By NHI Mgmt Group Editorial TeamBased on Abnormal AI: “How Choice Hotels Utilizes Innovative Security Solutions to Protect its Email Ecosystem” (June 26, 2026)

TL;DR: Choice Hotels found advanced email attacks bypassing legacy secure email gateways and traditional security tools before moving to behavioural detection, then remediated BEC and vendor email compromise faster and freed security time for proactive work, according to Abnormal AI. The core issue is that legacy email controls still miss behaviour-driven abuse patterns, not just malicious payloads.


At a glance

What this is: This webinar summary says Choice Hotels saw advanced email attacks bypass legacy secure email gateways and traditional tools, then improved remediation of BEC and vendor email compromise after changing approach.

Why it matters: IAM and security teams should note that email compromise increasingly exploits trust, behaviour, and vendor relationships, which makes detection and response more relevant than payload-only filtering.

By the numbers:

  • Choice Hotels protects data for 50 million members, guests, and employees against advanced email attacks.
  • Choice Hotels protects data for 50 million members, guests, and employees against advanced email attacks.

Context

Choice Hotels is a large hospitality organisation with a broad email attack surface, and the article frames the problem around advanced email attacks that were getting past legacy secure email gateways and other traditional security tools. The underlying governance issue is that email security is still often tuned to block known malicious content rather than behavioural abuse and impersonation.

For identity and access teams, that matters because business email compromise and vendor email compromise exploit trust relationships, not just technical vulnerabilities. When attackers use convincing, context-aware messages, the control problem shifts from message inspection alone to detection, verification, and response across identities, mailboxes, and third-party communication paths.


Key questions

Q: Why do secure email gateways miss modern business email compromise?

A: Secure email gateways were built to spot malicious links, attachments, and known spam patterns. Modern BEC often uses plain text, legitimate domains, and business context, so the email appears clean even when the request is fraudulent. The control gap is in context recognition, not message delivery.

Q: How should security teams handle vendor email compromise in enterprise environments?

A: Security teams should treat vendor email compromise as a trust and lifecycle problem, not only a phishing problem. The practical response is to maintain a living inventory of active vendor relationships, tie approvals to behavioural risk signals, and add independent verification for payment or account-change requests that arrive through trusted third-party channels.

Q: What breaks when security teams depend only on email content inspection?

A: Content-only inspection misses the behavioural evidence that usually reveals abuse, such as unusual reply timing, abnormal sender relationships, mailbox rule changes, or a suspicious payment request entering a trusted workflow. Once attackers can write better emails, the safer signal is what happens after delivery.

Q: How can teams tell whether behavioural email detection is working?

A: It is working when suspicious requests are flagged before approval, when impersonation patterns are detected across channels, and when legitimate business processes still move without excessive friction. The best signal is fewer unsafe actions taken on convincing but fraudulent requests.


Background and context

Why legacy secure email gateways miss behaviour-driven attacks

Legacy secure email gateways are strongest when they can score a message against known indicators, malicious attachments, suspicious links, sender reputation, or signature-based detections. Behaviour-driven attacks break that model because the content can be clean while the intent is fraudulent. Business email compromise and vendor impersonation often rely on conversation timing, relationship context, and workflow manipulation, which are hard for static rules to distinguish from legitimate business traffic. That creates a blind spot where the message looks normal but the interaction is not. Practical implication: treat email security as identity-adjacent detection, not only content inspection.

Practical implication: supplement content filtering with controls that evaluate sender behaviour, mailbox context, and abnormal communication patterns.

How BEC and vendor email compromise evade traditional controls

Business email compromise works by abusing trust in the communication chain, while vendor email compromise targets legitimate partner relationships and invoice or payment workflows. Neither attack requires malware if the adversary can convince a person to approve a transfer, reset credentials, or share sensitive information. Traditional tools often lack the contextual signals to spot a conversation that is plausible in isolation but anomalous across time, sender history, and business process. In practice, this is why organisations see message-level defences miss attacks that only reveal themselves when correlated with user behaviour and business context. Practical implication: build controls around trusted relationships, not just inbound email.

Practical implication: correlate email telemetry with identity and workflow context to catch impersonation before approval or data disclosure.

What operational change behavioural detection introduces

Behavioural detection shifts the question from 'Is this message malicious?' to 'Does this interaction behave like normal business communication?' That matters because it lets security teams prioritise suspicious sequences, such as unusual reply chains, first-time sender patterns, or abnormal requests arriving at high-trust moments. The article’s outcome is operational as much as technical: faster remediation and more time for proactive security management. In other words, the control value is not only better blocking, but a lower response burden when attacks do get through. Practical implication: measure detection quality by containment speed and analyst workload, not inbox noise alone.

Practical implication: optimise for faster investigation and remediation, since detection quality should reduce response effort as well as attack volume.


NHI Mgmt Group analysis

Legacy email security is a trust problem, not only a content-filtering problem. The article shows that attacks can bypass SEGs when the message itself is not obviously malicious. That exposes a governance gap: organisations still anchor email defence to payload inspection even though modern abuse is often behavioural and relational. The practical conclusion is that email security now sits closer to identity trust management than simple message hygiene.

Vendor email compromise is a third-party identity problem in disguise. When an attacker impersonates a supplier or partner, the control failure is not just inbox filtering. It is weak verification of external communication identity and insufficient scrutiny of trust-established workflows. For identity programmes, that means third-party communication paths deserve the same lifecycle and assurance thinking as any other privileged access path.

Behavioural detection should be treated as an identity control layer. The article’s real signal is that remediation gets faster when teams can see abnormal patterns across messages, users, and business context. That makes behavioural email defence part of the broader NHI and human identity governance conversation, because the security decision is no longer just whether a message arrived, but whether the interaction is credible.

Security teams are moving from mailbox defence to interaction defence. That shift changes where evidence lives and how incidents are handled. Teams need to think in terms of conversation anomalies, high-risk relationships, and workflow abuse, because the attacker’s objective is often to manipulate a legitimate process rather than defeat a technical control. Practitioners should re-evaluate where trust is assumed inside email-driven business processes.

What this signals

Interaction-level defence is becoming the practical boundary for email security. Teams that keep treating inbox defence as a standalone perimeter will continue to miss the trust abuse embedded in vendor impersonation and BEC. The governance shift is toward verifying the relationship, not just the message.

Email compromise now overlaps with identity assurance. When fraudulent requests arrive through a legitimate channel, the question becomes whether the communication context is credible enough to act on. That pushes email security into the same operational space as human identity, third-party assurance, and workflow control.


For practitioners

  • Map email trust relationships Identify which supplier, payment, and executive communication paths carry the highest business consequence if impersonated. Use those paths to prioritise monitoring and verification workflows rather than treating all inboxes equally.
  • Add behavioural detection to email controls Evaluate whether your current stack can flag unusual sender behaviour, reply chains, first-time contact patterns, and abnormal request timing. If it cannot, legacy filtering will continue to miss business email compromise.
  • Tighten vendor communication verification Require out-of-band verification for changes to payment, banking, or sensitive data requests that arrive through email. That closes the gap exploited by vendor email compromise and similar impersonation attacks.
  • Measure response speed to email abuse Track how quickly analysts can triage, contain, and remediate suspected BEC and impersonation events. Faster handling is the operational signal that detection is working beyond simple inbox filtering.

Key takeaways

  • Legacy email gateways are not designed to catch every malicious conversation, especially when attackers rely on believable context instead of malware.
  • The article’s example shows that behavioural attacks can bypass traditional tools while still creating business email compromise and vendor impersonation risk.
  • Practitioners should focus on identity-aware detection, verification workflows, and faster remediation rather than relying on content filters alone.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP API Security Top 10 addresses the attack surface, NIST CSF 2.0 and CIS Controls v8 set the technical controls, and ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
OWASP API Security Top 10API2 — Broken AuthenticationIdentity spoofing in email abuse exploits weak trust verification, not API auth directly.
Recommendation — Verify external communication identities before allowing sensitive actions or workflow changes.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsEmail abuse often turns trust into unauthorised action across business workflows.
Recommendation — Apply PR.AA-05 to restrict who can trigger sensitive approvals and payment changes from email.
CIS Controls v8CIS-5 — Account ManagementBEC and vendor impersonation exploit account trust and workflow misuse.
Recommendation — Use CIS-5 to tighten account governance around privileged communication paths and approvals.
ISO/IEC 27001:2022A.5.15 — Access controlEmail-driven abuse depends on weak control over who can initiate trusted business actions.
Recommendation — Use A.5.15 to enforce tighter access control over email-linked approval workflows.

Key terms

  • Business email compromise: A form of social engineering where an attacker impersonates a trusted person or domain to manipulate payment, change banking details, or extract sensitive information. It often succeeds without malware because the attacker targets process trust and human judgement instead of technical controls.
  • Vendor Email Compromise: Vendor email compromise is a form of impersonation that targets supplier, contractor, or partner relationships. Attackers exploit routine vendor communication patterns to request payment changes, invoice redirection, or other sensitive actions, so identity and process verification must extend beyond internal users.
  • Behavioral Detection: A monitoring approach that looks for unusual activity rather than relying only on static inventories. For SaaS integrations, it detects drift in token use, data movement, timing, and endpoint behavior so teams can spot compromise, misuse, or automation that no longer matches its expected pattern.
  • Secure Email Gateway: A secure email gateway is a control layer that inspects email before it reaches users and can also inspect outbound mail. It filters malicious content, enforces policy, and reduces exposure to phishing, malware, and data leakage, but it does not replace identity governance or account monitoring.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 27, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org