A cyber incident does not always begin inside the organisation that ultimately bears the cost. Sometimes it starts with a supplier, contractor, service provider or trusted partner. That is one of the important lessons emerging from the reported cyber incident involving Origin Energy, where authorities have traced the breach to a former employee connected with an offshore call centre operated by a third-party provider. According to reporting by the ABC, the incident potentially exposed information relating to approximately 900,000 current and former customers. The investigation remains ongoing.
What the Origin Energy breach means for partners managing email, identity and third-party risk
The details of the incident will continue to emerge. But for IT partners, MSPs and security providers, the broader lesson is already clear: Your client’s security perimeter is no longer defined by the systems they own. It extends into the organisations, people and communication channels they trust.
The trust problem is bigger than the technology problem
Modern businesses rarely operate in isolation. They rely on accountants, lawyers, distributors, software providers, managed service providers, offshore support teams, recruitment agencies, logistics companies and hundreds of other external relationships. Those relationships create enormous operational value. They also create pathways through which information, credentials, instructions and money can move.
Email sits at the centre of many of those interactions. A supplier sends an invoice. A customer requests a change to payment details. An executive asks a third party to provide information. An external consultant sends a document for approval. None of these activities look inherently suspicious. That is precisely why they are attractive to attackers.
The supplier problem for MSPs
For many partners, the traditional security conversation has centred on the client's own environment: Are endpoints protected? Is MFA enabled? Are systems patched? Is Microsoft 365 configured correctly? Are backups working?
Those questions remain essential. But partners should increasingly be asking another question: Who does your organisation trust to access, handle or communicate about your information? That means examining third-party relationships through a different lens.
A contractor with access to customer information can become a security concern. A supplier whose email account is compromised can become an avenue for fraud. A trusted external contact can become the identity an attacker chooses to impersonate. The security issue is therefore not simply whether a third party is secure. It is whether your client has controls capable of recognising when a trusted relationship has been compromised.
Email is where trust becomes actionable
Email security needs to evaluate more than whether a message contains malware. It needs to consider sender identity, domain reputation, behavioural signals, message characteristics, context and other indicators that can reveal an impersonation attempt. The goal is not to eliminate human judgement. It is to make sure employees are not being asked to make high-risk decisions with no technological support.
What should partners be asking clients?
1. Which third parties have access to sensitive information? Map suppliers, contractors, service providers and other external organisations that can access customer, financial or operational data.
2. What happens if one of those organisations is compromised? Do your clients have controls that can identify suspicious communications from otherwise trusted relationships?
3. How are payment changes verified? A written policy is useful. An enforced process is better.
4. Can the business detect compromised accounts quickly? The longer an attacker can operate inside a legitimate mailbox or conversation, the more convincing their activity can become.
5. What happens when an employee or contractor leaves a third party? Access, accounts, credentials and information flows need to be considered throughout the relationship lifecycle.
The partner opportunity is bigger than email filtering
For MSPs and resellers, this is an opportunity to move the conversation away from individual security products and towards risk management. Clients do not necessarily need another dashboard. They need confidence that the systems supporting their business can distinguish between legitimate trust and abused trust. That means combining strong identity controls, MFA, secure configuration, user processes, supplier governance, monitoring and specialist email protection. Email is one important layer in that broader architecture because it is where many trusted business relationships become operational.
Final thought
The most dangerous email in an employee's inbox may not look like an attack. It may look like a message from someone the business has worked with for five years. That is why modern email security cannot be based solely on identifying obviously malicious messages. It needs to understand trust, context and behaviour.
For partners, that creates a valuable conversation with customers: where does your security perimeter actually end? In an increasingly interconnected business environment, the answer is rarely at the edge of your own network. It ends where your trust begins.
Keeping Businesses Safe and Secure
Prevention is always better than a cure, and one of the best defences is to encourage businesses to proactively boost their company's cyber resilience levels to avoid threats landing in inboxes in the first place. The fact that a staggering 94% of malware attacks are delivered by email, makes email an extremely important vector for businesses to fortify.
No one vendor can stop all email threats, so it's crucial to remind customers that if they are using Microsoft 365 or Google Workspace, they should also have a third-party email security specialist in place to mitigate their risk. For example, using a specialist AI-powered email threat detection solution like MailGuard.
For a few dollars per staff member per month, businesses are protected by MailGuard's specialist, AI-powered zero-day email security. Special Ops for when speed matters! Our real-time zero-day, email threat detection amplifies your client's intelligence, knowledge, security and defence.
MailGuard provides a range of solutions to keep businesses safe, from email filtering to email continuity and archiving solutions. Speak to your clients today to ensure they're prepared and get in touch with our team to discuss fortifying your client's cyber resilience.
Talk to us
MailGuard's partner blog is a forum to share information; we want it to be a dialogue. Reach out to us and tell us what your customers need so we can serve you better. You can connect with us on social media or call us and speak to one of our consultants.
Australian partners, please call us on 1300 30 65 10
US partners call 1888 848 2822
UK partners call 0 800 404 8993




