TL;DR: Despite heavy investment in secure email gateways, 94% of organisations still report email security incidents and 87% of cybersecurity leaders are considering replacing SEGs, while advanced phishing attacks bypass detection more often, according to KnowBe4. Static DLP and gateway-centric controls are no longer enough when email risk spans identity, content, and user behaviour.
At a glance
What this is: This whitepaper argues that secure email gateways are no longer sufficient on their own, citing persistent incidents, rising phishing bypass rates, and growing interest in integrated cloud email security.
Why it matters: It matters because email remains an identity-adjacent attack path where human judgment, account compromise, and data leakage meet, so IAM and security teams need controls that cover access, detection, and response together.
By the numbers:
- 94% of organizations still experience email security incidents.
- 87% of cybersecurity leaders are now looking to replace their SEGs with a modern, integrated security stack.
- 47% increase in attacks getting through detection.
👉 Read KnowBe4's whitepaper on whether your SEG should be replaced
Context
Secure email gateways were designed to filter malicious messages, but modern email risk now spans phishing, business email compromise, misdirected sharing, and data loss driven by human error. In practice, that means the control boundary is broader than the gateway, and a pure SEG model leaves gaps across identity, content, and workflow governance.
The article's core claim is that organisations should move toward an integrated cloud email security stack that combines native Microsoft 365 controls with AI-assisted threat detection and outbound protection. For IAM and identity teams, the relevant issue is not just message filtering but how email security intersects with account compromise, permissioned access, and user-driven exfiltration.
Key questions
Q: What breaks when secure email gateways are the main email security control?
A: When SEGs are treated as the main control, organisations often miss identity-based phishing, internal impersonation, and outbound leakage driven by human error. The gateway may still block commodity spam, but it cannot fully govern user action, recipient context, or account compromise. That leaves a gap between message delivery and actual risk reduction.
Q: Why do static DLP rules fail to stop human email mistakes?
A: Static rules are built for known patterns, but misdirected email usually happens when a legitimate user sends valid content to the wrong place. That means the control sees compliant data and a permitted sender, yet still misses the real risk. Human error requires context-aware detection, not just keyword or label matching.
Q: How do security teams know if their email controls are actually overlapping?
A: Look for the same threat categories being claimed by both layers, the same messages being inspected twice, and the same native protections being disabled to keep the SEG functional. If both products depend on the same signals, the stack may be more redundant than defensive.
Q: Should organisations replace a SEG with integrated cloud email security?
A: Replacement makes sense when the organisation needs correlated inbound, outbound, and identity-aware controls that a SEG cannot provide on its own. The decision should be based on coverage gaps, response speed, and how well native platform telemetry can be combined with policy enforcement. If the stack is fragmented, consolidation may improve governance.
Technical breakdown
Why secure email gateways miss modern phishing patterns
Secure email gateways inspect inbound messages and attachments, but they often struggle with socially engineered lures that are well-formed, time-bound, and context aware. Attackers now use domain spoofing, thread hijacking, and payload-free phishing to evade content rules. As detection becomes more dependent on message reputation and static indicators, the control can lag behind attacker tradecraft. The result is not a complete failure of email security, but a narrowing of what the gateway is actually able to see.
Practical implication: teams should test SEG efficacy against current phishing tactics, not legacy spam-style simulations.
Why static DLP fails on human error and email exfiltration
Static data loss prevention relies on fixed patterns, labels, or keyword rules, which makes it brittle when a user sends sensitive data to the wrong recipient or shares content in an unexpected format. In email, exfiltration is often accidental rather than malicious, and that means intent-aware controls matter as much as content inspection. Modern protection needs policy context, recipient awareness, and workflow-level intervention, not only signature matching.
Practical implication: combine outbound policy controls with recipient validation and user friction for high-risk sends.
How integrated cloud email security changes the control model
Integrated cloud email security moves beyond a perimeter gateway by combining native platform telemetry, AI-driven detection, and policy enforcement across inbound and outbound mail. In Microsoft 365 environments, that typically means using platform controls for visibility and quarantine, then layering additional analysis for anomalies, impersonation, and data leakage. The architectural shift is from one choke point to multiple correlated signals, which improves detection depth and response speed.
Practical implication: evaluate whether your current stack can correlate identity, message, and content signals before replacing or extending the SEG.
Threat narrative
Attacker objective: The attacker seeks trusted access to accounts or data paths that email controls fail to restrict at the point of use.
- Entry begins with advanced phishing that bypasses gateway detection and reaches the target inbox through legitimate-looking email flow.
- Escalation follows when the recipient interacts with the message, enabling credential theft, impersonation, or unauthorized sharing from a trusted account.
- Impact occurs through account compromise, data exfiltration, or misdirected email that the perimeter gateway and static DLP did not stop.
NHI Mgmt Group analysis
Email security has become an identity problem as much as a content problem. The article's strongest implication is that message filtering alone cannot govern access, intent, or user action. Email is now a control surface where authentication, impersonation, and recipient trust collide, so practitioners should treat it as part of the broader identity security stack.
Static DLP creates a false sense of control because it assumes the risky event is obvious in advance. Human error rarely follows tidy policy categories, and misdirected email is often a workflow failure rather than a malicious exfiltration event. That means governance must account for recipient context, sharing paths, and policy enforcement at the moment of send.
Security teams are moving from gateway-centric defense to correlated enforcement across the email lifecycle. That shift aligns with NIST Cybersecurity Framework 2.0 thinking because visibility, detection, and response need to work across multiple control points. The named concept here is email control fragmentation: when gateway, native platform, and DLP policies operate independently, attackers and users both find gaps. Practitioners should plan for coordination, not just replacement.
Replacing a SEG is not a binary purchase decision, it is a governance redesign. The real question is whether the organisation can prove coverage against modern phishing, outbound leakage, and identity abuse with its current architecture. If the answer is no, then the programme needs integrated control logic before it can claim resilience.
For IAM leaders, the email stack should be evaluated as an authentication-adjacent trust layer. Compromise often begins in the inbox, but the damage lands in accounts, data movement, and delegated access. Teams should therefore align email security decisions with identity assurance and user-risk workflows, not treat them as separate procurement tracks.
What this signals
Email security programmes are increasingly judged on whether they can correlate message risk with identity risk, not just whether they can block inbound threats. That makes control integration more important than gateway tuning, especially where account compromise and user behaviour drive the real loss path.
Email control fragmentation: when native platform protections, DLP, and SEG policies operate separately, the organisation sees more alerts but less governance. Practitioners should align email policy with identity telemetry, tenant controls, and response workflows so the security model reflects how attacks actually move.
The practical signal for security leaders is simple. If phishing simulations, outbound leakage cases, and impersonation events still reach users, the programme is under-instrumented, not merely underconfigured. That is a governance issue as much as a tooling issue.
For practitioners
- Measure SEG performance against modern phishing scenarios Run simulation campaigns that include thread hijacking, trusted sender impersonation, and payload-free lures. Compare detection outcomes against current attack patterns rather than legacy spam rules, and validate how quickly suspicious mail is quarantined once it enters the tenant.
- Add recipient-aware outbound controls Use recipient validation, approval prompts, and policy exceptions for sensitive messages that leave the organisation. This reduces accidental exfiltration and misdirected mail, which static DLP often misses when the message content itself looks normal.
- Correlate email, identity, and tenant telemetry Connect mail logs, sign-in events, and risky-user signals so a suspicious message can trigger account review or step-up verification. That linkage is especially important in Microsoft 365 environments where native controls can provide visibility but not always complete decisioning.
- Reassess whether your SEG is still the control plane If inbound filtering, outbound DLP, and impersonation protection are managed in separate tools, the organisation may have control fragmentation instead of integrated defence. Document which risk types each layer actually covers before deciding whether to replace or extend the stack.
Key takeaways
- SEG-only strategies no longer match the way modern email attacks are delivered or abused.
- The governance gap is not just inbound phishing, but outbound leakage, impersonation, and human error that gateway rules cannot fully govern.
- Integrated email security should be evaluated as part of identity and tenant risk management, not as a standalone mail filter decision.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5 and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AC-4 | Email impersonation and account abuse hinge on access control and identity verification. |
| NIST SP 800-53 Rev 5 | IA-5 | Authenticator management matters when phishing leads to credential theft or account takeover. |
| MITRE ATT&CK | TA0006 , Credential Access; TA0001 , Initial Access | Phishing bypass and email compromise follow credential access and initial access tactics. |
| CIS Controls v8 | CIS-5 , Account Management | Account compromise from email attacks requires tight account management and monitoring. |
Map email risk decisions to PR.AC-4 and ensure suspicious messages trigger identity-aware response.
Key terms
- Secure Email Gateway: A secure email gateway is a control layer that inspects email before it reaches users and can also inspect outbound mail. It filters malicious content, enforces policy, and reduces exposure to phishing, malware, and data leakage, but it does not replace identity governance or account monitoring.
- Integrated Cloud Email Security: Integrated cloud email security combines native cloud email telemetry, policy enforcement, and advanced threat detection into a broader control model. It is designed to cover phishing, impersonation, and outbound risk across the email lifecycle rather than relying on a single perimeter filter.
- Data Loss Prevention: Data loss prevention is the set of controls used to detect, block, and report sensitive data moving in ways the organisation does not allow. In practice, DLP must account for endpoints, email, cloud apps, APIs, and user behaviour, or it will miss the paths where real exposure happens.
- Email Control Fragmentation: Email control fragmentation occurs when gateway filtering, native platform security, and DLP policies are managed separately without shared decisioning. The result is uneven coverage, duplicated alerts, and gaps between detection and response, especially when phishing and human error intersect.
What's in the full report
KnowBe4's full whitepaper covers the operational detail this post intentionally leaves for the source:
- The vendor's breakdown of why 94% of organisations still see email security incidents despite SEG investment.
- The vendor's assessment framework for deciding when a modern integrated security stack is more appropriate than a gateway-only model.
- The vendor's discussion of Microsoft 365 native controls combined with AI-driven ICES for inbound and outbound protection.
- The vendor's analysis of static DLP limitations in misdirected email and human-error scenarios.
Deepen your knowledge
The NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, machine identity security, and secrets management. It helps practitioners connect identity controls to the broader security programme that depends on them.
Published by the NHIMG editorial team on August 2, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org