Tekspace Research

Email Security

A Cyber SaaS Analysis 2026
New domain assessments as they publish. Unsubscribe any time, and we never share or sell your data.

What’s actually landing in your inbox. This is Tekspace’s first publicly released assessment.

Email doesn’t sit at the edge of a business, it sits at the centre of it. Supply chain conversations, hiring decisions, financial approvals, the day-to-day traffic of how a company actually runs, all of it moves through someone’s inbox. That is what makes it worth defending properly, and it is also why most organisations are less protected than they assume.

We have spent years inside the systems that keep Australian businesses secure, running proof-of-concepts against live environments and seeing, again and again, what a well-configured Microsoft or Google tenant still lets through. Until now, that research stayed in-house, shaping the recommendations we made client by client rather than the market as a whole.

This report changes that. In collaboration with our partners, we look at email as a threat vector, study what businesses actually need from an email security solution, and evaluate the leading vendors in the space.

Thank you to Parabellum, ASI Solutions, Securelogic and the team behind the scenes (see Addendum for credits). Together, this work helps us deliver on our focus to protect people and data with simple, impactful cybersecurity.

Portrait photo of Frank De Pasquale
Frank De Pasquale
CEO at Tekspace

Threat Context

Insights from Parabellum Logo

CREST Pen Test certification badge. OffSec OSCE3 certification badge OffSec OSCE certification badge OffSec OSCP certification badge OffSec OSEP certification badge OffSec OSWE certification badge OffSec OSED certification badge OffSec OSWP certification badge OffSec OSAI certification badge

Phishing was the single largest cause of cyber incident data breaches notified to the OAIC in the second half of 2024, at 34%.1

It is tempting to picture the people behind those breaches as state agencies. A few are. Most are not. They are criminal businesses, run for profit, using email as a low-barrier, high-yield route to initial access, reconnaissance and persistence. The aim is simple: get into an organisation at scale, take money, and move to the next one. That reframing matters, because it tells you what you are actually defending against day to day.

Email is their default for the same reason a burglar tries the back door before the front. It is the most common way in, and it is rarely locked properly. As a keystone of communication, it is also a delivery mechanism for malware, credential harvesting and social engineering, and that risk is rising.

ASD’s Annual Cyber Threat Report 2024-25 found business email compromise fraud made up 15% of cybercrime reports from Australian businesses, up from 13% the year before. Total BEC losses reported by large businesses rose 138%.2

Email threats are on the rise in Australia as attackers exploit both trust and technology, Australian businesses are under real pressure to secure their email environments.

Share of business cybercrime reports to ASD · FY2024-25

Email compromise leads what businesses report

  1. Email compromise

    Without financial loss.

    19%
  2. Business email compromise fraud

    With financial loss.

    15%
  3. Identity fraud

    11%

Other report types not shown. Bars are drawn to scale, on a 0 to 100% axis.2

What generative AI changed is not whether these attacks happen, but how cheaply they can be run well. Profiling a target used to take days of manual research; now it’s automated and close to free, making campaigns cheaper, faster and far more convincing.

If your protection begins and ends with Microsoft or Google’s own defaults, you are very likely already receiving mail that should never have reached an inbox.

Email security vendor AegisAI analysed more than 20,000 phishing emails and found AI-written lures got past Gmail and Microsoft’s native filters 50.3% of the time, against 28.5% for human-written ones.3 That native protection is still built to judge a message once, at the point it arrives, then move on.

The cost of not looking

ASD, FY2024-25 $80,850

Average self-reported cost of a cybercrime report from an Australian business.2

Mandiant M-Trends 2026 14 days

Global median dwell time before a breach surfaces, up from 11.4

Mandiant M-Trends 2026 22 seconds

Median time between initial access and hand-off to a second threat group in 2025, down from more than eight hours in 2022.4

Where legacy filters fall short

The most common thing we find is that organisations do not know how much is already reaching their people. A monitoring pass over a live environment will pick up the data you need: malicious mail already sitting in real inboxes, often addressed to the same handful of people every time.

That gap, between what a team believes is getting through and what actually is, is the problem a dedicated email security layer exists to close. Network and endpoint tools were never built to see inside the inbox. Comprehensive email security products can.

Does your team have visibility of the dangerous mail that’s already getting through? For most, the honest answer is no. Legacy filters are built to look once, at the moment a message arrives, and a link that only turns malicious after it lands beats them easily. The four patterns below are built around that single blind spot.

Four patterns · Australian inboxes 2025-26

Mid-Campaign Defence Response

Attackers adapt as scanners improve, favouring links because the payload can change after the email lands. VIPRE’s Q1 2026 report, covering 1.8 billion emails, found attackers increasingly hiding behind trusted platforms: over 89% of phishing URLs started on a legitimate domain before redirecting.5

AI Deepfake Hybrids

Email scams paired with AI-generated voice or video: an email that appears to come from the CFO, then minutes later a voice note in the CFO’s own cadence confirming the transfer.

Chained Quishing

QR codes that route a target through several staged sites, slipping past filters. Abnormal Security’s H1 2024 threat report found C-suite executives 42 times more likely than other staff to receive QR code phishing attacks.6

Polymorphic AI Payloads

Malicious emails that use AI to rewrite themselves so they look different every time, defeating signature detection. And AI-written lures land: in a 2024 study of 101 people, fully AI-automated spear phishing emails got a 54% click-through rate, matching human experts, against 12% for generic phishing.7

Catching these attacks takes filtering mature enough to keep watching a message and its outcome all the way through the flow. Only a handful of the products assessed here can do that.

Security Outcomes

With the threat context as a backdrop, what do information technology professionals prioritise when considering a new email security solution?

  • Frank De Pasquale, Chief Executive Officer at Tekspace
  • Matt Flack, Chief Services Officer at ASI Solutions
  • Francisco Vera, Managing Director at Securelogic Solutions

What matters in your assessment? Whatever the domain, a security product earns its place against the same four outcomes. Expand each to see how we assess the email security category.

1

Efficacy

  • Phishing, account takeover and payload detection across inbound, internal and outbound mail
  • Links and attachments reassessed after delivery, not only on the way in
  • Efficacy provable in your own environment through a monitor-only trial
2

Operational Efficiency

  • False positives low enough that release requests stay manageable
  • Confirmed threats triaged and removed without per-message handling
  • SPF, DKIM and DMARC managed in the platform rather than as separate work
3

Reporting and Analytics

  • Threat and incident detail an administrator can act on directly
  • Executive-readable summaries that evidence return on the spend
  • Audit trails and breach alerting retained for investigation
4

User Experience

  • Click-time protection applied without a delay users notice
  • Self-service quarantine review, so releases do not queue at the service desk
  • Encryption and access revocation available to senders without specialist steps

Product Landscape

We’ve ranked 17 solutions, the market leaders and strong emerging players in email security, on the Tekspace Cyber Continuum™ to show what makes the top platforms so effective for buyers. It’s the architecture underneath that separates the leaders.

Focused

  • Mesh Icon
    Mesh
  • Hornetsecurity Vade Icon
    HornetsecurityVade
  • Graphus Icon
    Graphus
  • Material Icon
    Material
  • Sublime Icon
    Sublime

Features

  • Access Management
  • Advanced Threat Protection (ATP)
  • Anti-Malware
  • Anti-Phishing
  • Anti-Spam
  • Incident Data Management
  • Allow and Block Lists
  • Breach Detection Alerts
  • Activity Monitoring / Auditing
  • Compliance
  • Safe Banners
  • Autonomous Task Execution
  • (AI) Proactive Assistance
  • Internal to Internal Monitoring
  • Quarantine

Broad

  • Sophos Icon
    Sophos
  • Paubox Icon
    Paubox
  • SpamTitan Icon
    SpamTitan
  • Ironscales Icon
    Ironscales
  • Cloudflare Icon
    Cloudflare
  • Mimecast Icon
    Mimecast
  • Barracuda Icon
    Barracuda
  • Proofpoint Icon
    Proofpoint

Features

  • Account Takeover Prevention
  • Threat Intelligence Reporting
  • Targeted Attack Prevention
  • Email Archiving
  • Single Sign-On
  • Outbound Email Monitoring
  • Policy Enforcement
  • Real-Time Detection
  • Reporting and Monitoring (General)
  • API-based Architecture
  • Email Encryption
  • Data Loss Prevention

Comprehensive

See Vendors and Features
KnowBe4 Egress Icon
Darktrace Icon
Abnormal Icon
Check Point Harmony Icon

Comprehensive

  • KnowBe4 Egress Icon
    KnowBe4Egress
  • Darktrace Icon
    Darktrace
  • Abnormal Icon
    Abnormal
  • Check Point Harmony Icon
    Check PointHarmony

Features

  • (AI) Adaptive Learning
  • Data Exfiltration Detection
  • Reporting (User Management)
  • Digital Signatures
  • End User Self Service Quarantine
  • URL Re-Writing and Sandboxing
  • DMARC, SPF and DKIM Management
  • Reporting and Monitoring (Encryption)
  • APIs and SDKs
  • SMTP Mail Relay
  • User-Controlled Email Access Revocation
  • (AI) Anomaly Detection

To build it, we collated 400+ disparate features across the seventeen vendors, normalising them down to 39 scored features in 12 capability groups, each group sitting under one of the four outcomes above, so vendors are compared like for like rather than on the size of their marketing claims.

Want to know which of these fits your environment? We help with that.

A logo on a chart does not tell you whether the tool holds up against the phishing your people actually receive, or how much your team ends up releasing by hand.

Book your session

Conclusion

Email is where cybersecurity strategy for most Australian organisations begins.

The threat landscape keeps shifting, and the product you choose has a material impact on whether your business stays ahead of it. Efficacy, operational efficiency, reporting and analytics, and user experience are the four outcomes that separate the most effective solutions from the rest.

The gaps this report opened with do not close on their own. Network and endpoint tools were never built to see inside the inbox, and a filter that only looks once, at the moment a message arrives, misses the link that turns malicious after it lands. Closing both takes a solution built to keep watching a message all the way through, not just at the door.

It is also why native protection alone does not settle the question. Even at the most expensive tier Microsoft or Google sell, some malicious mail still gets through. So when we meet a business running nothing beyond the defaults, or nothing configured at all, on the exact channel that starts most Australian breaches, it is a genuinely hard thing to reconcile.

An opportunity to test it, not trust it.

You do not have to take our word for any of this. Run a solution in monitor-only mode against your own environment and, within days, you will see exactly what is reaching your people that should not be. We hope this research helps you make deliberate, not reactive, choices.

We're fielding this exact call right now, as BEC attempts keep climbing and email contracts come up for renewal this quarter. When you're ready to pressure-test that choice against your own environment, you can book time with Tekspace directly.

Addendum

Credits

In launching this report, Tekspace would like to acknowledge contributions from the following teams and individuals.

Contributors

  • Lead Analysts — Frank De Pasquale, CEO at Tekspace.
  • Threat Context — Martin Dybalski, Director; Stuart Shanahan, Director of Technical Services; and Kris Bowen, Senior Offensive Security Consultant, all at Parabellum.
  • Security Outcomes — Francisco Vera, Managing Director at Securelogic Solutions; and Matt Flack, Chief Services Officer at ASI Solutions.
  • Research and analysis by the Tekspace Research team.

References

  1. Office of the Australian Information Commissioner (2025), Notifiable Data Breaches Report: July to December 2024, Table 3 (phishing, compromised credentials, caused 84 of the 247 cyber incident breaches).
  2. Australian Signals Directorate (2025), ASD Annual Cyber Threat Report 2024-25 (business cybercrime report types, p.14: email compromise without financial loss 19%, business email compromise fraud 15%, up from 13%, identity fraud 11%; large-business BEC losses up 138%; $80,850 average self-reported cost per business report).
  3. AegisAI (2026), State of the AI Threat in Email: 2025 (the vendor’s own analysis of more than 20,000 phishing emails; AI-written lures got past native Gmail and Microsoft filtering 50.3% of the time, human-written ones 28.5%).
  4. Mandiant / Google Cloud (2026), M-Trends 2026 (global median dwell time 14 days, up from 11; median time from initial access to hand-off to a second threat group 22 seconds in 2025, down from more than eight hours in 2022).
  5. VIPRE Security Group (2026), Q1 2026 Email Threat Trends Report (1.8 billion emails analysed; over 89% of phishing URLs started on a legitimate domain before redirecting).
  6. Abnormal Security (2024), H1 2024 Phishing Frenzy: C-suite receives 42x more QR code attacks than average employee.
  7. Heiding, Lermen, Kao, Schneier and Vishwanath (2024), Evaluating Large Language Models’ Capability to Launch Fully Automated Spear Phishing Campaigns: Validated on Human Subjects, arXiv:2412.00586 (101 participants; fully AI-automated spear phishing 54% click-through, matching human experts; generic phishing 12%).

Email Security category

What this report does and doesn’t claim to cover, how we compare products fairly, and what to do if you still have questions.

Scope

Tekspace’s Email Security Cyber SaaS Analysis 2026 is not an exhaustive survey of every email security product in Australia. Instead, it focuses on solutions that are widely regarded as either market leaders, or strong emerging players.

Feature Granularity Model

We compare products at what we call Level 2: The Functional Group: specific enough to be meaningful, broad enough to compare very different products fairly, without losing sight of how they're meaningfully different.

Further questions

Why isn’t Microsoft or Google’s built-in protection enough on its own?

Native protection has to be good at hundreds of things, not just at stopping email attacks specifically. It catches well-known threats reliably, but as this report’s threat context shows, a meaningful share of dangerous mail still gets through native filtering alone, which is why a dedicated layer exists.

How is this different from a traditional secure email gateway (SEG)?

A traditional SEG sits in front of mail flow and filters on the way in, so every rule change risks disrupting delivery. The platforms in this report connect by API instead, reading mail without sitting in the direct path, and in the strongest cases analysing it before it ever reaches an inbox rather than pulling it back out after the fact.

How were the 17 vendors in this report actually compared?

We normalised the market down to 39 scored features and assessed each vendor at what we call the Functional Group level: specific enough to be meaningful, broad enough to compare very different products fairly. See Feature Granularity Model above for how that scale works.

One of these vendors has been acquired since publication. Does that change the findings?

Vade was acquired by Hornetsecurity and appears here as Hornetsecurity Vade. It was assessed as a standalone product and has not been reassessed since. What changes is how you buy it, not what it was found to do. Where a product has been folded into a larger platform, check the packaging and commercial terms before comparing it against a standalone tool.

What happens if I want another vendor assessed?

Get in touch. This report focuses on solutions widely regarded as market leaders or strong emerging players, not every product on the market, and we are glad to look at ones we have not yet covered.

Disclaimers

Findings reflect our professional judgement at the time of publication, based on the data available to us. Product capabilities and roadmaps change, so organisations should treat this report as a guide to practical decision making, not as a substitute for their own due diligence.

If you have identified errors in this report, or wish to have another product assessed, please contact our team.

Contact our team
Close

Focused

  • Mesh Icon
    Mesh
  • Hornetsecurity Vade Icon
    HornetsecurityVade
  • Graphus Icon
    Graphus
  • Material Icon
    Material
  • Sublime Icon
    Sublime

Features

  • Access Management
  • Advanced Threat Protection (ATP)
  • Anti-Malware
  • Anti-Phishing
  • Anti-Spam
  • Incident Data Management
  • Allow and Block Lists
  • Breach Detection Alerts
  • Activity Monitoring / Auditing
  • Compliance
  • Safe Banners
  • Autonomous Task Execution
  • (AI) Proactive Assistance
  • Internal to Internal Monitoring
  • Quarantine
Close

Broad

  • Sophos Icon
    Sophos
  • Paubox Icon
    Paubox
  • SpamTitan Icon
    SpamTitan
  • Ironscales Icon
    Ironscales
  • Cloudflare Icon
    Cloudflare
  • Mimecast Icon
    Mimecast
  • Barracuda Icon
    Barracuda
  • Proofpoint Icon
    Proofpoint

Features

  • Account Takeover Prevention
  • Threat Intelligence Reporting
  • Targeted Attack Prevention
  • Email Archiving
  • Single Sign-On
  • Outbound Email Monitoring
  • Policy Enforcement
  • Real-Time Detection
  • Reporting and Monitoring (General)
  • API-based Architecture
  • Email Encryption
  • Data Loss Prevention
Close

Comprehensive

  • KnowBe4 Egress Icon
    KnowBe4Egress
  • Darktrace Icon
    Darktrace
  • Abnormal Icon
    Abnormal
  • Check Point Harmony Icon
    Check PointHarmony

Features

  • (AI) Adaptive Learning
  • Data Exfiltration Detection
  • Reporting (User Management)
  • Digital Signatures
  • End User Self Service Quarantine
  • URL Re-Writing and Sandboxing
  • DMARC, SPF and DKIM Management
  • Reporting and Monitoring (Encryption)
  • APIs and SDKs
  • SMTP Mail Relay
  • User-Controlled Email Access Revocation
  • (AI) Anomaly Detection
Get the next assessment
No vendors selected yet
Make an enquiry