By NHI Mgmt Group Editorial TeamBased on Abnormal AI: “Bucking Tradition: How Florida Crystals Ditched the SEG to Improve Email Security” (June 26, 2026)

TL;DR: Florida Crystals said advanced email attacks were slipping past its existing defenses, and that replacing its SEG with Abnormal reduced email security costs by 40% while stopping a BEC attack during the proof of value, according to Abnormal AI. The lesson is that email controls must be judged on attack interception and operational fit, not on whether they preserve legacy architecture.


At a glance

What this is: This is a webinar-based case study showing how Florida Crystals replaced a traditional SEG after advanced email attacks kept bypassing its existing defenses.

Why it matters: It matters because email security decisions now sit at the intersection of identity abuse, BEC defence, and operational productivity, so IAM and security teams need to assess controls by interception value, not heritage.


Context

Florida Crystals is presented as a customer case study about email security modernisation, not as a product comparison exercise. The core issue is familiar to security teams: a legacy SEG can create an appearance of coverage while advanced phishing and business email compromise still reach users.

For IAM and security programmes, the important question is not whether a mail security stack preserves old architecture, but whether it changes attacker success rates and reduces analyst workload. That makes this a governance and control-effectiveness story, with clear implications for email identity protection and adjacent human identity controls.


Key questions

Q: What breaks when a legacy SEG misses advanced email attacks?

A: The main failure is that perimeter filtering can look intact while identity-driven attacks still reach users. When phishing, impersonation, or BEC bypass the SEG, the control is no longer measuring what matters. Security teams should treat that as a detection and governance gap, not a mail-routing problem.

Q: Why does BEC create risk even when email security is already deployed?

A: BEC works by manipulating trust and human decision-making, not by relying on malware delivery. A deployed email control can still miss the attack if it focuses on content signatures rather than sender behaviour, mailbox context, and business workflow abuse. The risk persists until the programme measures interruption of fraudulent action.

Q: What are the signs that an organisation’s email security controls are not working well enough?

A: Common warning signs include repeated phishing attempts reaching users, unexpected logins, weak or reused passwords, unreviewed mailbox settings, and employees opening files from unknown sources. If sensitive messages are being sent without encryption or if attackers can imitate trusted contacts easily, the email environment is not being governed tightly enough. These are control gaps, not isolated user mistakes.

Q: How should teams evaluate legacy email security versus newer detection approaches?

A: Use a scenario-based test that compares whether each control can stop a realistic impersonation or BEC path before business action occurs. The better control is the one that reduces attack success and analyst workload together. Architecture preservation by itself is not a valid selection criterion.


Background and context

Why legacy SEG coverage breaks down against advanced email attacks

A secure email gateway filters mail at the perimeter, but modern attacks often use identity-aware tactics rather than obvious malware. Business email compromise, impersonation, and payload-free social engineering can pass through traditional content inspection because the message looks normal even when the sender intent is malicious. In practice, the defender is trying to detect behavioural abuse, not just malicious attachments or links. That creates a gap between legacy email architecture and the way modern attackers operate across human identity workflows, mailbox access, and trusted communication paths.

Practical implication: evaluate email controls on their ability to detect identity-driven abuse, not only malware and static indicators.

What an active BEC interruption shows about control effectiveness

Stopping a BEC attack during a proof of value matters because it tests detection and response against a live social-engineering path, not a lab scenario. BEC is fundamentally an identity abuse problem: the attacker impersonates a trusted party, manipulates a human decision, and tries to move money or information through legitimate workflows. When a control catches that path in motion, it indicates the security stack is seeing behavioural signals that a SEG may miss. That shifts the measurement question from 'did mail arrive?' to 'did the system interrupt fraudulent intent before business action occurred?'.

Practical implication: use live attack interruption as a validation point for email security controls before treating them as fit for production.

Why productivity belongs in the control decision

Email security tools consume human attention when they produce false positives, manual triage, or exception handling. A stack that improves detection but burdens the security team can still be operationally weak if it shifts too much work into review queues. The governance issue is control efficiency: the right design reduces attack exposure while keeping analyst effort proportional to risk. For programmes that span email, IAM, and user behaviour, productivity is not a soft metric. It is evidence of whether the operating model can sustain the control over time without creating shadow processes or alert fatigue.

Practical implication: measure email security by both attack reduction and the analyst effort required to keep the control running.


NHI Mgmt Group analysis

Legacy SEG replacement is now an identity governance decision, not just an email security refresh. When attackers bypass perimeter filtering through impersonation and BEC, the control question shifts to how effectively the mail stack protects human decision points. That makes email security part of the broader identity programme, because the failure mode is abuse of trust, not simple message delivery. Practitioners should judge the stack by whether it changes the likelihood of fraudulent action.

Security effectiveness must be measured at the point of business interruption. Catching a live BEC attempt during a proof of value is more meaningful than counting blocked messages, because it demonstrates interruption before user action. That is the unit that matters for finance-facing and executive-targeted email risk. The practitioner takeaway is to align mail security evaluation with workflow protection, not with legacy filtering metrics.

Email trust debt: legacy controls can accumulate a hidden gap between apparent coverage and actual interception, especially when attackers use socially engineered, payload-light messages. The SEG may still function as designed while the threat has already moved to identity manipulation and mailbox trust. In that environment, the decisive question is whether the programme has visibility into behavioural abuse across human identity paths. Practitioners should treat email trust as a governed control surface, not a static inbox filter.

Productivity is part of security architecture when controls depend on human review. If the team spends too much time triaging false positives or exceptions, the control degrades operationally even when it looks effective on paper. That is why workflow load belongs in the same conversation as detection performance. Practitioners should assess whether the security operating model can sustain the chosen email control at scale.

What this signals

Email trust debt: organisations often retain a control that appears to cover the inbox while attackers have already shifted to identity manipulation and approval fraud. The real test is whether the programme can interrupt a fraudulent business action before the message becomes a decision.

For teams responsible for both IAM and email security, this is a reminder that the most valuable telemetry is not message volume but workflow disruption. If the stack cannot show that it stopped a live impersonation path, the control is probably optimised for reporting rather than risk reduction.


For practitioners

  • Measure BEC interruption, not just block counts Track whether the email control stops fraudulent approval paths before a user replies, forwards money, or changes account details. Use live attack simulation and proof-of-value outcomes as the primary success metric, not perimeter filtering volume.
  • Map email security to identity abuse patterns Review how impersonation, mailbox trust abuse, and executive fraud pass through your current email stack. Tie findings to the user workflows most likely to be targeted, especially finance, HR, and leadership chains.
  • Reduce manual triage load Identify where the current stack creates repetitive investigation work, exception handling, or alert fatigue. Rebalance the control set so analysts spend time on verified abuse rather than routine inbox noise.
  • Validate controls against live social engineering Test whether the email control can interrupt a realistic BEC path, including trusted sender impersonation and reply-chain manipulation. If it only performs in static phishing tests, it is not yet proving operational fit.

Key takeaways

  • Florida Crystals' case shows that a legacy SEG can remain operational while advanced email attacks still slip through to users and workflows.
  • The proof-of-value interruption of an active BEC attack is stronger evidence of control effectiveness than message filtering alone.
  • Email security decisions should be based on attack interruption, workflow protection, and analyst load, not on whether a legacy architecture is preserved.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP ASVS, NIST SP 800-53 Rev 5, NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP ASVSV16 — Security Logging and Error HandlingEmail attack interruption depends on visibility into abuse and response behaviour.
Recommendation — Instrument email security detections so BEC and impersonation events are observable in response workflows.
NIST SP 800-53 Rev 5IA-8 — Identification and Authentication (Non-Organizational Users)External email senders and trusted impersonation risk intersect with identity assurance.
Recommendation — Apply IA-8 thinking to external trust paths that influence user-facing business decisions.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsEmail abuse often targets authorisation decisions made through trusted communication channels.
Recommendation — Tighten authorisation pathways so email-driven requests cannot bypass decision controls.
CIS Controls v8CIS-5 — Account ManagementBEC and impersonation exploit account trust and operational misuse across business workflows.
Recommendation — Review and restrict accounts that can trigger high-risk business actions through email-driven requests.

Key terms

  • Business email compromise: A form of social engineering where an attacker impersonates a trusted person or domain to manipulate payment, change banking details, or extract sensitive information. It often succeeds without malware because the attacker targets process trust and human judgement instead of technical controls.
  • Secure Email Gateway: A secure email gateway is a control layer that inspects email before it reaches users and can also inspect outbound mail. It filters malicious content, enforces policy, and reduces exposure to phishing, malware, and data leakage, but it does not replace identity governance or account monitoring.
  • Email Trust Debt: Email trust debt is the gap that builds when a security team keeps a legacy mail control in place even though attackers have shifted to behavioural abuse and impersonation. The organisation still sees coverage, but the actual interruption of fraud no longer matches the threat.
  • Proof Of Value: A proof of value is a controlled evaluation that tests a security product against the buyer's own assets, traffic, and operating constraints. In regulated environments, it should prove enforcement coverage, operational fit, rollback safety, and the evidence the organisation will need later.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 27, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org