TL;DR: DexKo Global says replacing its legacy SEG with a Microsoft plus Abnormal API-based architecture across 7,000 employees and a partner-heavy supply chain freed budget and bandwidth while improving protection and automation, according to Abnormal AI. The real shift is that email security is moving toward API-level control and operational efficiency, not just filter tuning.
Editorial analysis by NHI Mgmt Group, based on content published by Abnormal AI: “The Fast Lane: How DexKo Global Rolled Off of Its Legacy SEG”.
Key questions
Q: How should security teams decide whether a legacy SEG still fits their environment?
A: They should test the SEG against today’s operating model, not last year’s mail flow.
Q: Why do partner-heavy email environments push teams away from gateway-only security?
A: Because the attack surface is no longer confined to internal mailboxes.
Practitioner guidance
- Reassess the email security control plane Compare your current SEG architecture against the way mail now moves through cloud platforms, acquired businesses, and external partners.
- Map partner and contractor exposure Inventory which suppliers, contractors, and acquired entities can reach users through email and how those trust relationships are governed.
- Measure operational drag, not just detection coverage Track analyst time spent on tuning, false positive handling, and manual investigation before and after architecture changes.
Bottom line: Legacy SEG retirement in this case reflects a broader move away from gateway-centric email security toward platform-integrated control.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Email security is moving from gateway control to identity-aware control. A legacy SEG assumes the mail boundary is the primary enforcement point, but modern collaboration is already distributed across cloud tenants, acquisitions, and partner ecosystems. That makes message security inseparable from identity context and platform integration. Practitioners should treat email security as part of the broader identity plane, not as a standalone filter stack.
A question worth separating out:
A: They should evaluate whether the email architecture can scale across multiple locations, inherited environments, and external trust relationships without adding disproportionate operational burden. In those cases, the right model is the one that supports platform integration and consistent governance across all mail paths, not the one that simply filters messages at the edge.
👉 Read our full editorial: Legacy SEG retirement shows how email security is being re-architected