惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Recorded Future
Recorded Future
Security Archives - TechRepublic
Security Archives - TechRepublic
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
Jina AI
Jina AI
I
InfoQ
D
DataBreaches.Net
人人都是产品经理
人人都是产品经理
腾讯CDC
GbyAI
GbyAI
V
Visual Studio Blog
H
Hackread – Cybersecurity News, Data Breaches, AI and More
Microsoft Azure Blog
Microsoft Azure Blog
F
Fortinet All Blogs
博客园 - 聂微东
美团技术团队
The Register - Security
The Register - Security
Engineering at Meta
Engineering at Meta
Apple Machine Learning Research
Apple Machine Learning Research
雷峰网
雷峰网
S
Schneier on Security
量子位
A
About on SuperTechFans
H
Help Net Security
MongoDB | Blog
MongoDB | Blog
S
SegmentFault 最新的问题
Know Your Adversary
Know Your Adversary
Cisco Talos Blog
Cisco Talos Blog
Vercel News
Vercel News
Simon Willison's Weblog
Simon Willison's Weblog
PCI Perspectives
PCI Perspectives
B
Blog
K
Kaspersky official blog
V
Vulnerabilities – Threatpost
aimingoo的专栏
aimingoo的专栏
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
U
Unit 42
G
Google Developers Blog
L
LINUX DO - 最新话题
Forbes - Security
Forbes - Security
AWS News Blog
AWS News Blog
P
Palo Alto Networks Blog
Security Latest
Security Latest
爱范儿
爱范儿
Attack and Defense Labs
Attack and Defense Labs
IT之家
IT之家
L
LINUX DO - 热门话题
D
Docker
P
Proofpoint News Feed
Y
Y Combinator Blog
P
Proofpoint News Feed

Human Risk Management Blog

Trust, Verify, Protect: Modernizing Email Security for the Cloud Report: Social Engineering Remains a Central Part of AI-assisted Attacks ClickFix Social Engineering is Now the Leading Malware Delivery Method CyberheistNews Vol 16 #28 Your 2026 Phishing by Industry Benchmarks: The Findings on Human Risk Scammers Can Use AI Tools to Pinpoint Your Location Based on a Photo Report: Attackers Are Using AI to Automate Social Engineering Your KnowBe4 Fresh Compliance Plus Content Updates from June 2026 From Awareness to Digital Workforce Security Your KnowBe4 Fresh Content Updates from June 2026 Threat Actor Uses Phishing to Breach Orgs for Ransomware Gangs Invoice Phishing Attacks Are Abusing the Shop App Phishing Campaign Impersonates Interpol to Deliver Ransomware Prompt Injection and the Rise of Agentic Risk Hyper-Targeted Social Engineering Needs Real-Time Video Response Your Email is Protected. Is Your Teams Chat? CyberheistNews Vol 16 #27 [HOW TO] Your Cybersecurity Starts at Home on World Social Media Day 2026 Phishing by Industry Benchmarking Report: Findings on Human Risk INC Ransomware Gang Targets the Legal Sector 5 Essential Cybersecurity Defenses for Cloud Email Security Cybercriminals Are Targeting the FIFA World Cup 2026 Why Bite-Sized Security Awareness Training Matters in an Age of TikTok and Digital Distraction Happy 3rd Birthday to Our KnowBe4 Community! Phishing Exposes Employee Data at 86% of Fortune 100 Companies Shadow AI Is Not Shadow IT With a Better Marketing Budget CyberheistNews Vol 16 #26 A New Extortion Scam Uses IT Impersonation to Breach Organizations Cybersecurity Starts At Home This World Social Media Day FTC Report: Americans Lost $3.5 Billion to Imposter Scams Last Year Report: Device Code Phishing is Surging Report: Online Shoppers Increasingly Ignore Scam Warning Signs Security Training Needs Google Maps, Not Christopher Columbus Turn Account Takeover Into Real-Time Security Coaching Extortion Gang Sends In-Person Attackers to Exfiltrate Data Attackers aren’t loyal to any collaboration channel CyberheistNews Vol 16 #25 [The AI Tell] How To Expose Machine-Written Phishing Fast Social Engineering Attacks Abuse Workplace Collaboration Tools New Extortion Brand Uses IT Impersonation to Breach Organizations APWG Report: Social Media Phishing is Surging Cybersecurity Awareness Training for AI: Key Focus Areas Americans Lost $900 Million to AI-Powered Scams Last Year What AI Can’t Hide When It Writes a Phishing Email Your AI Agents Are Eager to Please And Easy to Exploit From 1% to 26%: How AIDA Orchestration Fixes the Remedial Training Gap Best AI Agent Security Tools for SMB and Enterprise in 2026 4 Hot Summer Travel Tips To Avoid Scams CyberheistNews Vol 16 #24 [FBI Alert] Lock Down Your Microsoft 365 Device Code Flows Now The Role of Agentic AI in Phishing Security Training A Credit Score for Cyber Behavior Agentic AI Security in 2026: What to Know How to Secure AI Agents: 4 Best Practices An Overview of Email Compliance Regulations and Reporting Report: AI-Assisted Fraud is Surging Attackers Use Spoofed ChatGPT Site to Deliver Malware I Love Device-Bound Session Credentials, But They Are Still Phishable and Hackable Nearly Two-Thirds of CEOs Cite Cyberattacks as Their Top Concern A Look at Spam vs. Phishing: 4 Key Differences KnowBe4 Wins Multiple 2026 TrustRadius Top Rated Awards Cyber Insurance for Mid‑Market Organizations in Southeast Asia KnowBe4 Earns Multiple 2026 Buyer's Choice Awards from TrustRadius The New Frontier: Securing Japan’s Hybrid Digital Workforce (2026 & Beyond) CyberheistNews Vol 16 #23 Now Phishing Attacks Use Real Hotel Reservations to Target Travelers Report: AI-Enabled Social Engineering Attacks Are on the Rise Your KnowBe4 Fresh Compliance Plus Content Updates from May 2026 FBI: Kali365 Phishing Kit is Targeting Microsoft 365 Accounts KB4-CON - AI Is Everything How to Secure AI Adoption In Your Organization Your KnowBe4 Fresh Content Updates from May 2026 The Silent Invitation: A Deep Dive into Calendar Invite Phishing Cyber Insurance for Mid‑Market Organizations in Southeast Asia Chinese-Language Phishing Kits Are Growing More Advanced Phishing Attacks Are Using Real Hotel Reservation Info to Target Travelers Warning: Scammers are Exploiting Geopolitical Unrest Athletes Are Increasingly Targeted by Social Engineering Attacks AI Agent Governance Part 3 - Runtime Governance: The Hidden Performance Cost of Agentic AI AI Agent Governance Part 2 - What Good Looks Like: Governing AI Agents in Practice 8 Ways to Reduce False Positives in Email Security Ransomware Attacks Drive a Surge in Cyber Insurance Claims My Favorite 5 KnowBe4 Agents Perry Carpenter KB4-CON 2026 Q&A: Deepfakes & Deception Free Gift Fallacy: How Attackers Harvest Credit Cards via Fake Surveys When Global Conflict Becomes a Cyber Weapon: How Iran Tensions and Other Stressful Events Fuel Social Engineering Attacks CyberheistNews Vol 16 #21 [Heads Up] GitHub Breach Shows Developer Tools Are Social Engineering Targets Alert: Extortion Groups Are Using Phishing Kits to Automate Their Attacks Beyond the Chatbot: Why Your AI Agents are Your Newest (and Most Vulnerable) Colleagues Report: Adversarial Use of AI is Evolving
Static DLP Is Leaving You in the Dark: Why It’s Time for Intelligent, Self-Serve Outbound DLP and Misdirected Content Analysis
Haylea Reiner, MBA · 2026-07-07 · via Human Risk Management Blog

When we think about email security, our minds almost always jump to the inbound threats: the sophisticated phishing lures, the AI-generated business email compromise (BEC) attacks, and the malicious attachments knocking at the perimeter.

But there is a silent, internal crisis happening on the way out of your organization. And chances are, you’re flying completely blind to it.

According to product telemetry from KnowBe4’s Outbound Email Security, Prevent, organizations are typically only aware of roughly 10% of the outbound email security incidents that occur within their environments. The remaining 90% are incidents, like misdirected attachments, unencrypted PII, and lookalike domain impersonation attacks, go completely undetected. 

Most sensitive data loss isn't the result of a malicious insider plotting corporate espionage. It’s driven by well-meaning employees making simple, everyday mistakes under pressure. Typing a name too quickly into Outlook's autocomplete and routing a payroll spreadsheet to someone in Sales and not an external vendor, is all it takes to trigger a massive compliance violation.

To erase this visibility gap and hand control back to IT administrators, KnowBe4 is proud to announce the launch of two powerful, self-serve features in our Prevent Standard offering: the DLP rule builder and misdirected content analysis. By deploying these self-serve outbound features in the Standard offering, we are completely removing the enterprise-tier paywalls and expensive professional services requirements that historically kept these tools out of reach for the small and mid-market organizations.

The Frustrating Reality of Legacy Outbound Email Security

Historically, trying to solve outbound data leakage and misdirected emails has left small to mid-sized organizations stuck between two highly frustrating extremes:

  1. The Passive Trap: Relying solely on retrospectively reviewing audit logs or waiting for an employee to courageously self-report a mistake. By the time an admin notices the error, the data is already out in the wild and a compliance violation might already be headed for your organization.

  2. The Costly Expense: Critical DLP and relationship-aware matching have traditionally been tightly gated behind top-tier, expensive licensing suites (like Microsoft E5) or required weeks of costly third-party professional services to deploy and manage.

With Prevent, admins can now configure their DLP policies in a matter of minutes with no specialized support required.

Dual-Layer Defense: What’s New in KnowBe4 Prevent Standard

With today's release, Prevent Standard users gain access to two distinct, complementary layers of outbound protection:

  1. Prevent DLP Rule Builder: Autonomy Without Alert Fatigue: Admins can now independently build, customize, and manage sophisticated rules to block unauthorized emails containing structured sensitive data like PII, financial records, and medical data.

    • Score-Based Triggers: To eliminate the crippling alert fatigue caused by legacy tools, our builder utilizes advanced scoring thresholds. Instead of triggering a noisy, global block every time a single account number is mentioned, you can configure rules to only intervene if multiple high-risk data attributes are flagged together.

    • Compliance-Ready Controls: SOC teams can easily self-configure rules to stop unauthorized external communication, ensuring audit-readiness for strict regulations like HIPAA, GDPR, and PCI-DSS on their own terms.

2. Misdirected Content Analysis: The Right Information to the Right Person

Standard email filters only look at static text blocks. Prevent’s misdirected content analysis operates alongside the user, learning the unique communication DNA of your organization to understand true recipient relationships.

    • Context-Aware Protection: The system monitors for recipient anomalies and content mismatches. Even if an external email address is technically valid, the system catches near-miss errors if the attachment type or text context has never historically been shared with that specific recipient.

    • Bespoke Identifier Training: Admins aren't limited to generic templates. You can paste custom text-matching patterns directly into the UI, such as industry-specific Case IDs, Project Codes, or Client Numbers, to train the algorithm on data patterns unique to your business.

Turning Near-Miss Mistakes into Teachable Moments

Other outbound security tools push users out of the loop, creating frustration without changing behavior. KnowBe4 takes a human-centric approach.

When an employee attempts to send an email that breaches a custom DLP rule or exhibits a recipient mismatch, Prevent intervenes at the exact point of send. Before the email leaves the environment, the user is presented with a real-time, contextual nudge directly inside Outlook or OWA explaining why the flag occurred.

Our data shows that content-related nudges are 2 to 3 times more likely to be accepted by end-users. By showing the user exactly why an interaction is risky, we actively correct the human behavior behind the mistake, improving security proficiency over time.