Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Why Prediction, And Not Detection, Is The Key To Reducing Email Risk
Articles

Why Prediction, And Not Detection, Is The Key To Reducing Email Risk

ISBuzz TeamBy ISBuzz TeamMay 3, 2019Updated:July 4, 20245 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Email Security Risks
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

According to the Global Risk Report by the World Economic Forum, the threat of cyberattacks are now among the top three global fears identified by world economic leaders, along with natural disasters and terrorism. Such concerns are clearly warranted, as research from Juniper suggests that cyber breaches will cost businesses a collective $2 trillion in 2019 alone. 

As the threats multiply and grow more complex with increasingly burdensome consequences, many organizations remain in constant search of new tools, technologies and best practices to reduce risk. This is especially true for email security and phishing mitigation, as email remains the primary attack vector, with an estimated 90% of attacks initiating in the inbox. 

For years, most email security has been focused on detection, either by humans via phishing awareness training, or by machines, that scan messages at the gateway in search of links, attachments and other attributes common among malicious messages. Both approaches have had some success in mitigating email-driven attacks; however, attacker ingenuity has propelled them to evolve their techniques specifically to defeat these controls. 

Today, organizations that primarily rely on detection-based email security are putting their company and employees at great risk. While detection tools will continue to reveal some of the most obvious phishing attacks, techniques such as business email compromise and domain spoofing will increasingly slip through the cracks. 

Therefore, it is imperative for organizations to implement a predictive security posture as a means to proactively identify attacks and rapidly respond to threats before any business disruption can occur. 

Limitations of detection-based strategies 

The most common detection-based strategies, including secure email gateways (SEGs) and Domain-based Message Authorization System (DMARC) can identify many known threats, and they should certainly be a part off any security solution.

But we’re no longer living in the days of cookie-cutter attacks where simple filters and rules-based security solutions can cover all risks. Detection-based solutions have many limitations because they rely on information about known threats but are often powerless to identify the unknown. As such solutions are binary, static and purely content based, they are prone to missing small attack changes and permutations. In fact, many detection tools cannot adapt to the slightest alteration of code and are blind to context and advanced authentication capabilities. 

Access to black market tools, including AI-enabled programs and cloud-based automated PaaS (phishing as a service) solutions, are making it easier than ever for attackers to construct attacks that bypass SEGs and DMARC. But even when detection tools are successful, remediation is often not quick enough. In today’s threat landscape, it takes less than 82 seconds until the first click is lured, according to Aberdeen. 

The value of predictive email security 

Predictive technology is the use of machine learning to calculate with confidence a future event, thereby empowering organizations to proactively prepare for trending email phishing attacks. In fact, threat prediction can help businesses use data to prepare for what the next attack will look like and augment it to make it actionable, so to proactively prevent similar or trending attacks from infiltrating or repeat attacks from occurring. 

The use of predictive technology may be new to email security, yet it is not new to the broader cybersecurity industry. In fact, leading endpoint detection and response (EDR) platforms have utilized machine learning and AI to predict malware for the past several years. 

But for email specifically, predictive technology must be based on real-time decisions done by real human experts on a minutely basis. For busy security and SOC teams, the capacity to predict future events with a high-level of certainty is a potential resource savior, as many in security roles are overworked and overwhelmed with a growing number of investigations into suspicious emails. 

As cybercriminals constantly exploit email vulnerabilities and create new attack methods, organizations must process threat data as quickly as possible. Propelled by machine learning, predictive technology can cluster similar instances of an attack across an entire organization. This can save hundreds of hours of work by turning multiple permutations into a single incident, offering the ability to quarantine that incident across the entire organization. Clustering also prevents repeat attacks from being delivered, saving time in identifying other threats and reducing possible damage. 

Predictive technologies can also supplement network-driven data with actual human behavior and insight. Combining the two can enable SOC and security teams to create a historical portrait of how a phishing attack might look and how to alert employees before they fall for the bait. It’s a more forward-looking and proactive approach to detect anomalies and identify patterns in real-time to identify where an organization’s weak points are and where attackers may strike next. 

Organizations that only try to detect based on yesterday’s attacks will remain at great risk. In our whack-a-mole security environment, predicting the next attack is the only way to stay ahead of the disruption that comes with any successful email security incident. 

 

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

New Phishing Kit Starkiller Defeats Multi-Factor Authentication

February 23, 20264 Mins Read

ReliaQuest Uncovers Social Media Phishing Campaign Built on Trusted Tools

January 22, 20266 Mins Read

What Happens after a Phishing Email Lands in Your Inbox?

January 5, 20266 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}