TL;DR: EAB says its security team blocked thousands of phishing and business email compromise attacks across a partner ecosystem of 2,500+ education institutions after modernising email security and moving away from a legacy SEG, according to Abnormal AI. The case shows why email-layer controls now need to be judged on ecosystem reach, not inbox filtering alone.
Editorial analysis by NHI Mgmt Group, based on content published by Abnormal AI: “EAB Teaches a Masterclass in Email Security”.
Key questions
Q: How should security teams reduce the impact of phishing and BEC on human users?
A: Combine user education with technical controls that limit what a mistaken click or reply can do.
Q: Why do legacy SEG controls miss business email compromise in distributed organisations?
A: Legacy SEG controls are often tuned to content, reputation, and perimeter filtering, but BEC frequently uses legitimate-looking communication and trusted relationships.
Practitioner guidance
- Measure partner blast radius Map how far a compromised or spoofed sender can reach across partner institutions, executives, finance teams, and support workflows before delivery controls intervene.
- Test for vendor email compromise paths Run scenarios that use trusted partner branding, invoice language, and approval requests to see whether the stack blocks abuse before a recipient can act.
- Shift from content filters to behaviour signals Check whether detection looks for unusual sender behaviour, abnormal communication patterns, and impersonation rather than only static indicators and known bad content.
Bottom line: EAB’s case shows that email compromise in partner ecosystems is a trust-boundary problem, not just an inbox-filtering problem.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Legacy SEG design assumes the inbox is the unit of control. That assumption breaks in partner ecosystems where one sender relationship can influence many organisations at once. EAB’s case shows that email security is no longer a single-org filtering problem, but a trust-boundary problem across institutions. Practitioners should evaluate controls by how much of the ecosystem they can protect, not by how many messages they can scan.
A question worth separating out:
Q: How should security teams handle vendor email compromise in enterprise environments?
A: Security teams should treat vendor email compromise as a trust and lifecycle problem, not only a phishing problem. The practical response is to maintain a living inventory of active vendor relationships, tie approvals to behavioural risk signals, and add independent verification for payment or account-change requests that arrive through trusted third-party channels.
👉 Read our full editorial: EAB's email security masterclass shows the SEG is not enough