Most business owners think of email security the way they think of flood insurance: a line item you pay for, hope you never need, and quietly resent every renewal. Fair. But what if I told you the right email security tool starts paying you back on day one — not in “breach avoided” hypotheticals, but in actual hours your team stops wasting on garbage in their inbox?
That’s not a pitch. That’s what six-plus months of real data from one of our small law-firm clients shows. Here’s the breakdown.
First, what Avanan actually is
Avanan — now branded Check Point Harmony Email & Collaboration after Check Point acquired them in 2021 — is an email security platform built for Microsoft 365 and Google Workspace. What makes it different from the “email security” you’ve probably heard of before is how it plugs in.
Traditional email security uses something called a Secure Email Gateway, or SEG. A SEG sits in front of your mail — you change your MX records (the internet’s phone book entry that tells the world where to send your email) so mail routes through the gateway first, gets scanned, and then gets delivered to your inbox. It works, but it has blind spots: it can’t see internal email (partner emailing paralegal), and once mail is delivered, it’s done.
Avanan is API-based. It sits inside Microsoft 365 or Google Workspace, scanning mail after it’s been delivered — and it can quarantine or “claw back” a message even after it’s already in the inbox. No MX changes. No routing surgery. And critically, it inspects internal-to-internal email, which is exactly where Business Email Compromise (BEC — that’s when a bad actor takes over one of your employee accounts and emails your other employees or your clients) does the most damage. It runs on top of the native Microsoft or Google filters, not instead of them. Layered defense.
The case study: an 11-seat professional services firm
The client is a small law firm we support in New Jersey — 11 seats, Microsoft 365, the usual mix of partners, associates, paralegals, and admin staff. We deployed Avanan and have been watching the detection dashboards for over six months. As of this writing, the year-to-date window covers roughly 6.77 months.
Here’s what Avanan has caught and handled in that time:
- Graymail (newsletters, promos, low-value bulk mail): 11,787 messages — 61% remediated
- Spam: 6,480 — 99% remediated (we’ll get to why we don’t count this)
- Phishing: 342 attempts — 100% remediated
- Data Loss Prevention (DLP) events: 149 — 100% remediated
- Anomalies flagged: 26
- Malware: 3 attempts — 100% remediated
Total: about 18,790 items handled without a human in the loop.
Let me translate that into monthly numbers, because “over 6.77 months” isn’t how any of us think:
- ~1,740 pieces of graymail per month
- ~51 phishing attempts per month reach this 11-person firm
- ~22 DLP events per month (sensitive data going somewhere it shouldn’t)
- 3 malware attempts caught in the first 7 months of the year — small number, but each one is a potentially firm-ending event
A single business email compromise at an 11-person law firm can run six figures once you count downtime, forensics, and lost billable hours. The math on prevention isn’t complicated.
— Glenn Kupsch, President, Adaptive IT
The “bonus” ROI most people ignore: graymail
Here’s the math nobody in email security marketing wants to walk you through, because it’s boring and it’s small. But small × 11 people × every workday adds up fast.
Graymail isn’t spam. It’s the newsletter you signed up for three years ago, the vendor “checking in,” the promotional blast from a conference you attended once. It’s not malicious. It’s just noise. And every one of those messages takes an employee about five seconds to see, judge, and delete — or worse, get pulled into reading for thirty seconds before catching themselves.
At this firm, Avanan is quietly handling roughly 1,740 pieces of graymail per month. At five seconds per message, that’s 8,700 seconds — 2.42 hours per month of collective staff time this firm is no longer spending on inbox triage.
Dollarize it. A small law firm blends out to something like $110/hour across partners, associates, paralegals, and admin (conservative — partner time alone is multiples of that). 2.42 hours × $110 = about $266/month in reclaimed productivity.
Avanan runs roughly $6 per user per month at typical MSP pricing — call it ~$66/month for an 11-seat firm. (That’s an estimate; your actual price varies by contract term, reseller, and bundle.)
$266 in reclaimed time ÷ $66 in cost ≈ a 4x monthly return on productivity alone. Before we count a single phishing email that didn’t land. Before we count the malware that didn’t detonate. Before we count the client data that didn’t leak.
Why we don’t count spam in the ROI
Quick honest note: we deliberately left the 6,480 spam messages out of the ROI math. Every mail platform on earth — Microsoft 365, Google Workspace, even your old on-prem Exchange — does basic spam filtering out of the box. Claiming Avanan’s “unique value” includes spam filtering would be dishonest. Avanan does it, and does it better, but it’s not what you’re paying it for. Phishing, BEC, malware, DLP, and graymail cleanup are.
Insurance with an ROI
Now let’s talk about the “insurance” side, because this is where the number gets scary.
According to IBM’s Cost of a Data Breach Report 2024, the global average breach costs $4.88 million. The US average is $9.36 million. For small and mid-sized businesses under 500 employees, the average is $3.31 million. Those numbers are for enterprises and mid-market — not for an 11-person law firm. But scale it down. A realistic BEC or wire-fraud incident at a small firm — one where a bad actor spoofs the managing partner and gets a paralegal to redirect a client trust wire — runs somewhere in the $25,000 to $150,000 range once you tally downtime, forensics, breach notification, lost billable hours, and reputational cleanup. And that’s assuming no bar complaint.
So the pitch is this: even if Avanan never stops a real attack, this firm is already netting a 4x monthly return on it in reclaimed time. The 342 phishing attempts and 3 malware payloads it did stop this year? That’s the insurance side — and it’s free, because the productivity math already covered the premium.
Do this for free, regardless
Whether you ever look at a paid email security tool or not, do this today: make sure your DMARC, DKIM, and SPF records are in place and correctly configured on your domain. These three DNS records tell the rest of the internet which servers are actually allowed to send email as you — which cuts down dramatically on spoofing and impersonation. Setting them up is free. It takes a knowledgeable person maybe an hour. Ask whoever runs your IT, or ask us — but get it done. It’s the single highest-impact free thing a small business can do for email security.
As an MSP, we see a lot of trash out there. The single easiest thing any business can do — for free, today — is get your DMARC, DKIM, and SPF records right. It won’t stop everything, but it’ll cut the garbage way down.
— Glenn Kupsch, President, Adaptive IT
Want to see your own numbers?
We’ll set up a 14-day Avanan trial on your Microsoft 365 or Google Workspace tenant, no MX changes, no disruption to your existing mail flow. At the end of two weeks, we’ll walk you through your own detection dashboard — what got caught, what got clawed back, and what it would cost you in time and risk if it hadn’t. Then you decide.
Email us at [email protected] and we’ll get it scheduled.