NewKnowledge base governance playbook is live
← Back to Field Notes

Cybersecurity

Your Email Security Tool Stopped Yesterday's Attacks. Here's What It's Missing Today.

A product-adjacent thought-leadership piece on why static email security misses novel attacks and what behavior-based detection changes.

June 20, 20264 min readHosted articleIllustrated field note
A security shield blocks obvious email threats while a trusted-looking message reaches a user, illustrating the need for behavioral detection.

The Understory

When the Message Looks Like Business as Usual

Modern email attacks increasingly borrow the language, timing, and relationships of ordinary work. That changes what security has to notice, because the danger may live in the behavior rather than the message itself.

There’s a version of email security that made a lot of sense in 2010.

Attackers were sending malicious attachments, so security tools scanned attachments. Attackers were embedding bad links, so security tools checked links against known-bad lists. Attackers were spoofing domains, so security tools flagged mismatched sender addresses.

It was a long, reactive game of pattern recognition: find a known threat, build a rule, block it.

That reactive approach could only last so long. The problem was that attackers were writing the playbook, and the best security could do was keep up.

A pictogram showing known malicious emails being compared against a static rule gate while an unfamiliar message passes because it has no match.
Reactive security is excellent at recognizing yesterday’s attack. A first-of-kind message has nothing familiar to match.
Note

Section

What modern BEC actually looks like

Business email compromise is one of the most financially damaging forms of cybercrime, precisely because it often does not look like an attack.

There’s no malware. No suspicious attachment. No link to click. In many cases, there’s nothing technically “wrong” with the email at all.

There’s nothing technically “wrong” with the email at all.

It’s just a message, often from what looks like a trusted vendor, a known executive, or a familiar finance contact. It asks for something routine: update a bank account, approve a wire transfer, confirm credentials before an audit. The language is professional. The timing makes sense. The sender’s display name checks out. The signature even has that goofy GIF you’ve seen a million times.

Legacy tools have nothing obvious to scan. No signature to match. No known-bad URL to flag.

And so, the email sails right through.

A clean, professional vendor email passes several technical checks while a subtle anomaly marker highlights an unusual banking request.
A message can pass every conventional check and still be dangerous because the suspicious part is the request, not the payload.
Note

Section

The gap no one talks about

Rule-based detection asks, “Have we seen this before?”

That’s a reasonable question. Human nature finds comfort in routine, and we assume attackers are reusing the same infrastructure, templates, and techniques because that’s what they’ve been doing since time immemorial.

Modern attackers are still doing that ... along with more.

They’ve studied how your organization operates, and they’re crafting attacks that look exactly like business as usual. Your vendors, workflows, org chart, and culture are all useful raw material. In a world where companies eagerly publish their partnerships and accomplishments, those details are not as hard to mimic as we would hope.

First-of-kind attacks, by definition, don’t match any rule you’ve already written.

Even familiar attacks have been iterated. Slightly different sender. Slightly different language. A new domain registered last week. The signature-based tool looks for an exact match it doesn’t find, and the email lands in someone’s inbox.

Note

Section

What behavioral detection is actually doing

Instead of asking, “Is this a known threat?” behavioral AI asks a different question: “Does this look normal?”

Not normal in the abstract. Normal for this sender, this recipient, and this communication pattern. It builds a baseline that purely reactive defenses cannot. How does this vendor typically communicate? What time of day does this executive usually send email? Does this message match the writing style we’ve come to expect from this address? Has this sender ever asked for a wire transfer before?

When something deviates, even if there’s nothing technically malicious about the email, that deviation is the signal.

A pictogram timeline shows a vendor’s normal email pattern followed by one unusual banking-change request highlighted in cyan.
Behavioral detection evaluates the message against the history of the relationship, not merely a global list of known threats.

A vendor you’ve worked with for three years suddenly asks you to update their banking information by email. No link. No attachment. Perfect grammar. The legacy tool sees nothing to flag. The behavioral model sees a vendor who has never done this before, ever, in three years of communication history.

And now we see the gap.

Note

Section

Why this matters right now

Abnormal AI’s 2026 Attack Landscape Report found that 61% of business email compromise was vendor-related, with attackers increasingly impersonating trusted suppliers and partners rather than strangers. The report analyzed nearly 800,000 email attacks across more than 4,600 organizations during the second half of 2025.

Two organizations exchange an ordinary-looking vendor email above a data card stating that 61 percent of BEC is vendor-related.
The trusted relationship is the attack surface. Routine vendor communication provides both the disguise and the leverage.

The attack surface is bigger than your perimeter. Why would attackers need to penetrate it when they can borrow the shape of a relationship your employees already trust? Your inbox is a seldom-locked door, and you don’t even have the key anymore.

The tools built for 2010 are still doing their jobs. They’re stopping the attacks they were designed to stop.

Is that still enough?

More writing

Read more Field Notes

Browse articles on AI, security, workplace communication, change, and systems.

View all articles →