Join our Newsletter — 33% off our NHI Course

Secure email gateways and identity attacks: what should teams do?

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20739
Topic starter  

TL;DR: Traditional secure email gateways are failing to stop socially engineered attacks such as supply chain compromise, executive impersonation, and account takeover, according to Abnormal AI’s on-demand webinar. The real issue is not email filtering alone, but identity trust assumptions that break when attacks bypass the SEG layer.

Editorial analysis by NHI Mgmt Group, based on content published by Abnormal AI: “Is Your Secure Email Gateway Really Necessary? Blocking the Attacks Your SEG Never Could”.

Key questions

Q: What breaks when secure email gateways are the main email security control?

A: When SEGs are treated as the main control, organisations often miss identity-based phishing, internal impersonation, and outbound leakage driven by human error.

Q: Why do supply chain compromise and executive impersonation bypass email controls so often?

A: Because both attack types borrow legitimacy from a trusted relationship.

Practitioner guidance

  • Review trusted sender assumptions Map which internal, executive, and third-party identities can trigger high-risk actions by email, and remove implicit trust where a message alone is enough to start work.
  • Add identity-aware detection Correlate sender behaviour, authentication context, and message patterns so impersonation and account takeover are evaluated as identity events, not just email events.
  • Protect high-risk approvals Require out-of-band verification or step-up checks for payment, access, and vendor-change requests that arrive through email, especially when the request claims authority.

Bottom line: Secure email gateways do not stop every modern attack because the threat has shifted toward abusing trusted identities and relationships.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 3 days ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21503
 

Secure email gateways are now a partial control, not a trust boundary. Their inspection model was built for message-based threats, but identity-led attacks exploit the social and organisational meaning attached to the message. When the sender relationship is the attack surface, the gateway may still function technically while failing strategically. Practitioners should treat SEG output as one signal inside a broader identity trust model, not as the line that defines safety.

A few things that frame the scale:

  • 92% of organisations expose NHIs to third parties, raising concerns about supply chain security, according to the Ultimate Guide to NHIs.

A question worth separating out:

Q: What should teams do when a trusted account or executive identity is abused through email?

A: Treat it as an identity incident, not just a mail incident. Contain the account, revoke any delegated or standing authority it can exercise, review recent requests initiated from that identity, and inspect downstream approvals for business action taken on trust alone. The goal is to stop the compromised identity from continuing to authorise work.

👉 Read our full editorial: Secure email gateways are failing against modern identity attacks


This post was modified 3 days ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.