Cybersecurity
Your Email Security Tool Stopped Yesterday's Attacks. Here's What It's Missing Today.
A product-adjacent thought-leadership piece on why static email security misses novel attacks and what behavior-based detection changes.

The Understory
When the Message Looks Like Business as Usual
Modern email attacks increasingly borrow the language, timing, and relationships of ordinary work. That changes what security has to notice, because the danger may live in the behavior rather than the message itself.
There’s a version of email security that made a lot of sense in 2010.
Attackers were sending malicious attachments, so security tools scanned attachments. Attackers were embedding bad links, so security tools checked links against known-bad lists. Attackers were spoofing domains, so security tools flagged mismatched sender addresses.
It was a long, reactive game of pattern recognition: find a known threat, build a rule, block it.
That reactive approach could only last so long. The problem was that attackers were writing the playbook, and the best security could do was keep up.

Section
What modern BEC actually looks like
Business email compromise is one of the most financially damaging forms of cybercrime, precisely because it often does not look like an attack.
There’s no malware. No suspicious attachment. No link to click. In many cases, there’s nothing technically “wrong” with the email at all.
There’s nothing technically “wrong” with the email at all.
It’s just a message, often from what looks like a trusted vendor, a known executive, or a familiar finance contact. It asks for something routine: update a bank account, approve a wire transfer, confirm credentials before an audit. The language is professional. The timing makes sense. The sender’s display name checks out. The signature even has that goofy GIF you’ve seen a million times.
Legacy tools have nothing obvious to scan. No signature to match. No known-bad URL to flag.
And so, the email sails right through.

Section
The gap no one talks about
Rule-based detection asks, “Have we seen this before?”
That’s a reasonable question. Human nature finds comfort in routine, and we assume attackers are reusing the same infrastructure, templates, and techniques because that’s what they’ve been doing since time immemorial.
Modern attackers are still doing that ... along with more.
They’ve studied how your organization operates, and they’re crafting attacks that look exactly like business as usual. Your vendors, workflows, org chart, and culture are all useful raw material. In a world where companies eagerly publish their partnerships and accomplishments, those details are not as hard to mimic as we would hope.
First-of-kind attacks, by definition, don’t match any rule you’ve already written.
Even familiar attacks have been iterated. Slightly different sender. Slightly different language. A new domain registered last week. The signature-based tool looks for an exact match it doesn’t find, and the email lands in someone’s inbox.
Section
What behavioral detection is actually doing
Instead of asking, “Is this a known threat?” behavioral AI asks a different question: “Does this look normal?”
Not normal in the abstract. Normal for this sender, this recipient, and this communication pattern. It builds a baseline that purely reactive defenses cannot. How does this vendor typically communicate? What time of day does this executive usually send email? Does this message match the writing style we’ve come to expect from this address? Has this sender ever asked for a wire transfer before?
When something deviates, even if there’s nothing technically malicious about the email, that deviation is the signal.

A vendor you’ve worked with for three years suddenly asks you to update their banking information by email. No link. No attachment. Perfect grammar. The legacy tool sees nothing to flag. The behavioral model sees a vendor who has never done this before, ever, in three years of communication history.
And now we see the gap.
Section
Why this matters right now
Abnormal AI’s 2026 Attack Landscape Report found that 61% of business email compromise was vendor-related, with attackers increasingly impersonating trusted suppliers and partners rather than strangers. The report analyzed nearly 800,000 email attacks across more than 4,600 organizations during the second half of 2025.

The attack surface is bigger than your perimeter. Why would attackers need to penetrate it when they can borrow the shape of a relationship your employees already trust? Your inbox is a seldom-locked door, and you don’t even have the key anymore.
The tools built for 2010 are still doing their jobs. They’re stopping the attacks they were designed to stop.
Is that still enough?
More writing
Read more Field Notes
Browse articles on AI, security, workplace communication, change, and systems.
