TL;DR: Choice Hotels found advanced email attacks bypassing legacy secure email gateways and traditional security tools before moving to behavioural detection, then remediated BEC and vendor email compromise faster and freed security time for proactive work, according to Abnormal AI. The core issue is that legacy email controls still miss behaviour-driven abuse patterns, not just malicious payloads.
Editorial analysis by NHI Mgmt Group, based on content published by Abnormal AI: “How Choice Hotels Utilizes Innovative Security Solutions to Protect its Email Ecosystem”.
Key questions
Q: Why do secure email gateways miss modern business email compromise?
A: Secure email gateways were built to spot malicious links, attachments, and known spam patterns.
Q: How should security teams handle vendor email compromise in enterprise environments?
A: Security teams should treat vendor email compromise as a trust and lifecycle problem, not only a phishing problem.
Practitioner guidance
- Map email trust relationships Identify which supplier, payment, and executive communication paths carry the highest business consequence if impersonated.
- Add behavioural detection to email controls Evaluate whether your current stack can flag unusual sender behaviour, reply chains, first-time contact patterns, and abnormal request timing.
- Tighten vendor communication verification Require out-of-band verification for changes to payment, banking, or sensitive data requests that arrive through email.
Bottom line: Legacy email gateways are not designed to catch every malicious conversation, especially when attackers rely on believable context instead of malware.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Legacy email security is a trust problem, not only a content-filtering problem. The article shows that attacks can bypass SEGs when the message itself is not obviously malicious. That exposes a governance gap: organisations still anchor email defence to payload inspection even though modern abuse is often behavioural and relational. The practical conclusion is that email security now sits closer to identity trust management than simple message hygiene.
A question worth separating out:
Q: How can teams tell whether behavioural email detection is working?
A: It is working when suspicious requests are flagged before approval, when impersonation patterns are detected across channels, and when legitimate business processes still move without excessive friction. The best signal is fewer unsafe actions taken on convincing but fraudulent requests.
👉 Read our full editorial: Email attack bypasses expose the gap in legacy SEG controls