Craig MacAlpine is CEO and Founder of Expert Insights. Before founding Expert Insights in August 2018, Craig spent 10 years as CEO of EPA Cloud, an email security provider that rebranded as VIPRE Email Security following its acquisition by Ziff Davis, formerly J2Global (NASDAQ: ZD) in 2013.
Craig is a passionate security innovator with over 20 years of experience helping organizations to stay secure with cutting-edge information security and cybersecurity solutions.
Using his extensive experience in the email security industry, he founded Expert Insights with the singular goal of helping IT professionals and CISOs to cut through the noise and find the right cybersecurity solutions they need to protect their organizations.
What Is Proofpoint Essentials? Proofpoint is the world’s largest email security provider, delivering protection to organizations of all sizes, including 85% of the Fortune 100. Proofpoint Essentials is their solution designed for small- to mid-sized businesses, delivering enterprise-grade security at an accessible price point. Essentials is a comprehensive protection platform comprised of advanced email protection,...
As a relative newcomer in the threat detection and response market, what is an XDR solution and why should you consider investing in one?
How do the different types of email encryption work, and which is the best to secure your organization's email communications?
Expert Insights CEO Craig MacAlpine and Content Editor Joel Witts appeared on the Easy Prey Podcast to talk though the risks associated with ransomware attacks
How to choose the right email security software.
How Expert Insights is helping Bleam to provide their customers with the best cybersecurity solutions on the market
A comparison between Mimecast and Proofpoint, two market leading email security vendors.
We reviewed the leading endpoint security platforms on the breadth of threat detection, how well each handles the range of device types in modern enterprise environments, and the management overhead that security teams face at scale.
We reviewed the leading business DMARC solutions on reporting quality for identifying unauthorized senders, ease of moving from monitoring to enforcement, and how well each surfaces domain spoofing attempts before they reach targets.
We reviewed the leading email archiving platforms on search performance under large data volumes, retention policy flexibility, and the eDiscovery workflows that legal and compliance teams rely on when records are requested.
We reviewed the leading email encryption platforms on the strength of encryption implementation, the friction they introduce for recipients, and how well the admin controls support compliance and audit requirements.
We reviewed the leading email security platforms on threat detection coverage, deployment complexity, and how well each handles the full range of attacks targeting business email. Here's what we think organizations should be running.
We reviewed the leading email spam filtering platforms on catch rates, the false positive rates that determine whether legitimate email gets blocked, and how well each handles the phishing and malware payloads hidden in spam campaigns.
We reviewed the leading M365 backup platforms on workload coverage, recovery granularity, and how well they handle eDiscovery requests alongside standard data restoration. Native M365 tooling does not replace what these platforms deliver.
We reviewed the leading user authentication and access management platforms on policy control depth, the range of authentication options, and how well each handles risk-based access decisions in real time.
We reviewed the leading MFA platforms on the authentication methods they support, application coverage breadth, and how well they handle step-up authentication for high-risk access scenarios.
We reviewed 11 security awareness training platforms on content engagement, simulation realism, and behavioral change metrics. The best ones show measurable risk reduction; the weakest ones show completion rates.
We reviewed the leading phishing protection platforms on detection accuracy, response speed, and how well technical controls complement awareness training to reduce overall click-through risk.
We reviewed 10 phishing awareness training platforms on simulation quality, content engagement, and the reporting that tells you which employees remain your highest risk. Click rates alone are not enough.
We reviewed the top business password managers on encryption architecture, admin visibility, and team sharing controls. Our top picks are Dashlane, Keeper, Proton, and NordPass.
We reviewed email security platforms built for MSP environments on tenant isolation, white-label options, and the automation that matters most when you are managing security at scale.
We reviewed 12 email security platforms built for Microsoft 365 environments. The best ones extend native Defender capabilities; the weakest ones duplicate them.
by Craig MacAlpine
We review 11 phishing simulation platforms based on simulation quality, training content, and reporting capabilities.
We reviewed the leading BEC protection solutions on the accuracy of sender impersonation detection, how well each identifies payment redirect fraud, and the speed at which suspicious communications are flagged for human review.
We reviewed the leading email security platforms built for Google Workspace on how effectively they extend native protection, the depth of BEC detection, and how well they handle threats that arrive through legitimate-looking senders.
We reviewed the leading anti-impersonation and spoofing solutions on DMARC enforcement depth, display name spoofing detection, and how well each identifies the lookalike domains that attackers use to conduct convincing phishing campaigns.
IRONSCALES has long been a leader in phishing protection. But recently, it has expanded beyond email into collaboration security, with deepfake meeting protection for Microsoft Teams that detects both face and voice impersonation and general deepfake masking. Microsoft positions M365 and Defender as a strong native security baseline, but both Microsoft and industry analysts recognise...
by Craig MacAlpine
We compared 10 Mimecast alternatives on threat detection accuracy, Microsoft 365 integration, and total cost of ownership. Here’s what we think is worth your time to evaluate.
Are we heading towards a passwordless future, and what would that look like?
A quick look at the very basic fundamentals of cloud computing and the types of cloud environments you’ll find.
The world wide web can be a dangerous place. While not quite the Wild West, end-users still need their wits about them and think carefully about parts of the internet they choose to visit.
by Expert Insights
CrashPlan is a data resilience solution for servers, endpoints, and SaaS applications, including Microsoft 365 and Google Workspace. CrashPlan was initially part of Code42, but in 2022, the company was spun out to Mill Point Capital. In 2024, CrashPlan acquired Parablu, strengthening its backup and recovery capabilities for OneDrive and Azure environments. Although CrashPlan is...