Join our Newsletter — 33% off our NHI Course

Legacy SEG replacement in email security: what changed for Florida Crystals?

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20739
Topic starter  

TL;DR: Florida Crystals said advanced email attacks were slipping past its existing defenses, and that replacing its SEG with Abnormal reduced email security costs by 40% while stopping a BEC attack during the proof of value, according to Abnormal AI. The lesson is that email controls must be judged on attack interception and operational fit, not on whether they preserve legacy architecture.

Editorial analysis by NHI Mgmt Group, based on content published by Abnormal AI: “Bucking Tradition: How Florida Crystals Ditched the SEG to Improve Email Security”.

Key questions

Q: What breaks when a legacy SEG misses advanced email attacks?

A: The main failure is that perimeter filtering can look intact while identity-driven attacks still reach users.

Q: Why does BEC create risk even when email security is already deployed?

A: BEC works by manipulating trust and human decision-making, not by relying on malware delivery.

Practitioner guidance

  • Measure BEC interruption, not just block counts Track whether the email control stops fraudulent approval paths before a user replies, forwards money, or changes account details.
  • Map email security to identity abuse patterns Review how impersonation, mailbox trust abuse, and executive fraud pass through your current email stack.
  • Reduce manual triage load Identify where the current stack creates repetitive investigation work, exception handling, or alert fatigue.

Bottom line: Florida Crystals' case shows that a legacy SEG can remain operational while advanced email attacks still slip through to users and workflows.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 3 days ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21501
 

Legacy SEG replacement is now an identity governance decision, not just an email security refresh. When attackers bypass perimeter filtering through impersonation and BEC, the control question shifts to how effectively the mail stack protects human decision points. That makes email security part of the broader identity programme, because the failure mode is abuse of trust, not simple message delivery. Practitioners should judge the stack by whether it changes the likelihood of fraudulent action.

A question worth separating out:

Q: How should teams evaluate legacy email security versus newer detection approaches?

A: Use a scenario-based test that compares whether each control can stop a realistic impersonation or BEC path before business action occurs. The better control is the one that reduces attack success and analyst workload together. Architecture preservation by itself is not a valid selection criterion.

👉 Read our full editorial: Florida Crystals and the SEG replacement problem in email security


This post was modified 3 days ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.