rising: Is Your Email Security Keeping Up?

Microsoft 365 email security

From 1 July 2026, the list price of most commercial Microsoft 365 subscriptions goes up. Microsoft has confirmed the change covers Office 365 E3, Microsoft 365 Business and Enterprise plans, and a range of standalones, with existing customers picking up the new pricing at their next renewal after that date. For some businesses the rise is modest. For others, particularly those with a mix of Enterprise and Frontline licences, it is sharp enough to prompt a real conversation at board level.

A renewal is rarely just a price negotiation. It is a procurement event that puts the whole stack back on the table. Are you on the right plan? Are you using what you are paying for? And the question that gets asked least often: is the email environment running on top of all that licensing protected to the level your business needs?

Why email is still the easiest way in

The pattern has been consistent for years, and the most recent UK data confirms it. The government’s Cyber Security Breaches Survey 2025/2026 found that phishing was by far the most prevalent type of attack experienced by businesses, reported by 38% of businesses surveyed, and rated as the most disruptive type of breach by 69% of the businesses it affected. For medium and large businesses, the headline breach rate sits well above 60%.

Email remains the cheapest, fastest, and most reliable way for a criminal to get a foothold inside a business. What has changed is the shape of the threat. Bulk spam and crude phishing still arrive in volume, but the attacks that cause real damage are increasingly targeted. Business email compromise is one example, where an attacker impersonates a director or a supplier to redirect a payment. Spear phishing is another, drawing on publicly available information about an individual to craft a message that looks entirely normal. Account takeover sits somewhere in between, with stolen credentials letting an attacker sit quietly inside a real mailbox for weeks before acting.

The National Cyber Security Centre has been clear that business email compromise is a rising concern for small and medium businesses, partly because the financial damage of a single successful supplier payment redirection can run into six figures, often with little chance of recovering the money once it has moved.

Where standard Microsoft 365 protection runs out

Most businesses paying for Microsoft 365 assume the bundled security covers them. For day-to-day spam and known malware, the default tools do a reasonable job. The harder questions sit at the edges.

When a finance team receives an email that appears to come from a supplier they have paid every month for five years, asking for the bank details to be updated, what is stopping that message from reaching the inbox? When a director’s account is accessed at three in the morning from an IP address in another country, what is watching for that? When an internal email is sent from a real compromised mailbox to a colleague, what flags it as suspicious before the colleague acts on it?

These are the scenarios where standard configurations often come up short. Built-in protection is typically tuned conservatively to avoid blocking legitimate traffic, which means the more sophisticated, lower-volume attacks regularly slip through. The price increase coming on 1 July 2026 is going to force renewals into the open, and that creates a natural moment to ask whether the protection layer has kept pace with the way attacks have changed.

What stronger email protection looks at

A more capable setup is less about adding one product and more about putting a few things together so they work as a system. In practice, that usually means looking at four areas.

The first is threat prevention at both the gateway and inside the mailbox itself, combining traditional filtering with API-based inbox defence that can see internal traffic and unusual sender behaviour. The second is threat detection for the threats that get through, identifying suspicious activity inside the Office 365 environment before damage spreads. The third is incident response, so that when something does land, the response is automated where possible, with quick recovery from backup. The fourth is impersonation protection, designed specifically for account takeover and business email compromise, watching behavioural signals rather than just message content.

None of this is exotic. The tools exist and are widely used. The gap, in our experience, is less about technology availability and more about whether anyone has sat down with a specific business to look at where its current cover ends and where the residual risk sits.

Use the renewal as a review moment

A renewal is a good forcing function. You are already going to scrutinise the cost line. Adding ten minutes to that conversation to ask, “What does our current setup catch, and what does it not?” is rarely wasted time. It is also much cheaper than discovering the answer after a successful attack.

For businesses across the West Midlands that rely on Microsoft 365 for daily communication, the price change coming on 1 July 2026 is not the most important thing about the next renewal on its own. The more useful question is whether the protection sitting on top of those licences still matches the level of threat that has been steadily shifting since the last contract was signed.

If it does, the renewal is straightforward. If it does not, the renewal is the right time to do something about it.

Before you sign the renewal

Most businesses approaching a Microsoft 365 renewal scrutinise the cost line and skip past the security one. The assumption is that Microsoft’s defaults cover the basics, and the basics are what most attacks look like.

Five years ago that assumption mostly held. It holds less well now.

If you would like a second opinion on whether your current setup still matches the threats your business is facing, get in touch. We will take a look and tell you what we find. No pressure beyond that.

Frequently Asked Questions

Microsoft 365 security in Birmingham involves protecting your accounts, email, and data with multi-factor authentication (MFA), threat protection, and monitoring for suspicious activity. Strong Microsoft 365 protection in Birmingham pairs the right licence settings with ongoing oversight.

Microsoft 365 pricing changes from 1 July 2026, with existing customers seeing new prices at their next renewal. Use the renewal to confirm which email security features your licence includes and whether you need added protection.

Business email compromise protection works by combining email filtering, MFA, and impersonation detection with monitoring and a clear response plan. It stops fraudulent payments and account takeover before they cause a loss.

1732024282120
Neil Norton

Went to Birmingham City University and achieved his BSc. (Hons) from 1989-1992 in Industrial Information Technology.