Email Security
A Cyber SaaS Analysis 2026Threat Context
How email exploits are evolving in Australia.
Security Outcomes Video
What Australian IT leaders prioritise when choosing an email security solution.
Product Landscape
17 leading vendors benchmarked on The Tekspace Cyber Continuum™.
Conclusion
Key takeaways, future outlook, and how to act on this research.
What’s actually landing in your inbox. This is Tekspace’s first publicly released assessment.
Email doesn’t sit at the edge of a business, it sits at the centre of it. Supply chain conversations, hiring decisions, financial approvals, the day-to-day traffic of how a company actually runs, all of it moves through someone’s inbox. That is what makes it worth defending properly, and it is also why most organisations are less protected than they assume.
We have spent years inside the systems that keep Australian businesses secure, running proof-of-concepts against live environments and seeing, again and again, what a well-configured Microsoft or Google tenant still lets through. Until now, that research stayed in-house, shaping the recommendations we made client by client rather than the market as a whole.
This report changes that. In collaboration with our partners, we look at email as a threat vector, study what businesses actually need from an email security solution, and evaluate the leading vendors in the space.
Thank you to Parabellum, ASI Solutions, Securelogic and the team behind the scenes (see Addendum for credits). Together, this work helps us deliver on our focus to protect people and data with simple, impactful cybersecurity.
Phishing was the single largest cause of cyber incident data breaches notified to the OAIC in the second half of 2024, at 34%.1
It is tempting to picture the people behind those breaches as state agencies. A few are. Most are not. They are criminal businesses, run for profit, using email as a low-barrier, high-yield route to initial access, reconnaissance and persistence. The aim is simple: get into an organisation at scale, take money, and move to the next one. That reframing matters, because it tells you what you are actually defending against day to day.
Email is their default for the same reason a burglar tries the back door before the front. It is the most common way in, and it is rarely locked properly. As a keystone of communication, it is also a delivery mechanism for malware, credential harvesting and social engineering, and that risk is rising.
ASD’s Annual Cyber Threat Report 2024-25 found business email compromise fraud made up 15% of cybercrime reports from Australian businesses, up from 13% the year before. Total BEC losses reported by large businesses rose 138%.2
Email threats are on the rise in Australia as attackers exploit both trust and technology, Australian businesses are under real pressure to secure their email environments.
Email compromise leads what businesses report
-
19%
Email compromise
Without financial loss.
-
15%
Business email compromise fraud
With financial loss.
-
11%
Identity fraud
Other report types not shown. Bars are drawn to scale, on a 0 to 100% axis.2
What generative AI changed is not whether these attacks happen, but how cheaply they can be run well. Profiling a target used to take days of manual research; now it’s automated and close to free, making campaigns cheaper, faster and far more convincing.
If your protection begins and ends with Microsoft or Google’s own defaults, you are very likely already receiving mail that should never have reached an inbox.
Email security vendor AegisAI analysed more than 20,000 phishing emails and found AI-written lures got past Gmail and Microsoft’s native filters 50.3% of the time, against 28.5% for human-written ones.3 That native protection is still built to judge a message once, at the point it arrives, then move on.
The cost of not looking
Average self-reported cost of a cybercrime report from an Australian business.2
Global median dwell time before a breach surfaces, up from 11.4
Median time between initial access and hand-off to a second threat group in 2025, down from more than eight hours in 2022.4
Where legacy filters fall short
The most common thing we find is that organisations do not know how much is already reaching their people. A monitoring pass over a live environment will pick up the data you need: malicious mail already sitting in real inboxes, often addressed to the same handful of people every time.
That gap, between what a team believes is getting through and what actually is, is the problem a dedicated email security layer exists to close. Network and endpoint tools were never built to see inside the inbox. Comprehensive email security products can.
Does your team have visibility of the dangerous mail that’s already getting through? For most, the honest answer is no. Legacy filters are built to look once, at the moment a message arrives, and a link that only turns malicious after it lands beats them easily. The four patterns below are built around that single blind spot.
Mid-Campaign Defence Response
Attackers adapt as scanners improve, favouring links because the payload can change after the email lands. VIPRE’s Q1 2026 report, covering 1.8 billion emails, found attackers increasingly hiding behind trusted platforms: over 89% of phishing URLs started on a legitimate domain before redirecting.5
AI Deepfake Hybrids
Email scams paired with AI-generated voice or video: an email that appears to come from the CFO, then minutes later a voice note in the CFO’s own cadence confirming the transfer.
Chained Quishing
QR codes that route a target through several staged sites, slipping past filters. Abnormal Security’s H1 2024 threat report found C-suite executives 42 times more likely than other staff to receive QR code phishing attacks.6
Polymorphic AI Payloads
Malicious emails that use AI to rewrite themselves so they look different every time, defeating signature detection. And AI-written lures land: in a 2024 study of 101 people, fully AI-automated spear phishing emails got a 54% click-through rate, matching human experts, against 12% for generic phishing.7
Catching these attacks takes filtering mature enough to keep watching a message and its outcome all the way through the flow. Only a handful of the products assessed here can do that.
Security Outcomes
With the threat context as a backdrop, what do information technology professionals prioritise when considering a new email security solution?
- Frank De Pasquale, Chief Executive Officer at Tekspace
- Matt Flack, Chief Services Officer at ASI Solutions
- Francisco Vera, Managing Director at Securelogic Solutions
What matters in your assessment? Whatever the domain, a security product earns its place against the same four outcomes. Expand each to see how we assess the email security category.
Efficacy
- Phishing, account takeover and payload detection across inbound, internal and outbound mail
- Links and attachments reassessed after delivery, not only on the way in
- Efficacy provable in your own environment through a monitor-only trial
Operational Efficiency
- False positives low enough that release requests stay manageable
- Confirmed threats triaged and removed without per-message handling
- SPF, DKIM and DMARC managed in the platform rather than as separate work
Reporting and Analytics
- Threat and incident detail an administrator can act on directly
- Executive-readable summaries that evidence return on the spend
- Audit trails and breach alerting retained for investigation
User Experience
- Click-time protection applied without a delay users notice
- Self-service quarantine review, so releases do not queue at the service desk
- Encryption and access revocation available to senders without specialist steps
Product Landscape
We’ve ranked 17 solutions, the market leaders and strong emerging players in email security, on the Tekspace Cyber Continuum™ to show what makes the top platforms so effective for buyers. It’s the architecture underneath that separates the leaders.
Focused
See Vendors and FeaturesFocused
- Mesh
- HornetsecurityVade
- Graphus
- Material
- Sublime
Features
- Access Management
- Advanced Threat Protection (ATP)
- Anti-Malware
- Anti-Phishing
- Anti-Spam
- Incident Data Management
- Allow and Block Lists
- Breach Detection Alerts
- Activity Monitoring / Auditing
- Compliance
- Safe Banners
- Autonomous Task Execution
- (AI) Proactive Assistance
- Internal to Internal Monitoring
- Quarantine
Broad
See Vendors and FeaturesBroad
- Sophos
- Paubox
- SpamTitan
- Ironscales
- Cloudflare
- Mimecast
- Barracuda
- Proofpoint
Features
- Account Takeover Prevention
- Threat Intelligence Reporting
- Targeted Attack Prevention
- Email Archiving
- Single Sign-On
- Outbound Email Monitoring
- Policy Enforcement
- Real-Time Detection
- Reporting and Monitoring (General)
- API-based Architecture
- Email Encryption
- Data Loss Prevention
Comprehensive
See Vendors and FeaturesComprehensive
- KnowBe4Egress
- Darktrace
- Abnormal
- Check PointHarmony
Features
- (AI) Adaptive Learning
- Data Exfiltration Detection
- Reporting (User Management)
- Digital Signatures
- End User Self Service Quarantine
- URL Re-Writing and Sandboxing
- DMARC, SPF and DKIM Management
- Reporting and Monitoring (Encryption)
- APIs and SDKs
- SMTP Mail Relay
- User-Controlled Email Access Revocation
- (AI) Anomaly Detection
To build it, we collated 400+ disparate features across the seventeen vendors, normalising them down to 39 scored features in 12 capability groups, each group sitting under one of the four outcomes above, so vendors are compared like for like rather than on the size of their marketing claims.
Want to know which of these fits your environment? We help with that.
A logo on a chart does not tell you whether the tool holds up against the phishing your people actually receive, or how much your team ends up releasing by hand.
Book your sessionConclusion
Email is where cybersecurity strategy for most Australian organisations begins.
The threat landscape keeps shifting, and the product you choose has a material impact on whether your business stays ahead of it. Efficacy, operational efficiency, reporting and analytics, and user experience are the four outcomes that separate the most effective solutions from the rest.
The gaps this report opened with do not close on their own. Network and endpoint tools were never built to see inside the inbox, and a filter that only looks once, at the moment a message arrives, misses the link that turns malicious after it lands. Closing both takes a solution built to keep watching a message all the way through, not just at the door.
It is also why native protection alone does not settle the question. Even at the most expensive tier Microsoft or Google sell, some malicious mail still gets through. So when we meet a business running nothing beyond the defaults, or nothing configured at all, on the exact channel that starts most Australian breaches, it is a genuinely hard thing to reconcile.
An opportunity to test it, not trust it.
You do not have to take our word for any of this. Run a solution in monitor-only mode against your own environment and, within days, you will see exactly what is reaching your people that should not be. We hope this research helps you make deliberate, not reactive, choices.
We're fielding this exact call right now, as BEC attempts keep climbing and email contracts come up for renewal this quarter. When you're ready to pressure-test that choice against your own environment, you can book time with Tekspace directly.
Addendum
Credits
In launching this report, Tekspace would like to acknowledge contributions from the following teams and individuals.
Contributors
- Lead Analysts — Frank De Pasquale, CEO at Tekspace.
- Threat Context — Martin Dybalski, Director; Stuart Shanahan, Director of Technical Services; and Kris Bowen, Senior Offensive Security Consultant, all at Parabellum.
- Security Outcomes — Francisco Vera, Managing Director at Securelogic Solutions; and Matt Flack, Chief Services Officer at ASI Solutions.
- Research and analysis by the Tekspace Research team.
References
- Office of the Australian Information Commissioner (2025), Notifiable Data Breaches Report: July to December 2024, Table 3 (phishing, compromised credentials, caused 84 of the 247 cyber incident breaches).
- Australian Signals Directorate (2025), ASD Annual Cyber Threat Report 2024-25 (business cybercrime report types, p.14: email compromise without financial loss 19%, business email compromise fraud 15%, up from 13%, identity fraud 11%; large-business BEC losses up 138%; $80,850 average self-reported cost per business report).
- AegisAI (2026), State of the AI Threat in Email: 2025 (the vendor’s own analysis of more than 20,000 phishing emails; AI-written lures got past native Gmail and Microsoft filtering 50.3% of the time, human-written ones 28.5%).
- Mandiant / Google Cloud (2026), M-Trends 2026 (global median dwell time 14 days, up from 11; median time from initial access to hand-off to a second threat group 22 seconds in 2025, down from more than eight hours in 2022).
- VIPRE Security Group (2026), Q1 2026 Email Threat Trends Report (1.8 billion emails analysed; over 89% of phishing URLs started on a legitimate domain before redirecting).
- Abnormal Security (2024), H1 2024 Phishing Frenzy: C-suite receives 42x more QR code attacks than average employee.
- Heiding, Lermen, Kao, Schneier and Vishwanath (2024), Evaluating Large Language Models’ Capability to Launch Fully Automated Spear Phishing Campaigns: Validated on Human Subjects, arXiv:2412.00586 (101 participants; fully AI-automated spear phishing 54% click-through, matching human experts; generic phishing 12%).
Email Security category
What this report does and doesn’t claim to cover, how we compare products fairly, and what to do if you still have questions.
Scope
Tekspace’s Email Security Cyber SaaS Analysis 2026 is not an exhaustive survey of every email security product in Australia. Instead, it focuses on solutions that are widely regarded as either market leaders, or strong emerging players.
Feature Granularity Model
We compare products at what we call Level 2: The Functional Group: specific enough to be meaningful, broad enough to compare very different products fairly, without losing sight of how they're meaningfully different.
Further questions
Why isn’t Microsoft or Google’s built-in protection enough on its own?
Native protection has to be good at hundreds of things, not just at stopping email attacks specifically. It catches well-known threats reliably, but as this report’s threat context shows, a meaningful share of dangerous mail still gets through native filtering alone, which is why a dedicated layer exists.
How is this different from a traditional secure email gateway (SEG)?
A traditional SEG sits in front of mail flow and filters on the way in, so every rule change risks disrupting delivery. The platforms in this report connect by API instead, reading mail without sitting in the direct path, and in the strongest cases analysing it before it ever reaches an inbox rather than pulling it back out after the fact.
How were the 17 vendors in this report actually compared?
We normalised the market down to 39 scored features and assessed each vendor at what we call the Functional Group level: specific enough to be meaningful, broad enough to compare very different products fairly. See Feature Granularity Model above for how that scale works.
One of these vendors has been acquired since publication. Does that change the findings?
Vade was acquired by Hornetsecurity and appears here as Hornetsecurity Vade. It was assessed as a standalone product and has not been reassessed since. What changes is how you buy it, not what it was found to do. Where a product has been folded into a larger platform, check the packaging and commercial terms before comparing it against a standalone tool.
What happens if I want another vendor assessed?
Get in touch. This report focuses on solutions widely regarded as market leaders or strong emerging players, not every product on the market, and we are glad to look at ones we have not yet covered.
Disclaimers
Findings reflect our professional judgement at the time of publication, based on the data available to us. Product capabilities and roadmaps change, so organisations should treat this report as a guide to practical decision making, not as a substitute for their own due diligence.
If you have identified errors in this report, or wish to have another product assessed, please contact our team.
Contact our teamWe'll connect you with the right people
Vendors see your organisation's size and industry, never your name or contact details.
By making an enquiry you agree to Tekspace contacting you about it and sending related research. Unsubscribe any time. Privacy