TL;DR: Email security is increasingly a behavioural problem, with attackers using phishing, business email compromise, and AI-powered tactics to exploit the human element, according to Abnormal AI. That means resilience now depends on combining user education with technology rather than treating awareness as a separate programme.
Editorial analysis by NHI Mgmt Group, based on content published by Abnormal AI: “The People Problem: Addressing Human Behavior to Build Better Email Security”.
Key questions
Q: How should security teams reduce phishing risk without relying only on awareness training?
A: They should combine user training with behavioural detection, vendor verification, and tighter controls on high-risk identity actions.
Q: Why does AI-assisted phishing make human error harder to manage?
A: AI-assisted phishing produces messages that are grammatically clean, context-aware, and tailored to the target, which reduces the value of spotting obvious errors.
Practitioner guidance
- Map high-risk user decisions Identify the email actions that create the most downstream risk, such as payment approvals, credential resets, vendor banking changes and mailbox delegation.
- Link training to live detections Use targeted awareness exercises that mirror the actual phishing and BEC patterns your telemetry sees, then feed user-reported events and suspicious-message telemetry into response workflows.
- Add verification to sensitive workflows Require out-of-band checks for requests that change money movement, credentials or delegated access, especially when the request arrives by email and claims urgency.
Bottom line: Email threats are increasingly successful because they target user behaviour as much as inbox controls.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Behavioural susceptibility is now a core email security control plane: Email defence fails when organisations treat user judgement as an external variable instead of part of the control design. Phishing and BEC succeed by shaping human decisions at the moment of action, which means the programme has to measure and influence behaviour as directly as it monitors messages. Practitioners should treat human response patterns as a governed security surface, not a soft edge.
A question worth separating out:
Q: How should teams govern email access when an agent needs it to work?
A: They should govern it as a non-human identity boundary. That means assigning ownership, scoping what the inbox can reach, limiting default blast radius, and defining revocation criteria from the start. If the inbox is part of the workflow, then its access profile must be reviewed like any other privileged operational dependency.
👉 Read our full editorial: Human behavior now drives the email security problem