By NHI Mgmt Group Editorial TeamBased on Abnormal AI: “Is Your Secure Email Gateway Really Necessary? Blocking the Attacks Your SEG Never Could” (June 26, 2026)

TL;DR: Traditional secure email gateways are failing to stop socially engineered attacks such as supply chain compromise, executive impersonation, and account takeover, according to Abnormal AI’s on-demand webinar. The real issue is not email filtering alone, but identity trust assumptions that break when attacks bypass the SEG layer.


At a glance

What this is: Abnormal AI argues that secure email gateways are being bypassed by identity-led attacks such as supply chain compromise, executive impersonation, and account takeover.

Why it matters: IAM and security teams need to treat email security as an identity trust problem, because message filtering alone does not stop attacks that succeed through impersonation and account abuse.


Context

Secure email gateways were built to inspect messages and block known malicious content, but the attack surface has moved toward trusted relationships, impersonation, and compromised accounts. In that model, the control fails not because email is unimportant, but because the real decision point is who appears to be speaking and whether the recipient trusts the sender.

For identity programmes, this is a boundary problem rather than a pure mail-security problem. Once attackers can ride supply chain trust, executive identity, or account takeover, the controls that matter shift toward identity verification, behavioural detection, and governance over who can act in an organisation's name.


Key questions

Q: What breaks when secure email gateways are the main email security control?

A: When SEGs are treated as the main control, organisations often miss identity-based phishing, internal impersonation, and outbound leakage driven by human error. The gateway may still block commodity spam, but it cannot fully govern user action, recipient context, or account compromise. That leaves a gap between message delivery and actual risk reduction.

Q: Why do supply chain compromise and executive impersonation bypass email controls so often?

A: Because both attack types borrow legitimacy from a trusted relationship. The recipient sees a familiar domain, an expected workflow, or a known authority figure, so the message appears credible even when the underlying intent is malicious. The risk rises when business processes allow email alone to authorise action without additional verification.

Q: How do organisations know if email security is actually working?

A: Look for fewer fraudulent requests reaching approval stages, faster triage of suspicious mail, and reduced analyst time spent on low-value noise. Effective email security improves decision quality, not just blocking rates, because the real test is whether risky identity-linked messages are stopped before business action occurs.

Q: What should teams do when a trusted account or executive identity is abused through email?

A: Treat it as an identity incident, not just a mail incident. Contain the account, revoke any delegated or standing authority it can exercise, review recent requests initiated from that identity, and inspect downstream approvals for business action taken on trust alone. The goal is to stop the compromised identity from continuing to authorise work.


Background and context

Why secure email gateways miss identity-led attacks

A secure email gateway inspects inbound mail for malicious links, attachments, sender reputation, and other content signals. That works when the threat is embedded in the message itself, but modern attacks often arrive through legitimate infrastructure, compromised accounts, or socially engineered trust paths. The control is tuned to message hygiene, while the attacker is abusing identity confidence. In practical terms, the gateway can see an email that looks normal even when the underlying sender relationship is compromised or fraudulent.

Practical implication: pair SEG controls with identity-aware detection that evaluates sender legitimacy, account behaviour, and trust context.

Why impersonation and account takeover change the control model

Executive impersonation and account takeover are identity attacks because the attacker does not need to defeat email filtering if they can convince a user that the message is authentic. In these cases, the control problem shifts from content blocking to identity assurance. The question becomes whether the organisation can verify who is actually sending, authorising, or requesting action. That changes the defensive stack: message inspection remains useful, but it is no longer the primary trust control.

Practical implication: require identity verification signals, behavioural analysis, and protected approval workflows for high-risk requests.

Why defence in depth must include sender trust and governance

Defence in depth for email now needs layered controls across identity, behaviour, and response. That means governing who can send as whom, detecting anomalies in communication patterns, and reducing the blast radius when an account or vendor relationship is abused. The article's core point is not that email controls are useless, but that they are incomplete when trust is the target. Security teams need visibility into who is trusted, why, and under what conditions that trust should fail.

Practical implication: map trusted sender paths, review approval dependencies, and monitor for abnormal use of business-critical identities.


NHI Mgmt Group analysis

Secure email gateways are now a partial control, not a trust boundary. Their inspection model was built for message-based threats, but identity-led attacks exploit the social and organisational meaning attached to the message. When the sender relationship is the attack surface, the gateway may still function technically while failing strategically. Practitioners should treat SEG output as one signal inside a broader identity trust model, not as the line that defines safety.

Identity trust assumptions are the real failure mode in modern email attacks. Supply chain compromise, executive impersonation, and account takeover all work by borrowing legitimacy from a known identity path. That makes this a governance problem as much as a detection problem, because organisations must decide which identities are allowed to trigger action and which requests require extra verification. The implication is that trust must be explicit, not inherited from the channel.

Mail security and identity security are converging operationally. The old split between email hygiene and identity governance no longer matches how attackers operate. Security teams need to review how approvals, exceptions, and delegated authority behave when the request arrives through a trusted message rather than a malicious payload. The practical conclusion is that identity-aware controls now belong in the email security conversation.

Complete defence in depth for email depends on limiting business trust, not just blocking bad content. If an attack can persuade a user to act, the control problem has already moved beyond the SEG. This pushes teams toward tighter sender governance, stronger verification for high-risk requests, and better monitoring of anomalous communication patterns. Practitioners should reframe email risk as a question of who is trusted to ask for action.

Identity blast radius is the more relevant metric than message filtering rates. The business consequence of a successful impersonation or takeover is not just one malicious email, but the scope of actions that identity can trigger across the organisation. That makes the control objective containment of trust abuse, not merely higher detection counts. Teams should measure how far a compromised sender can move decisions, not only how many messages were blocked.

From our research library:

What this signals

Identity trust is now the decisive layer in email security. When attackers can reach users through supply chain relationships, executive personas, or compromised accounts, the control question changes from 'was the message malicious?' to 'was the identity legitimate enough to act?' Security programmes need to track that shift in their detection logic and approval design.

Trusted communication paths should be governed like privileged access. A sender who can trigger financial, access, or vendor actions through email effectively holds a privileged business pathway. That means organisations should review who can speak for whom, how those delegations are recorded, and what verification is required before the request is honoured.

Abnormal AI's webinar frames a broader industry change: email filtering is no longer sufficient on its own. The practical implication for practitioners is to align mail security with identity governance, so impersonation and account abuse are caught where trust is granted, not only where content is scanned.


For practitioners

  • Review trusted sender assumptions Map which internal, executive, and third-party identities can trigger high-risk actions by email, and remove implicit trust where a message alone is enough to start work.
  • Add identity-aware detection Correlate sender behaviour, authentication context, and message patterns so impersonation and account takeover are evaluated as identity events, not just email events.
  • Protect high-risk approvals Require out-of-band verification or step-up checks for payment, access, and vendor-change requests that arrive through email, especially when the request claims authority.
  • Limit delegated communication paths Reduce who can speak for executives, finance, procurement, and supplier relationships, and record those delegations as governed access rather than informal practice.

Key takeaways

  • Secure email gateways do not stop every modern attack because the threat has shifted toward abusing trusted identities and relationships.
  • Executive impersonation, supplier compromise, and account takeover succeed when email requests are treated as authoritative without additional verification.
  • Practitioners should govern trusted senders and high-risk approvals as identity controls, not just as mail hygiene.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10, OWASP API Security Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0 sets the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-10 — Human Use of NHIThe article centres on identity trust abuse through email, where humans are induced to act on behalf of identities.
Recommendation — Govern high-risk email-driven actions as identity-controlled workflows, not informal requests.
OWASP API Security Top 10API2 — Broken AuthenticationImpersonation and account takeover reflect authentication and trust failures, even when the channel is email.
Recommendation — Strengthen authentication checks before email-triggered approvals can change access or money movement.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe article's control gap is over-trusted authority to request action through email.
Recommendation — Restrict who can authorise high-risk actions and verify requests against governed permissions.
MITRE ATT&CKTA0006; TA0008 — Credential Access; Lateral MovementAccount takeover and trusted-path abuse are part of the attack pattern discussed.
Recommendation — Map impersonation and takeover scenarios to credential access and lateral movement detections.

Key terms

  • Email identity trust: The set of assumptions that make a sender or request appear legitimate inside an organisation. In modern attacks, this trust often matters more than the maliciousness of the message itself, because users and workflows may act on authority before technical inspection can intervene.
  • Executive impersonation: Executive impersonation is a social engineering tactic where an attacker poses as a senior or trusted person to influence decisions or approvals. The goal is not always account takeover. It is often to exploit authority, urgency, and familiarity to make a person bypass normal checks.
  • Account Takeover: Account takeover is unauthorized use of a legitimate account after an attacker obtains valid access through stolen credentials, tokens, or trusted integrations. The key security problem is that the resulting activity often looks normal to logs and controls, which makes containment and attribution harder than in a forced-entry breach.
  • Identity-aware detection: Identity-aware detection is security monitoring that evaluates alerts using identity context such as target role, privilege level, authentication state, and account type. It improves triage because the same suspicious action has different meaning depending on whether it involves a human user, service account, or machine credential.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 27, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org