Organizations should prioritize prevention first when attackers are using convincing lures, compromised accounts, or AI-generated messages that are difficult for employees to spot. Training still matters, but it cannot reliably stop a well-crafted fraud attempt once it reaches the inbox. Blocking malicious mail earlier reduces exposure, limits human decision fatigue, and protects against high-impact financial loss.
Why prevention has to win the first move
Blocking malicious email first is the right priority when the attack arrives through a channel that staff are expected to trust. security awareness still has value, but it is a slower, probabilistic control. If the message is convincing enough to survive inbox delivery, the organisation has already shifted the problem onto the recipient, which is a weaker and less consistent control point.
That is especially true when the lure uses a compromised sender, a familiar vendor relationship, or a polished AI-generated message. Those conditions reduce the chance that a person will reliably spot the fraud in time, while even a brief exposure can be enough to trigger credential theft, payment diversion, or malicious link clicks.
When email is the delivery path, the security goal is to stop the highest-risk messages before they create human decision fatigue. That means looking at the quality of filtering, impersonation controls, attachment detonation, URL inspection, and spoofing resistance as primary controls, not optional helpers after training.
One useful data point from NHI Mgmt Group’s Ultimate Guide to Non-Human Identities is that 79% of organisations have experienced secrets leaks, and 77% of those incidents caused tangible damage. That is a reminder that a single successful lure can create real loss well before any awareness lesson has a chance to help.
Where awareness still matters, and where it does not
Awareness training is most valuable when it shapes reporting behaviour, slows down impulse-driven actions, and reinforces a habit of verifying unusual requests through a separate channel. It is not reliable as the last line of defence against a well-crafted message that mimics a normal workflow, especially when the attacker already understands the organisation’s language, suppliers, or internal process patterns.
The practical mistake is treating training as a substitute for prevention. If users are repeatedly asked to make high-stakes judgement calls on messages that should have been stopped upstream, the organisation is depending on perfect behaviour under time pressure. That is not a sound operating model for fraud defence or business email compromise.
Blocking controls should be tuned to the actual attack path the organisation sees, including lookalike domains, reply-chain abuse, compromised accounts, and malicious link redirection. Training then becomes a supporting layer that improves suspicion, escalation, and resilience when something unusual reaches the inbox anyway.
- Prioritise controls that reduce exposure before delivery.
- Use training to improve reporting and verification, not to absorb the full burden of defence.
- Measure whether suspicious mail is being stopped early enough to prevent user interaction.
Risk and Threat Considerations
Email-delivered fraud is dangerous because it exploits a trusted business channel and asks a person to make a split-second judgement under ambiguity. The risk rises when the attacker has a compromised account, a realistic brand impersonation, or AI-generated language that matches the tone of a real workflow.
Failure mechanism: The malicious message reaches the inbox, the recipient recognises it too late or not at all, and the attacker converts that brief exposure into credential theft, payment fraud, or mailbox abuse.
Impact: Even one missed message can create financial loss, account takeover, internal impersonation, or a broader compromise path if the attacker uses the mailbox to stage follow-on fraud.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK address the attack and risk surface, while CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| CIS Controls v8 | CIS 9 — Email and Web Browser Protections | Email blocking and filtering directly reduce malicious-message exposure. |
| CIS 14 — Security Awareness and Skills Training | Training remains a supporting control for reporting and verification behavior. | |
| Recommendation — Harden email and web filtering to block malicious messages before users can act on them. Use awareness training to reinforce reporting and verification, not as the primary fraud stop. | ||
| NIST CSF 2.0 | PR.PT — Protective Technology | Mail filtering, spoofing defenses, and URL controls are protective technologies for this attack path. |
| PR.AT — Awareness and Training | Training supports user judgment when prevention does not catch every lure. | |
| DE.CM — Continuous Monitoring | Monitoring mail flow and phishing indicators helps validate whether blocking is effective. | |
| Recommendation — Deploy protective technologies that block suspicious email before it reaches the inbox. Train users to verify high-risk requests and report suspicious messages promptly. Monitor email security telemetry to confirm malicious mail is being detected and contained. | ||
| MITRE ATT&CK | T1566 — Phishing | The question concerns a common email-borne attack path and its prevention. |
| Recommendation — Map observed email-borne fraud attempts to phishing techniques and tune blocking accordingly. | ||
Practitioner Guidance
What to prioritise: Put your first effort into the controls that reduce inbox exposure, because they lower the number of human decisions you are asking staff to get right. If a campaign is already landing in user mailboxes, training alone is not an adequate control boundary.
What to verify: Check whether your mail security stack is actually stopping spoofing, lookalike domains, malicious links, and high-confidence impersonation before delivery. If those signals are still reaching users, the awareness programme is being asked to compensate for a control gap it cannot close.
Practitioner takeaway: Awareness is the backup layer, but prevention is the control that buys time, reduces fatigue, and keeps employees from having to detect fraud that the platform should have blocked first.
Related resources from NHI Mgmt Group
- How should organisations reduce business email compromise risk without relying only on awareness training?
- What do organisations get wrong about email security awareness training?
- How should security teams prevent business email compromise in finance workflows without relying on awareness training alone?
- What should organisations check before relying on a managed training platform for custom AI models?