Upstream gateways often depend on known bad indicators, which is weak against personalised phishing, vendor impersonation, and account abuse that looks legitimate at delivery time. Behavioural models work better when they learn baseline patterns for users, identities, and content, then flag deviations. That reduces blind spots where attackers use trusted relationships instead of obvious malware or links.
Why This Matters for Security Teams
Upstream gateways and signature-based controls are designed to stop known-bad content, known-bad infrastructure, and repeatable attack patterns. That works reasonably well for commodity malware and bulk phishing, but modern email and identity attacks are often built to look ordinary at delivery time. The message may be clean, the link may be newly registered but not yet flagged, and the account activity may mirror valid business behaviour. This is why identity-aware detection has become a core control, not an optional layer.
Security teams often miss that the failure is not only about email security. It is also about trust in accounts, suppliers, delegated access, and session behaviour. A message from a compromised vendor mailbox can bypass reputation filters, while a stolen identity can turn a legitimate login into a foothold. Guidance from NIST SP 800-53 Rev 5 Security and Privacy Controls supports layered monitoring and access control, but in practice the blind spot appears when organisations rely on delivery-time inspection alone. In practice, many security teams encounter these attacks only after a trusted identity has already been used to request payment, reset credentials, or change routing rules, rather than through intentional detection of behaviour drift.
How It Works in Practice
Modern attackers increasingly exploit the gap between content inspection and identity misuse. A gateway can score an email for malicious links, but it cannot reliably decide whether a reply from a known supplier is part of a business email compromise, or whether a login from a valid user is actually an adversary using stolen credentials. Effective detection therefore shifts from static indicators to telemetry across message flow, authentication events, device signals, and user behaviour.
Operationally, that means correlating signals such as sender reputation, domain age, reply-chain anomalies, impossible travel, MFA fatigue attempts, unusual inbox rule creation, and anomalous OAuth consent. Threat hunting frameworks such as the MITRE ATT&CK Enterprise Matrix help teams map these behaviours to techniques like credential access, valid accounts, and email collection. For AI-assisted attacks, the MITRE ATLAS adversarial AI threat matrix is increasingly relevant when attackers use generative systems to scale social engineering, tailor lures, or automate reconnaissance.
- Use email security to block obvious malicious content, but do not treat it as the primary identity control.
- Score authentication, mailbox, and collaboration events for deviations from baseline.
- Correlate sender, user, device, and session context before escalating.
- Feed confirmed incidents back into detection logic so patterns learn from compromise paths, not just bad URLs.
Authoritative advisories from CISA cyber threat advisories consistently show that phishing is often a delivery mechanism for account compromise rather than a standalone email problem. These controls tend to break down when organisations have poor identity telemetry, fragmented logging across SaaS platforms, or no visibility into delegated mailbox and OAuth activity because the attack then looks like normal use.
Common Variations and Edge Cases
Tighter detection often increases operational overhead, requiring organisations to balance lower false negatives against more false positives and investigation load. That tradeoff is especially visible in executive communications, high-volume vendor workflows, and environments with heavy automation, where legitimate anomalies are common and static rules age quickly.
Best practice is evolving, and there is no universal standard for exactly how much behavioural modelling is enough. Some teams use risk-based authentication and mailbox analytics only for high-value users, while others extend the same logic to service accounts and agentic workflows. The identity bridge matters here: if an AI agent can read mail, trigger workflow actions, or approve requests, then it is effectively part of the trust boundary and must be monitored like any other privileged identity.
This is also where upstream controls miss context. A message may be safe in transit but dangerous after delivery if it leads a user to authorise a session, approve a token grant, or alter a payment path. When an attacker uses a trusted account, vendor relationship, or AI-generated pretext, signature-based tools rarely see a clear malicious artefact. Organisations that handle sensitive communications should review control mappings against NIST control guidance and incident patterns seen in real campaigns such as the Anthropic first AI-orchestrated cyber espionage campaign report. Those patterns show how attackers increasingly adapt content, timing, and identity use to stay inside normal-looking behaviour rather than crossing obvious malware thresholds.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK, OWASP Agentic AI Top 10 and MITRE ATLAS address the attack and risk surface, while NIST CSF 2.0 and NIST AI RMF set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | DE.CM-1 | Continuous monitoring is needed to catch identity and mailbox abuse missed by gateways. |
| MITRE ATT&CK | T1078 | Valid accounts is a common way attackers bypass signature-based controls. |
| NIST AI RMF | AI-assisted phishing changes content and behaviour faster than static rules can follow. | |
| OWASP Agentic AI Top 10 | Agentic workflows expand the trust boundary for email and identity abuse. | |
| MITRE ATLAS | AML.T0052 | Adversarial AI can be used to generate tailored lures and evade simple detection. |
Test AI-assisted attack scenarios so detection logic covers prompt-driven social engineering and evasion.
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on August 25, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org