惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

月光博客
月光博客
有赞技术团队
有赞技术团队
S
SegmentFault 最新的问题
宝玉的分享
宝玉的分享
量子位
小众软件
小众软件
The Cloudflare Blog
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
大猫的无限游戏
大猫的无限游戏
C
Check Point Blog
G
Google Developers Blog
博客园 - 叶小钗
H
Help Net Security
Jina AI
Jina AI
Y
Y Combinator Blog
Last Week in AI
Last Week in AI
GbyAI
GbyAI
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
Apple Machine Learning Research
Apple Machine Learning Research
MyScale Blog
MyScale Blog
T
Tailwind CSS Blog
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
Vercel News
Vercel News

Human Risk Management Blog

Future-Proofing Organizations in the Face of AI What Security Can Learn From Dinosaurs Inside the OS-Aware Phishing Kit Profiling Your Device CyberheistNews Vol 16 #30 [Protect Your Users] AI Hallucinations Are Fueling Phishing Attacks Majority of Organizations Hit by Targeted Impersonation Attacks The Open-Source Paradox: Navigating the New Frontier of AI Supply Chain Risk Introducing The Hybrid Nudge Experience: Outbound Email Security Built for Your Risk Appetite Elevating the SOC Experience: Smarter Automation, Richer Threat Intelligence, and AI-Native Investigation New Phishing Tools Enable Attackers to Easily Bypass Multifactor Authentication From Inbox to Encryption: How Ransomware Delivery Has Evolved Attackers Exploit AI Hallucinations to Send Users to Phishing Sites Warning: ARToken Phishing Kit Automates BEC Attacks The New Face of AI Risk Trust Nothing: Tips to Secure AI Tools and Agents CyberheistNews Vol 16 #29 ClickFix Social Engineering is Now the Leading Malware Delivery Method Beyond the Checkbox: How a Proactive Partnership Led to Turnkey Hazing Compliance Report: Social Engineering Remains a Central Part of AI-assisted Attacks ClickFix Social Engineering is Now the Leading Malware Delivery Method CyberheistNews Vol 16 #28 Your 2026 Phishing by Industry Benchmarks: The Findings on Human Risk Scammers Can Use AI Tools to Pinpoint Your Location Based on a Photo Report: Attackers Are Using AI to Automate Social Engineering Your KnowBe4 Fresh Compliance Plus Content Updates from June 2026 From Awareness to Digital Workforce Security Your KnowBe4 Fresh Content Updates from June 2026 Threat Actor Uses Phishing to Breach Orgs for Ransomware Gangs Invoice Phishing Attacks Are Abusing the Shop App Phishing Campaign Impersonates Interpol to Deliver Ransomware Prompt Injection and the Rise of Agentic Risk Hyper-Targeted Social Engineering Needs Real-Time Video Response Your Email is Protected. Is Your Teams Chat?
Trust, Verify, Protect: Modernizing Email Security for th...
Dr. Kawin Boonyapredee · 2026-07-16 · via Human Risk Management Blog

CISO_Blog_KawinB_400x225Picture this: Your company just fell victim to a massive data breach. The culprit wasn't a sophisticated malware strain, a zero-day exploit, or a compromised firewall. It was a perfectly legitimate-looking login from a VP’s account, originating from an unrecognized IP address, requesting an urgent wire transfer via a spotless, text-only email.

In the modern threat landscape, attackers have realized something crucial: Why break in when you can just log in?

As organizations shift to the cloud, the line between email security and identity management has blurred entirely. Traditional email security is failing because it’s looking for bad files, while attackers are busy stealing good identities. Here is how cloud email security should work in a world dominated by identity-first attacks.

The Core Problem: The Legacy Email Security Mirage

For decades, Secure Email Gateways (SEGs) acted as the bouncers of the corporate network. They inspected incoming traffic at the perimeter, checking for known bad signatures, malicious attachments and sketchy URLs.

But in a cloud-first world (think Microsoft 365 and Google Workspace), the perimeter no longer exists.

Attackers use trusted infrastructure: Phishing pages are hosted on legitimate SharePoint or Google Drive links.

Payload-less attacks dominate: Business Email Compromise (BEC) and vendor email compromise often contain zero links and zero attachments. They rely purely on social engineering and identity impersonation.

The attack happens inside the house: If an attacker compromises a user's credentials via a session hijacking attack, they can send malicious emails internally. A traditional SEG will never even see it.

What is an Identity-First Attack?

Identity-first attacks target the human element and the authentication mechanisms protecting them. Instead of exploiting software vulnerabilities, they exploit trust. Common tactics include:

  • Session Hijacking / Cookie Theft: Bypassing Multi-Factor Authentication (MFA) by stealing active session tokens.
  • Credential Stuffing: Using leaked passwords across multiple platforms.
  • Lookalike Domains & Display Name Spoofing: Creating an email address that looks identical to a company executive or trusted vendor (e.g., ceo@cornpany.com instead of company.com).

The Blueprint for Modern Cloud Email Security

To survive a world of identity-first threats, email security can no longer operate in a silo. It must evolve from a perimeter filter into an integrated, identity-aware behavioral engine. Here is what that looks like in practice:

1. Moving from Gateways to API-Based Architecture

Modern email security must sit inside the cloud email provider via native APIs, not in front of it. API-based solutions have total visibility. They can scan internal-to-internal emails, analyze historical communication patterns and retroactively remediate threats even after they land in an inbox.

2. Establishing a Dynamic "Behavioral Baseline"

Instead of looking for what is bad, security tools must deeply understand what is normal. By integrating with identity providers (like Okta, Entra ID, or Ping Identity), an identity-first email security platform builds a baseline of user behavior:

  • What time does this user usually log in?
  • What devices and locations do they typically use?
  • Who do they normally communicate with, and what is their typical tone or writing style?

If an executive suddenly emails finance from a new IP address demanding a wire transfer using language they've never used before, the system should automatically flag it, even if the MFA check passed.

3. Continuous, Risk-Based Authentication

Authentication is not a one-time event at login. If a user’s email behavior suddenly shifts (e.g., they start mass-forwarding sensitive emails to an external address), the email security engine must feed this risk telemetry back to the Identity Provider (IdP). This triggers an automatic response, such as forcing a re-authentication prompt, step-up MFA or terminating the active session entirely.

4. Supply Chain and Vendor Risk Profiling

You might have world-class security, but what about your vendors? Attackers frequently compromise a third-party vendor and use their legitimate email accounts to launch attacks against you.

Modern email security must continuously map your organization's supply chain, analyzing the reputation and communication cadence of external partners to detect when a trusted vendor's identity has been hijacked.

The Path Forward: Zero Trust for the Inbox

Adopting an identity-first approach to email security means applying the core principles of Zero Trust: Never trust, always verify.

The Identity-First Security Mantra: Treat every email not just as a piece of data, but as an assertion of identity.

When your email security solution can instantly cross-reference the content of a message with the context of the identity sending it, the attacker’s playbook falls apart. It’s time to stop focusing purely on the perimeter and start securing the identities that define your business.