TL;DR: Despite heavy investment in secure email gateways, 94% of organisations still report email security incidents and 87% of cybersecurity leaders are considering replacing SEGs, while advanced phishing attacks bypass detection more often, according to KnowBe4. Static DLP and gateway-centric controls are no longer enough when email risk spans identity, content, and user behaviour.
NHIMG editorial — based on content published by KnowBe4: Are You Ready to Replace Your SEG?
By the numbers:
- 94% of organizations still experience email security incidents.
- 87% of cybersecurity leaders are now looking to replace their SEGs with a modern, integrated security stack.
- 47% increase in attacks getting through detection.
Questions worth separating out
Q: What breaks when secure email gateways are the main email security control?
A: When SEGs are treated as the main control, organisations often miss identity-based phishing, internal impersonation, and outbound leakage driven by human error.
Q: Why do static DLP rules fail to stop human email mistakes?
A: Static rules are built for known patterns, but misdirected email usually happens when a legitimate user sends valid content to the wrong place.
Q: How do security teams know if their email controls are actually overlapping?
A: Look for the same threat categories being claimed by both layers, the same messages being inspected twice, and the same native protections being disabled to keep the SEG functional.
Practitioner guidance
- Measure SEG performance against modern phishing scenarios Run simulation campaigns that include thread hijacking, trusted sender impersonation, and payload-free lures.
- Add recipient-aware outbound controls Use recipient validation, approval prompts, and policy exceptions for sensitive messages that leave the organisation.
- Correlate email, identity, and tenant telemetry Connect mail logs, sign-in events, and risky-user signals so a suspicious message can trigger account review or step-up verification.
What's in the full report
KnowBe4's full whitepaper covers the operational detail this post intentionally leaves for the source:
- The vendor's breakdown of why 94% of organisations still see email security incidents despite SEG investment.
- The vendor's assessment framework for deciding when a modern integrated security stack is more appropriate than a gateway-only model.
- The vendor's discussion of Microsoft 365 native controls combined with AI-driven ICES for inbound and outbound protection.
- The vendor's analysis of static DLP limitations in misdirected email and human-error scenarios.
👉 Read KnowBe4's whitepaper on whether your SEG should be replaced →
Email security incidents persist despite SEGs: are controls keeping up?
Explore further
Email security has become an identity problem as much as a content problem. The article's strongest implication is that message filtering alone cannot govern access, intent, or user action. Email is now a control surface where authentication, impersonation, and recipient trust collide, so practitioners should treat it as part of the broader identity security stack.
A question worth separating out:
Q: Should organisations replace a SEG with integrated cloud email security?
A: Replacement makes sense when the organisation needs correlated inbound, outbound, and identity-aware controls that a SEG cannot provide on its own. The decision should be based on coverage gaps, response speed, and how well native platform telemetry can be combined with policy enforcement. If the stack is fragmented, consolidation may improve governance.
👉 Read our full editorial: Email security incidents persist despite SEGs, driving ICES adoption