Email is no longer the only battleground

Phishing remains one of the most persistent threats for organizations, with an estimated 90% of attacks beginning with a phishing email. But attackers have adapted as businesses have adopted a growing number of communication and collaboration tools. Threats like business email compromise (BEC), QR phishing, and account takeovers now span multiple channels — email, Slack, Teams, SMS, and cloud drives — exploiting weaknesses wherever users communicate.

Traditional secure email gateways (SEGs) and email authentication alone are no longer sufficient. Attackers engage employees across a combination of channels, building trust before pivoting targets to less-secure apps and devices. An integrated approach that assesses user risk holistically — before, during, and after message delivery — is needed to address this cross-application threat landscape.

Assessing user risk across the platform

Instead of relying on fragmented tools that create blind spots, a platform approach treats email security as part of a broader strategy for evaluating user-related risk. With visibility into user actions outside of email, security operations center (SOC) teams can identify and respond to a wider range of insider threats, not just phishing attacks. A unified dashboard should provide answers to three key questions:

  1. Who in the organization is being targeted?
  2. Who are the attackers impersonating?
  3. What risky behaviors are users performing?

Identifying targeted users

SOC teams can review which users are most frequently targeted, helping them decide which accounts to harden with measures like enforced MFA and which risky users to monitor for behavioral deviations. For high-risk users, organizations can require connections from managed devices — for example, enforcing a device posture check via Crowdstrike before allowing access to sensitive applications.

Visibility into attack types and frequencies also informs policy adjustments. If email analysis reveals that attackers are frequently leveraging links, SOC teams can use gateway policies to block similar links arriving through other communication methods like LinkedIn, Teams, or Slack, preventing users from interacting with malicious content regardless of the channel.

Tracking impersonation attempts

Dashboards can also reveal which users are being impersonated most often. Frequently impersonated users can be added to an impersonation registry, which increases the sensitivity of detection models to apply greater scrutiny to messages originating from those users.

Domain name registrars offering email security can go further: customers can report lookalike domains for action, preventing attackers from damaging their brand reputation. Free DMARC management tools allow organizations to track who is sending email on their behalf, update SPF records, and move toward p=quarantine or p=reject policies to make spoofing more difficult.

Monitoring risky user behavior

Several mechanisms provide visibility into user actions. Internal message tracking within email security can alert on malicious or suspicious behaviors, with managed services providing additional alerts for potential fraud, account takeover, or insider threats.

CASB solutions display user actions labeled with risk levels so teams know which findings are critical. Data loss prevention (DLP) violation views reveal unauthorized data egress, with automatic blocking policies preventing exfiltration of sensitive data. Placing internal applications behind access controls prevents users with improper permissions or high risk levels from reaching critical resources, with login failure metrics available for further investigation.

These signals feed into a unified risk score that can be exported for automated action within other security platforms.

Improving SOC efficiency

Unifying these capabilities in a single interface backed by one data lake reduces the burden on SOC teams, eliminating the need to build rules or switch between disparate workflows.

AI-driven protection

Predictive AI models replace the rule creation and maintenance required by legacy secure email gateways. Trained on diverse data from across a large network footprint, these models recognize emerging threats earlier and identify new tactics with higher accuracy than reactive measures.

Automated isolation

Browser isolation reduces risk when users visit potentially malicious websites. A clientless remote browser running on a global network allows SOC teams to prohibit behaviors like copy/paste, upload/download, and keyboard inputs within isolated sessions. Policies can be based on content categories derived from constantly updated threat intelligence, so new malicious websites are covered automatically without manual policy updates.

Automated blocking

Websites that require more than isolation can be fully blocked based on category tags. Custom block pages give SOC teams a channel to communicate with users about risky behaviors, raising awareness so users can alter their actions and report suspected attacks.

Upcoming capabilities

Planned enhancements for the coming year deepen the integration of email security with broader SASE platforms, improving insight and protection against user-based threats.

Email Link Isolation currently applies to suspicious links. Future configurations will allow customers to customize policies to meet internal requirements, providing more granular control over which websites users can access from email without isolation.

Outbound email DLP

An upcoming add-in for Microsoft Outlook will extend the DLP engine to outbound email messages. This client-side application will enable downstream policy actions when DLP policies are violated while minimizing disruption to existing email infrastructure.

Expanded user risk scoring

Additional signals will feed into user risk scores, enabling SOC teams to create more policies within the platform or trigger automated external actions based on observed risk levels.

Organizations can currently use Retro Scan, a free tool that applies predictive AI models to scan existing inbox messages. It detects threats and highlights findings for remediation, helping organizations implement controls to prevent similar attacks from reaching inboxes in the future.