TL;DR: Forrester’s Total Economic Impact study found four global customers prevented $4 million in BEC losses while SOC analyst hours on email security tasks fell 95%, as cloud email adoption and API-based security challenge legacy models, according to Abnormal AI. Email compromise is now a governance and control-plane problem, not just a detection problem.
Editorial analysis by NHI Mgmt Group, based on content published by Abnormal AI: “The Total Economic Impact™️ of Abnormal Security”.
Key questions
Q: What breaks when email security only looks for malicious exfiltration?
A: What breaks is the ability to detect legitimate mistakes that cause the same business impact as hostile theft.
Q: Why does cloud email adoption make legacy email security weaker?
A: Cloud email shifts control into APIs, mailbox settings, and service-side activity that perimeter tools often cannot govern well.
Practitioner guidance
- Map mailbox delegation paths Identify who can act on behalf of each mailbox, including delegated senders, shared inboxes, forwarding rules, and service-linked access paths.
- Shift from gateway-only inspection to service-side governance Validate whether your email security stack can inspect and constrain cloud service activity, not just inbound messages.
- Tie BEC controls to identity lifecycle reviews Include email permissions, trusted senders, forwarding rights, and shared mailbox access in joiner-mover-leaver and access review processes.
Bottom line: BEC is increasingly a governance failure as much as a detection failure, because attackers exploit trusted identity paths and business workflows after delivery.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Cloud email security is now a control-plane discipline, not an inbox filter problem. The article points to a shift from static gateway inspection to API-based visibility into mailboxes, delegation, and post-delivery abuse. That matters because BEC increasingly lives in the trust fabric around email, not only in malicious content. Practitioners should treat email security architecture as part of identity governance, not as a separate detection silo.
A question worth separating out:
Q: How do organisations know if email security is reducing business fraud risk?
A: Look beyond spam and phishing counts. Measure whether the environment can spot mailbox-rule abuse, anomalous delegation, suspicious invoice changes, and post-delivery misuse of trusted mail paths. If those signals are invisible, email security may be filtering noise without materially reducing BEC exposure.
👉 Read our full editorial: Cloud email and BEC risk are outpacing legacy security models