Cloud-Native Email Security Gets a New Category: ICES

Email security has shifted decisively from on-premises gateways to cloud-native architectures, and the threat landscape has shifted with it. Gartner's 2021 Market Guide for Email Security (ID G00735200) reflects this change by introducing a new category for the first time: Integrated Cloud Email Security (ICES).

Two trends carried over from the 2020 guide: cloud adoption continues to grow, and phishing, ransomware, and account takeover attacks continue to rise. Gartner estimates that 70% of organizations now use cloud email suites, primarily Microsoft 365 and Google Workspace. Despite built-in hygiene and protection from these providers, email remains a significant attack vector, with phishing, ransomware, and Business Email Compromise causing substantial financial losses. Gartner warns that "Continued increases in the volume and success of phishing attacks and migration to cloud email require a reevaluation of email security controls and processes."

What ICES Solutions Offer Over Traditional SEGs

Gartner positions ICES as the predominant defense against phishing threats that slip past traditional security controls. While vendor capabilities vary, ICES offers three main advantages over legacy Secure Email Gateways (SEGs): advanced threat detection, ease of use, and improved visibility and response. Area 1 Security is named as a Representative Vendor in this new category.

Advanced Threat Detection

Sophisticated phishing attacks often avoid standard detection by omitting links or attachments entirely, relying on social engineering to trick victims into transferring funds or sharing credentials. Other attacks hide malicious links or weaponized documents behind layers of benign content. Gartner notes that as Microsoft and Google's built-in security improves, threat actors are responding with fake login pages to harvest credentials, and that "many ransomware-as-a-service gangs use email as the initial entry point." To address these challenges, ICES solutions employ advanced techniques including natural language understanding (NLU), natural language processing (NLP), social graph analysis of communication patterns, and image recognition.

Ease of Deployment and Visibility

With most organizations running on cloud email providers, API-based integration offers flexibility and faster time to value compared to legacy gateway deployments. Gartner predicts the number of anti-phishing solutions delivered via API integration with email platforms will increase more than 4x by 2025. These same API integrations also enable easy export of email events into SIEM or SOAR platforms, allowing broader threat visibility and coordinated response. Many ICES solutions also offer built-in response or managed services.

The Traditional SEG Is Losing Ground

Hardware-based and hosted-hypervisor SEGs are struggling to keep pace with cloud-native threats. Many organizations with existing SEGs look to ICES to close the gap left by missed threats. Gartner observes that "increasingly the combination of the cloud email providers' native capabilities and an ICES is replacing the traditional SEG." The firm predicts that by 2023, nearly half (40%) of organizations will rely on built-in cloud email protections plus an ICES rather than a SEG — an increase of nearly 150%.

Tip of the ICEberg for Cloud-Native Email Security: Area 1 Named in the Gartner™ Market Guide for Email Security

Area 1 Horizon as an ICES

Area 1 Horizon uses the advanced detection techniques Gartner cites — NLU, NLP, social graph analysis, and image recognition — to preemptively stop threats. Unlike many ICES vendors that offer API-only integration, Area 1 can be deployed via API or inline as the MX record holder, covering pre-delivery, at-delivery, and post-delivery protection. Its deployment options and direct integration are designed for easy evaluation and rapid business value.

BLOG-1442 Embedded Image - W928r7

For response capabilities, the platform includes built-in message retraction and integrates with SIEMs and SOARs for a cohesive extended detection and response (XDR) strategy. Gartner's Market Guide includes a short list of recommended vendor criteria, which Area 1 states it maps to completely:

BLOG-1442 Embedded Image - NKJgQV

Beyond that, Area 1 supports 16 of the 19 key features Gartner lists for all email security vendors.

BLOG-1442 Embedded Image - fV39nS

This positions Area 1 to provide seamless deep integration with Microsoft 365 and Google Workspace for a modern, cloud-first architecture, while still interoperating with existing SEGs for organizations not ready to make the full switch.

Gartner, "Market Guide for Email Security," Mark Harris, Peter Firstbrook, Ravisha Chugh, Mario de Boer, 7 October 2021. Gartner does not endorse any vendor, product, or service depicted in its research publications.