Email Security is a core element of every cybersecurity fabric. It helps in protecting against attacks involving emails, such as phishing attacks and attacks using malicious email attachments. There is an ongoing race between attackers and defenders, with the vendors adding more and increasingly sophisticated detection engines for dealing with the vast array of email-based attack vectors. While many email systems come with built-in email security capabilities, heterogeneous environments as well as elevated security requirements may mandate additional solutions.
Martin Kuppinger, Principal Analyst at KuppingerCole, will deliver a deep dive into the evolving email security landscape. He’ll examine architectural shifts, emerging threat vectors, and the technical criteria that matter most when evaluating modern email security solutions. The session will also unpack key findings from the latest Leadership Compass on Email Security, offering a comparative analysis of leading vendors and deployment models to support informed decision-making.
Who Should Attend?
This webinar is ideal for CISOs, IT security leaders, identity architects, and risk management professionals looking to strengthen their organization’s cyber resilience through Identity Threat Detection & Response (ITDR) strategies.
Welcome to our KuppingerCole Analysts webinar, At the Forefront of Cybersecurity, Where Attacks Start. I'm Martin Kuppinger. I'm one of the founders of KuppingerCole Analysts and acting as a principal analyst. And this webinar really has a focus on what we covered in our leadership compass email security, which we published last year, where we look at email security solutions, why we need them, et cetera. I have to admit, when I look at the title now, I would say, okay, maybe it's really not email security anymore when I read all the stuff around this AI agent going rogue.
I already forgot almost the name, but we saw so many LinkedIn messages today and yesterday around that Claude something. Then it might be that we have other attack surface emerging because no one cares about building secure AI solutions, no one cares about secure deployment of AI solutions, and no one cares about governance, obviously.
Otherwise, things like that couldn't happen that way. But still email security and emails are a major challenge we are facing. And so from that perspective, it is a very significant risk and attack surface. So what I'd like to do now is after a little bit of housekeeping, dive a bit deeper into my perspectives on the topic. Feel free to enter questions at any time. There's a questions button at the lower right edge of your screen. We will do a bit of polls. You're muted centrally. We also do a Q&A at the end.
But if there are questions coming in earlier, I always will pick up questions whenever they fit into the flow of the webinar. We are recording the webinar, and we will make a recording and the slide is available sometimes soon in the next couple of days. I'd like to start with one poll before we then go into the topic. The poll is I think you need to read the entire sentence because it's up to you have an email security solution in place. But it's also about that serves your needs. So probably most of you have some built in email security somewhere in place.
It's covering everything or at least one of your major email solutions. But the question is, does it really deliver to what you need? Do you feel this is what really all you need or you're fully served? Or is it that you say, okay, even if I have something in place, there might be some gaps. So the poll remains open for a while. You can respond to the poll earlier or later. And the agenda today is pretty simple. I'll look a bit or share a bit my perspectives on email security, some thoughts that also were central to this leadership compass, but also a bit beyond.
And so I have six themes I'd like to discuss around email security today. The first one is why email security remains so essential in cybersecurity, even while we do every security mistake we can think about. And a lot of mistakes I can't think about around AI as I've already said. So why is it still so essential? Is email built in email security sufficient or do you need more and when? Why are multi-channel capabilities are increasingly becoming the new normal?
Why should you look at this when thinking about email security and maybe moving to a sort of an inbound graphic security, which then also honestly could be, might be not a perfect time because that could happen pretty broad because a web application firewall in some sense is also about inbound traffic, but let's say inbound communication. Which criteria to look at when selecting email security solutions, most relevant players in the market, a bit to look at the results of this leadership compass. And one topic I added, why also must think about transactional email security.
So these are the areas I'd like to touch on the course of this webinar. And the first one is why does email security remain so essential in cyber security? And so it is a preferred type vector. So we have emails for phishing, for credentials, and then the attack follows. This is a very common theme. A lot of this is filtered out, but we still see a lot of phishing emails coming in. So that remains a challenge.
And this is a core of a very, very large portion of today's cyber attacks to send out either very targeted or broadly distributed emails, trying to gain access to certain credentials and use these credentials then for attacks. And these attacks can then be pretty broad and simple, but it also can be very elaborated and very targeted, depending on the type of the attacker and what the attacker is after.
We have also the situation of delivering malware via emails, via attachments, for instance, to write attacks, including the ransomware directly, or to just plant something somewhere which is used by the attacker to perform more sophisticated attacks. And again, emails are a very common way to start these attacks.
And then we have this back-end BEC, business email compromise, where the target is to send out mails that look like legitimate mails, usually to decision-makers, to people that have a certain level of responsibility, and to lead them to take some sort of erroneous actions, ideally paying some money somewhere where it shouldn't flow. So these are three examples of typical attacks. And when we look at the majority of attacks, there are a lot of statistics out there, but it's a matter of fact that there's really a significant share of email involvement in cyberattacks.
And that means we need to look at this. And I had a quite interesting conversation with someone just this week about cyberattacks just this week, about the sort of the awareness, cybersecurity awareness trainings. And that person said, basically, yes, we're doing this for two or three years or so. At the end, the results are still pretty much the same they have been at the beginning of the training. I know also scenarios where it became better. So where people really started to react more conscious.
But what's also very clear is that there are scenarios like peak workload times, take the end of year bookings. If you then target a finance department, the likelihood that someone falls trapped to a malicious email is much higher than in times of sort of regular workloads or during events or whatever else. So email is a critical thing. And we need technology that supports us here, that backs us. And then the interesting question is, are built-in email security solutions.
So all the stuff that comes from your email service provider, be it Microsoft data, Deutsche Telekom, be it whoever else, is this sufficient or do you need more? And that is something which is not so easy to answer because there is not a wrong or a right. But there are certain criteria or aspects you should look at when thinking about this or think about what does it mean for you? So how does this look for you? So the one is clearly, how willing are you to accept a certain level of risk or to avoid risk?
That is something which is, I argue more on the risk-averse side or the other side of things. Generally speaking, I think with the risk around emails, it makes a lot of sense to be really risk-averse, being very reluctant and trying to minimize the risk, also by technology as much as we can. But it differs from organization to organization. A second element, and this is maybe the most important factor to look at, that's the heterogeneity of your environment. So built-in solutions are good for that specific email solution, but they rarely serve a more complex environment.
And it's interesting to see how many different email services are in place in large organizations. It's rarely just one. There's usually some legacy. There might be some email servers, some MTAs, that are used for certain business purposes, like electronic invoicing, stuff like that. There might be good old Lotus Notes stuff around. I still see it every now and then. There might be modern Microsoft 365 and old Microsoft Exchange on-premises. And every other type of mix, there might be really just specific email services within a business application and all that stuff.
So the more heterogeneous the environment is, the more likely you will need more than just the built email security. This is clearly a very important factor here.
And again, a reminder, if you have any questions, don't hesitate asking these questions. And also comments, best move it into the questions section, not into the chat. Lower right edge of the screen, you will find this questions area, because then I will see it. Another aspect here is, what are your capabilities in managing email security? So building email security is a very convenient thing usually, because you don't need to think much about it. And then I think different factors come together. On the one hand, it means when you add something, you need a decision process.
You need to bring two solutions together, build and plus the additional ones, or just use the additional one. You will have more administrative and operational tasks to perform. On the other hand, there are some of the solutions that are where you get a very strong sort of managed services approach, which can also be interesting when you're lacking the internal resources and skills to do it. So other providers might be the ones to help you with a fully managed service, also covering more complex environments, which might be of benefit.
Or you say it's I'm just already overwhelmed by dealing with the built-in security stuff, and I can't handle more of that. Both can happen.
Both are, in that sense, well, it's multi-channel support needs. Some of the other solutions beyond built-in solutions tend to be broader in the multi-channel support. So when you have slack around, et cetera, and stuff like that, that might be the thing you want to look at. And I think we have seen in many areas of cybersecurity now that, for instance, slack is a good means for users to share also stuff that must not be shared, like long living secrets and stuff like that. So that also might be of relevance.
Transactional email security, something I'll touch on in a minute, so shift this a bit back. But if you look at all this, like electronic invoicing, good old edifact, et cetera, then things may look very different when you have business applications that use basically emails to share information, communicate instead of API-based communication, or at least file transfers. And it happens, and it happens not rarely.
Also, your own vendor and platform strategy may play a role. So if you say, I work with some of the providers of a very comprehensive, maybe also broader cybersecurity set of solutions, and there are some, if you can later on look at the list of vendors, then it might be just a strategic choice to say, okay, we do a lot of stuff in cybersecurity. We also do the email security stuff. At the end of the day, it's also clearly a matter of budget.
But that is surely the, and that's why I talk about it at least, alas, this is surely the thing which shouldn't lead to a decision to say, okay, I don't do proper email security, because that then would be very closely related to a risk acceptance. So at the end of the day, cybersecurity costs money, and I think we can, and all the examples of organizations that were hit hard by cyber attacks demonstrated, you can't afford saving on the wrong place. And email security is highly important.
So when we look at this multi-channel thing, not all of this is really related to the typical incoming attacks, but I just want to give you an impression. So Slack data breach at Disney, disrupting threats that, or in this case, more disrupt the functionality of Teams, Zoom workplace vulnerabilities, another Slack one, or that hackers really leverage Teams to drop malware, steal data, things like that. We see a lot of things happening around these other channels.
And some of these channels are really like the, some of these attacks, like the last one I have on that list, are really some that basically use Teams, for instance, or others, as the new type of attack channel. So it is basically another way, aside of email, to use an email, I dare to say still is the most relevant, and it will remain the most relevant, because it's so easy to construct an email address or to just send out a ton of mails with varieties of email addresses, and some will work. So that is so easy that email is just this very simple approach for attackers.
And that means our main emphasis still should be email security, but we must not ignore that attackers always will test whatever is exposed sort of to the outer space, because all of that can be the next attack surface.
So when we look at email security, and this is a little bit smaller font, honestly, sorry, but I think it should be large enough still to read, which criteria to look at when selecting an email security, and there are a lot of criteria we ask for in our leadership compass, but this is a bit of an amalgamation of some of the core areas we looked at when we created this piece of research. So clearly one is identifying, blocking, spam, and other stuff.
We need to potentially classify and control content media that are in violation of policies, we need to identify and block suspicious content, so this is the anti-malware stuff that comes in. Click time protection against malicious links, probably one of the most relevant areas nowadays, because it's very common that there are just links in and when you click on the link, you end somewhere else. And there are situations where you just don't do the mouse over checking, okay, is this really the right domain that is in there, is there anything suspicious, etc.
So this is probably one of the most important things, and some of these phishing mails, in this case mostly, are really, really well constructed. So it's really that you need to look very thoroughly, is this really it or not.
Post-delivery protection, that is also a very important way to say, okay, sometimes I need to deliver something, but if it appears, if I learn later that there are certain types of attacks running, I'm able to remove potentially malicious content, and even after the delivery, it's also very important to look at when you look at the different deployment and implementation models. So where does the email security, so you can sit in this entire chain, does it sit, so to speak, ahead of the inbox, does it sit more on the inbox, makes a huge difference.
CDR, content disarmament reconstruction, is very important to analyze attachments, to potentially even sanitize documents, etc. And we see some interesting trends here, like solutions that for a rapid delivery, then in the first step, deliver sort of the safe part of a mail, and hint on that some elements are still under analysis before they are then finally delivered. So to find a good balance between fast delivery of mails and security.
We could always argue that email is not a real-time synchronous communication, but I think we're a bit used to talking with someone, that person says, oh, I'll send you quickly a mail, with that and that and that, and we expect this to be in our inbox immediately. I think we need to accept also from a security perspective that there's a bit of a gap, at least in delivery, which is always there, surely, but it could also be something which is in a range of some seconds, and a little bit more, maybe, and if we accept this, I think it really helps for security.
Data loss prevention is more on the outgoing side, phishing protection, so by looking at also the social engineering types, and what is strange in this, and is this a, whatever, is this the mail written in the same way, in the same language, etc., as it usually is by the sender, or so. All these things, business email compromise, where it really looks at these things that are targeted at decision makers. Email encryption, also very important.
So, ideally, every email we send out is digitally signed, is encrypted, which is not so easy, because not that many have an SMIME certificate implemented, and SMIME is still, I think there's room for improvement in the way SMIME is handled, but honestly, I think that this is really not easy, and you need a bit of an understanding of how to make it work, and sometimes I wonder why, after decades, we haven't solved it as well. Anyway, eDiscoverer could be important.
Backup archival, also very important, also in a way that ensures that we don't get the malware back after restoring it, and last but not least, clearly, all this monitoring, analytics, forensics, etc. So, we looked at really a broad set of capabilities, and if you have ever read a leadership conversation, you know that there are different perspectives we take, including the spider charts per vendor, where we look at different areas of capabilities, and great vendors on these.
Another element, transactional email security, and this is a thing where we need to understand we have transactional emails, and there are associated risks.
So, these transactional emails are used for data transfers, like in traditional schemes, but not that infrequent for application-to-application communication, and when I look at some of these no-code orchestration things we have around, then sometimes we see, okay, whatever this tool, like our project management tool, issues an email, we use this email, and in our process, in our no-code automation, we then analyze the email to create a task, an outlook, or something like that, and then we basically do something which is a bit API-based, but which is also a bit email-based, and so there's an attack surface.
Just take electronic invoicing.
Yes, there's an attack surface, those things come in, and just believing that no one will send an email to invoice that company name is probably not secure enough, but we also need to ensure that these things, when they are really used by relevant business applications that need a certain availability, that these are working well, that they are not, whatever, from some sort of a denial of service attack, and then we also have this transactional integrity risk, so we must ensure that such emails, if they are used, and some of these scenarios are there and are here to stay, and some of them are really just horribly legacy but you don't have any chance to get rid of them, then you also need to ensure that the delivery of the emails is really reliable, because otherwise, we will suffer potentially in the business process.
This is one of the areas which is, by the way, rarely covered by the common email security solution, so that might be an area where you say, okay, just because of that, I need a separate solution for certain aspects, and what we also could look at is clearly things like deployment models, so do you want to have it in the cloud, or do you need at least partially on-premises, depending on also what you have in email systems around. Then players in the market, so which players are most relevant, and I think this list already indicates that it's not a 100% complete list.
This list just looks at which vendors do we have in the rating, and which vendors do we have on the vendors to watch list, so we had 16 vendors in the rating, not 14 vendors in the rating, sorry, and a list of about 30 plus vendors on the vendors to watch list. We could add some like data 443 and others as well here, so it's really a market with quite a number of players, so we always try to have as many as we can in our rating.
Sometimes vendors, for instance, after acquisitions, refrain from participating, but I think we have truly covered most of the leading vendors in this market, and what also was a result of that is that we see that the market overall is relatively mature, so the vendors, when we look at this overall leadership chart, are leaders or they are in the better part of the challenger section, which means basically you could say all of these deliver a valuable solution, a sufficiently mature solution, to cover email security needs.
Not everyone is a perfect fit for every need, very clearly, but all of these solutions have a rightful place in the market, so that is one of the things here. It's not very surprising that companies like Roofpoint, Cisco, Microsoft, Checkpoint, or Trellix are leading when we look at the overall leadership, which is an allegation of product capabilities, of innovativeness, and of the market position.
We also have these perspectives on product leadership, where we see that really a lot of these solutions are, I think all solutions are really solid, many, many of them are already, so to speak, rock solid, making it into the leader space, still leaving some room for improvement for everyone, so there's still some white space above the top vendors, but I would dare to say we have a rather mature market with quite a good selection of vendors, again with some standing a bit out from the breadth and depth of their capabilities, but really many powerful solutions here.
The same holds true for innovativeness, so we see still quite some innovation, so every time when I speak with the vendors, they come up with new engines for covering new types of attacks, adding features, etc., and I think this makes us, this demonstrates also that it's a continuous race between the attackers and the defenders that triggers the innovation in this market segment.
Again, we see that the vendors all deliver a really good degree of innovation, so when you look at these vendors, the one thing I always bring up is, I think there's a slight tendency to say, okay, who's the upper right edge, that's probably who I should look for.
I think I just can recommend go deeper, I think there's a reason why a leadership compass of Google Analysts is usually some 50, 60, or 80 pages, or even longer, providing a lot of detail, providing a lot of insight, and providing different perspectives on vendors, looking at the strengths and challenges, providing the spider charts, which don't say, okay, this one is maybe the best in archiving this one, or it's really strong in that area, because what you, at the end of the day, need is some solution, one or multiple solutions that really serve your needs.
So, the first thing is really to understand what you need, also at your end, not only from which vendors, and never start with the tool first. Start with, what do I need in security? How does my architecture look like? Which email services do I have? How can I manage these perfectly well? Where do I have which level of risk, et cetera? Then you can go further into the enterprise and the market analysis, talk with vendors, run a POC, and finally make a management decision. But I strongly recommend doing POCs.
I strongly recommend when you, so usually you send out, after you've moved from a long list to a short list, you usually send out an RFI, an RFP, so a request for information or proposal. You then have presentations by the vendors. I strongly recommend that these presentations are done by the vendor plus their service provider.
So, if they don't provide a service themselves, they usually have a partner. Work with both, because the service provider, the integrator, will be the one you spend way more time with than with the vendor itself.
So, you need to understand both. Do a proof of concept, probably because this is, and focus this proof of concept on some critical aspects, some challenging, interesting, and relevant aspects. Not everything. It's not a pilot. It's not a deployment. It's a proof of concept.
So, it should be very focused. Before you're done, can make your decision.
So, and look at what you're lacking. This is the starting point. What does it mean? What do you need to improve? What are your expectations? And then you can come to the requirements.
So, to the RFI, RFP, you also need to understand what the starting point is. Why did you start this project? There must be a reason. And will this, not solving this, become a problem? And what is the cause of that? And then you understand which type of solution you need. Then you can go into specific requirements. It's always think about the future as well.
So, what do you need today? What may you need in the future? And this is really an area where we can help.
So, we are doing research on identity and cybersecurity for decades. We have a lot of contacts within the market. And we are a neutral advisor.
So, if you ever need support, don't hesitate asking us. And that's what I wanted to share with you around email security. If you have questions, it's the right time now to enter your questions into the Q&A section. In the meanwhile, I'd like to bring up the second poll.
And so, I touched on some advanced requirements, multi-channel support, transaction email security, heterogeneous support, support for multiple different types of email services, et cetera. So, when you look at your current email security solution, does it support these advanced requirements you see or you expect that may become relevant for your organization? Does it serve them only partially? Or do you say, do you know? Or do you just say, I have no clue. I don't know what it can do and whatnot. We leave the poll open for a bit so that you can look at the poll.
And in the meanwhile, I'd like to invite you to take a look at the poll. And in the meanwhile, I would love to start the Q&A, but there are no questions yet.
So, don't be shy, but bring up your questions now so that we have something to discuss. For the first poll, it was a very split result, by the way.
So, interestingly, no one said that the current solution fully supports all... Oh, no, this was the wrong... I looked at the wrong one.
So, for the first one, I think you were quite positive in saying your current email solution serves the need. For the second one, I still wait a bit until you have maybe completed the poll because there are not that many results yet.
So, again, if there are any questions, it would be the time now to enter these questions, to bring them into discussion. We have a lot of research around email security and cybersecurity and identity overall.
So, don't miss looking at our Google Research. We have subscriptions which give you access to all the research and other types of services. Have a look at this. Very easy to spot at our website. Help like our bias compasses, our leadership compass, and other themes. We will run our European Identity and Cloud Conference again from May 19th to 22nd in Berlin, which is a conference around digital identity, security, privacy, governance, et cetera.
So, a lot of this is identity-related. Some of this is cloud, especially.
So, rain cloud-related. A lot around UDI and other upcoming evolutions. But we also will tackle some of the cybersecurity stuff there.
So, it's definitely the place to be in these areas. And last but not least, I touched already, we have a variety of services, research and webinars and advisory.
So, it looks like you don't have any questions. Feel free to reach out to me afterwards. And that means, for me, thank you to you for listening to this webinar.
The link, I believe, will lead you to my LinkedIn account. Otherwise, I'm very easy to find on LinkedIn.
So, if you have any questions, don't hesitate to ask them. Otherwise, enjoy the rest of your day. Bye.
See All Locations
See All Locations