TL;DR: Email security has shifted from blocking phishing and malware to controlling sensitive data as it moves through mail, SaaS, endpoints, GenAI, and MCP-connected workflows, according to Strac. The practical problem is no longer just account compromise; it is unmanaged data movement that demands discovery, inspection, and inline remediation.
NHIMG editorial — based on content published by Strac: History of Email Security
Questions worth separating out
Q: How should organisations control sensitive data in GenAI tools?
A: Organisations should treat prompts, uploads, and model outputs as governed data flows, then apply classification, inspection, and logging at the point of use.
Q: Why do email security controls fail to stop many data leaks?
A: They are designed primarily to stop malicious inbound traffic and account abuse, while many leaks come from authorised users moving legitimate information into the wrong place.
Q: What do security teams get wrong about DLP?
A: The common mistake is assuming DLP can fix excessive access after the fact.
Practitioner guidance
- Map sensitive data paths across email and downstream systems Trace how PII, PHI, PCI data, secrets, and confidential files move from inboxes into SaaS apps, cloud storage, browsers, endpoints, and GenAI tools.
- Pair discovery with inline enforcement Do not stop at identifying sensitive content.
- Extend governance to AI agent workflows Review where MCP-connected agents can retrieve, transform, or forward enterprise data, then apply the same policy expectations you use for human handling of regulated content.
What's in the full article
Strac's full article covers the operational detail this post intentionally leaves for the source:
- Deep content inspection examples for email bodies, attachments, screenshots, and scanned documents
- Inline remediation options such as redaction, masking, blocking, quarantine, and user coaching
- How Strac applies DSPM plus DLP across SaaS, GenAI, browsers, endpoints, and MCP-connected workflows
- Implementation-oriented examples for handling PII, PHI, PCI data, credentials, and secrets
👉 Read Strac's analysis of email security, GenAI, and MCP data risks →
Email security, MCP, and GenAI: are your controls keeping up?
Explore further
Email security without data lineage is a control illusion. Traditional messaging security can reduce phishing and spoofing, but it does not determine where sensitive data goes after a legitimate user sends it. Once information reaches SaaS, GenAI, or endpoint workflows, the risk profile changes from message security to data governance. Practitioners should treat lineage as a first-class security control, not an afterthought.
A question worth separating out:
Q: Who is accountable when AI agents use shared credentials across workflows?
A: Accountability belongs to the organisation that owns the credential lifecycle and the policy attached to it. When shared secrets are used across humans, agents, and machines, the governance model must still identify which actor used the credential, under what approval path, and for what task. Without that, accountability becomes ambiguous.
👉 Read our full editorial: Email security now depends on controlling data across AI workflows