The spam filter era is over
For years, email security meant a spam filter. Block the obvious junk, quarantine the malware, and most of the threat was handled. That model addressed a threat landscape that no longer dominates. The attacks that cause the most damage today are not mass-market spam. They are targeted, well-crafted, and often carry no malicious attachment or link at all, which means the tools built to catch spam simply do not see them.
Email remains the most common entry point for serious incidents, so the gap between what legacy filters catch and what attackers now send is a gap worth closing deliberately.
What is getting through
Business email compromise
The highest-cost email threat carries no malware. An attacker impersonates a senior figure or a supplier and uses a plausible, well-timed message to redirect a payment or extract sensitive information. There is nothing for a malware scanner to detect. the payload is social, not technical.
AI-generated phishing
The tell-tale signs people were trained to spot (clumsy grammar, awkward phrasing) are disappearing. Generative tools produce fluent, contextual, convincing messages at scale, in any language. The quality floor of phishing has risen sharply, and volume has risen with it.
Supplier and supply-chain impersonation
Attackers increasingly exploit trusted relationships, impersonating a genuine supplier or compromising their account to send a message that arrives in the middle of a real conversation. Because it comes from a known contact, it clears the instinctive checks a recipient would apply to a stranger.
The attack moved from the attachment to the message
Legacy email security was built to inspect content: attachments, links, known-bad indicators. The most damaging modern attacks put the payload in the intent of a clean-looking message. Defending against them requires understanding context and behaviour, not just scanning content.
Why legacy gateways miss it
A traditional secure email gateway asks whether a message contains something known to be bad. That question has no useful answer for a fluent, malware-free message from a display name you recognise. The gateway sees a clean email and passes it. The controls that catch these attacks ask different questions: does this sender's behaviour match their history, is this domain a subtle look-alike, is this an unusual payment request arriving through an unusual channel.
A layered answer
No single control solves modern email risk. A layered posture is what closes the gap:
- Authentication standards. SPF, DKIM, and DMARC, correctly configured and enforced, make it far harder for attackers to spoof your own domain.
- Behavioural and impersonation detection. Controls that model normal sender behaviour and flag anomalies catch what content scanning cannot.
- Robust identity and MFA. Since account takeover is a primary route, phishing-resistant MFA on email accounts limits the damage a stolen password can do.
- Process controls for payments. Out-of-band verification for payment changes defeats business email compromise regardless of how convincing the message is.
- Detection and response. When something does get through, detection and response shortens the time between compromise and containment.
"You cannot filter your way out of business email compromise. The message is clean. The defence is a combination of authentication, behavioural detection, and a payment process that does not rely on a single email being genuine."
Edge7 Networks, Security PracticePeople are part of the control
Technology carries most of the load, but people remain part of the control set, provided the training is realistic. Awareness that teaches staff to verify unusual payment requests through a second channel, and that makes it safe to question a message that seems to come from a senior figure, closes the specific gap that business email compromise depends on. The goal is not to turn every employee into an analyst. It is to build one or two reliable habits around the highest-risk actions.
Where to start
A sensible starting point is a review of your current email security posture against the threats that actually matter now: is DMARC enforced, can your controls detect impersonation rather than only malware, and does your payment process survive a convincing fake. Most organisations find at least one of those open.
Edge7 Networks works with IT teams across Ireland and the UK on email security and the wider detection that backs it up. If your defences are still built around the spam-filter model, a posture review is the right first step.