TL;DR: 70% of its customers have fully moved away from secure email gateways, as legacy SEG controls continue to miss attack types that are increasing and Microsoft 365 expands native security capabilities, according to Abnormal AI. The shift shows email defence is now a control-design problem, not just a filtering problem.
Editorial analysis by NHI Mgmt Group, based on content published by Abnormal AI: “The Great SEG Migration: Lessons Learned from Replacing 100 SEGs”.
Key questions
Q: What breaks when secure email gateways are the main email security control?
A: When SEGs are treated as the main control, organisations often miss identity-based phishing, internal impersonation, and outbound leakage driven by human error.
Q: When should organisations prioritise native platform controls over a SEG?
A: Prioritise the native platform when it already provides the baseline inspection, policy enforcement, and threat detection that the SEG was added to supply.
Practitioner guidance
- Reassess SEG coverage by attack path Map which attacks still require a gateway layer and which are already handled by Microsoft 365 native controls, then compare that to the mailbox abuse patterns you actually see.
- Tie email defense to identity controls Connect phishing defence, conditional access, and account recovery so mailbox compromise cannot easily become identity takeover.
- Audit which detections are content-only Separate static message filtering from behavioural or identity-aware detections, then identify where your current stack still depends on signature-style inspection.
Bottom line: Legacy secure email gateways are losing influence because modern email attacks increasingly bypass content-centric inspection and move into identity abuse paths.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Email defence has moved from perimeter filtering to identity-adjacent control design. The article’s central signal is not that one product class is fading, but that the attack surface has changed faster than gateway-era assumptions. When threats land in authentication flows, mailbox trust, or platform-native collaboration, the control question shifts to where identity enforcement actually happens. Practitioners should treat email security as part of the access stack, not a separate inbox problem.
A question worth separating out:
Q: How should security teams share accountability for email-to-identity attacks?
A: Email security and IAM teams should treat mailbox abuse, phishing recovery, and token theft as one operational chain. If each team only owns its own tool set, attackers can move from mail delivery to identity compromise without a clear response owner. Joint ownership should cover prevention, detection, and recovery across the same path.
👉 Read our full editorial: Legacy secure email gateways are losing ground in email defense