By NHI Mgmt Group Editorial TeamBased on Abnormal AI: “Vision 2023: Looking Ahead at 2023 Cyber Threats” (June 26, 2026)

TL;DR: Email remains a high-risk attack channel, and Abnormal AI’s Vision 2023 conference focused on how cybercrime and cybersecurity are changing through sessions on CISO concerns, business email compromise, and Microsoft 365 protection, with on-demand access and up to 7 ISC2 CPE credits. The core takeaway is that email governance still depends on identity controls, because attacker success often begins where authentication, trust, and user behaviour intersect.


At a glance

What this is: Abnormal AI’s Vision 2023 content frames email as an enduring attack surface, with sessions focused on CISO concerns, business email compromise, and Microsoft 365 protection.

Why it matters: It matters because business email compromise sits at the boundary of human identity, mailbox trust, and governance, so IAM and security teams cannot treat email abuse as only a messaging issue.


Context

Email security is not just a mail gateway problem. When attackers abuse trusted communication channels, they are really exploiting identity, user expectations, and access decisions around the mailbox and the services it connects to.

This conference content treats business email compromise as a current operational risk, not a theoretical one. That framing matters for organisations that still separate email controls from broader IAM and governance work.

The underlying issue is that email remains easy to social-engineer, easy to impersonate, and deeply embedded in approval and payment workflows. That makes it a standing control concern for both security and identity programmes.


Key questions

Q: How should security teams reduce business email compromise risk beyond secure email gateways?

A: They should add controls that operate after delivery and after user interaction, because BEC usually succeeds by exploiting trust and workflow, not by delivering obvious malware. That means mailbox monitoring, identity-aware verification for financial requests, and escalation paths that do not depend on a single email being trusted. The strongest programmes treat email as an identity and process problem, not just a filtering problem.

Q: Why does email still create identity risk even with strong security tools?

A: Because the attacker often does not need to defeat the toolset if they can exploit trust in the sender or the workflow. Email combines human judgment, account access, and business authority, so a single compromised mailbox can influence decisions across the organisation.

Q: What are the signs that email trust controls are failing?

A: Repeated replies to suspicious requests, high forward rates, weak reporting discipline, and inconsistent escalation around vendor changes are all warning signs. If analysts see lots of noise but few confirmed reports, attackers may be succeeding because the organisation is not distinguishing routine messages from risky ones quickly enough.

Q: How should security teams balance awareness training and process controls for BEC?

A: Use awareness training to reduce mistakes, but rely on process controls to stop the loss path. The practical answer is layered verification, segregation of duties, and callback rules for high-risk requests, because trained users can still be bypassed when attackers exploit urgency and fear.


Background and context

Why business email compromise keeps working

Business email compromise succeeds because email is a trust transport, not a strongly bound identity control. Attackers do not need to defeat every security layer if they can impersonate a sender, hijack an account, or manipulate a recipient into acting outside normal verification paths. Once the mailbox is trusted, the attacker can steer conversations, redirect payments, or request sensitive changes. The governance gap is not just detection, but the assumption that a familiar mailbox name equals a legitimate request. Practical implication: treat email-origin trust as a control surface, not a courtesy signal.

Practical implication: build verification steps around high-risk email-driven actions instead of relying on sender familiarity.

Microsoft 365 protection depends on identity controls

Protecting Microsoft 365 against BEC is partly an identity problem because the platform concentrates authentication, collaboration, and downstream business process access in one environment. If an account is compromised, the attacker can move from inbox access to file sharing, message forwarding, and persistence mechanisms that keep the intrusion useful. Technical controls only reduce risk when they are paired with strong authentication, conditional access, and mailbox abuse monitoring. Practical implication: align Microsoft 365 protection with the same identity governance used for other high-value enterprise systems.

Practical implication: review conditional access, MFA strength, and mailbox persistence settings as part of the same control set.

CISO concern is shifting from delivery to trust

The article’s CISO framing reflects a broader shift in email defence. The question is no longer only whether malicious messages are delivered, but whether users and workflows can distinguish legitimate business intent from impersonation. That changes the security model from blocking bad mail to protecting the decision point at the point of action. In practice, that means identity assurance, user verification, and process controls become part of email security architecture. Practical implication: measure whether business-critical email actions still depend on unauthenticated trust.

Practical implication: assess where business processes still rely on unauthenticated email trust.


NHI Mgmt Group analysis

Email compromise is an identity failure before it is a messaging failure. Business email compromise works because organisations still let mailbox trust stand in for request trust. The real weakness is not the transport layer alone, but the gap between who can send a message and who can legitimately initiate a business action. Practitioners should treat this as a governance problem spanning authentication, verification, and process design.

Mailbox compromise creates a privileged communication channel, not just an inbox issue. Once an attacker can read, reply, and forward from a trusted account, they inherit the social authority of that identity across finance, HR, and executive workflows. That is why BEC often bypasses technical detection until money or data has already moved. The control lesson is that identity assurance has to extend to the action triggered by the message.

Vision-style awareness sessions only help if they change operational checks. Conference content is useful when it pushes teams to re-evaluate how business email requests are validated, not when it simply raises awareness. Email governance still too often sits outside IAM and PAM decision-making, even though it influences access changes, payment approvals, and user trust. Practitioners should collapse that separation.

Human trust remains the easiest path into enterprise identity processes. BEC persists because people are still asked to make high-impact decisions based on lightly verified communication. That makes email a human identity control problem as much as a cyber threat problem. The implication is clear: security teams need shared ownership between IAM, messaging security, and business process control.

What this signals

Email security is really workflow security: if a message can authorise a payment, an access change, or a sensitive disclosure without second-factor verification at the business process level, the organisation has left identity assurance incomplete.

The practical shift is from filtering malicious mail to governing the actions that email can trigger. That requires IAM, messaging security, and fraud prevention teams to share ownership of the same risk path.

Enterprise email controls should be judged by whether they interrupt impersonation at the decision point, not by inbox volume alone.


For practitioners

  • Harden business email verification points Require out-of-band confirmation for payment changes, banking updates, executive requests, and other high-impact actions that arrive by email.
  • Align Microsoft 365 controls with identity governance Review mailbox access, forwarding rules, MFA strength, conditional access, and privileged admin paths together rather than as separate programmes.
  • Map email-driven workflows to fraud exposure Identify where email initiates spend, account changes, or data release, then add step-up checks for those workflows.
  • Train staff on sender trust failure modes Focus awareness on impersonation, look-alike domains, reply-chain abuse, and timing pressure rather than generic phishing slogans.

Key takeaways

  • Business email compromise remains effective because it exploits trust in identity and workflow, not just weaknesses in mail filtering.
  • The highest-risk email use cases are the ones that can trigger money movement, access changes, or sensitive data release.
  • Security teams need verification, identity assurance, and workflow controls around email-driven actions, not awareness alone.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK addresses the attack and risk surface, while NIST SP 800-63, NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST SP 800-63SP 800-63B — AuthenticationEmail compromise often succeeds by weakening authentication and trust in sender identity.
Recommendation — Strengthen authentication and verification before allowing email-triggered business actions.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsBEC is often amplified when email access translates into downstream business authority.
Recommendation — Review whether email access can still trigger high-risk entitlements or approvals.
CIS Controls v8CIS-5 — Account ManagementMailbox and admin account governance is central to preventing abuse of trusted email identities.
Recommendation — Audit account ownership, forwarding, and privileged mailbox access for misuse.
MITRE ATT&CKTA0006;TA0009 — Credential Access; CollectionBEC commonly involves account compromise followed by collection of messages and business context.
Recommendation — Map suspected BEC activity to credential access and collection techniques in detection content.

Key terms

  • Business email compromise: A form of social engineering where an attacker impersonates a trusted person or domain to manipulate payment, change banking details, or extract sensitive information. It often succeeds without malware because the attacker targets process trust and human judgement instead of technical controls.
  • Mailbox Trust: The implicit confidence users place in a recognised email account, display name, or conversation thread. In security terms, it is a fragile control assumption that attackers can exploit by impersonation, account takeover, or reply-chain abuse to create believable requests.
  • Out-Of-Band Verification: A confirmation step that uses a different channel or method than the original request. It reduces the chance that a single spoofed email, voice call, or video session can authorize privileged activity or financial transfer.
  • Email-Driven Workflow: A business process in which email can initiate, approve, or accelerate an action such as payment, account change, or document release. These workflows are high risk when the email itself is treated as proof of authority rather than one signal in a broader verification process.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 27, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org