In a recent SC Media webcast, host Adrian Sanabria, along with guests Dan Nickolaisen of Abnormal AI and Alexander Kisilev of Lundin Mining, explored how to rethink email security for modern enterprises.The three discussed the evolution of email threats, the limitations of traditional secure email gateways (SEGs), how AI and automation fuel attacker capabilities, and how next-generation email security solutions benefit operations and user experiences.Nickolaisen explained that SEGs originally functioned as frontline filters for unwanted or malicious emails — in other words, spam filters. But he said SEGs later evolved to combat malicious attachments, URLs, and links.Yet today, he added, email-based threats outpace traditional defenses. Social-engineering messages, such as those used for business email compromise, can often slip past payload-based filters because they contain no typical malicious signatures or attachments. They're just cleverly crafted messages that fool recipients into taking unwise actions, like making fraudulent payments.Kisilev described how adversaries leverage generative AI to craft more convincing phishing emails. Classic signs of phishing, such as spelling errors, have become less reliable indicators."Thanks to the proliferation and the wide availability of GenAI, we see that spelling mistakes are not a thing anymore," Kisilev explained. "As a matter of fact, in order to sound more human, sometimes you ask AI to make mistakes."Defenders must now look beyond static rules and patterns. At Lundin Mining, Kisilev said, resource constraints necessitated tools that could deliver gains in efficiency and effectiveness.The key benefit of adopting of Abnormal AI's solution, he said, was not just technical. It was also about transforming how phishing emails were reported, handled and responded to, improving both the user perception of IT and actual security posture.Prior to AI integration, Kisilev said, phishing reports sent by users often disappeared into a black hole. With Abnormal AI's assistance, responses were almost immediate."Now we get a response almost immediately, and people are realizing, 'Oh, somebody is actually responding to me with some valuable information,'" he said.Nickolaisen pointed out that today's phishing techniques often exploit legitimate platforms like Microsoft SharePoint, Canva, or Adobe Sign while using compromised accounts that pass standard authentication checks, making detection even harder.Traditional defenses, like sandboxing suspicious links, often fail as attackers use multi-step payloads or hide malicious intent by steering the user through legitimate platforms.Recent research indicated that the average lifespan of phishing infrastructure has dropped from about 24 hours several years ago to just a couple of hours today, he added."The infrastructure does not last for very long in the first place," Nickolaisen said. "Because a lot of it is abusing a number of different legitimate services, it's extremely difficult to detect and identify based on those traditional techniques."He detailed how Abnormal AI uses thousands of data signals to create a baseline model of normal communication patterns for each user, throwing into relief subtle deviations that might signal potential threats and augmenting detection through threat intelligence and heuristics.Nickolaisen and Kisilev touted other benefits of Abnormal AI, including how it boosts operational efficiency and shrinks workloads for both end-users and security teams. At Lundin Mining, it created a massive reduction in the hours spent managing email security, Kisilev said.At the end of the discussion, Kisilev said that security tools seemed to be moving away from traditional block-rate metrics to a quieter operational status in which a lack of incidents can constitute success.Nickolaisen laid out what prospective buyers of next-gen email security should look for: deep behavioral profiling across vast data sets, contextual risk assessment, and a willingness to measure efficiency gains. All three are vital when even a 1% failure rate can add up to thousands of incidents.Key takeaways for security practitioners:
- Generative AI has drastically increased the sophistication and scale of phishing and business email compromise, erasing traditional signals and creating new challenges for defenders.
- Traditional secure email gateways (SEGs) block most obvious threats, but the latest attacks use social engineering, legitimate services, and AI-powered tactics, making behavioral and contextual analysis essential for detection.
- Modern AI-powered solutions such as Abnormal AI not only improve protection through behavioral profiling and anomaly detection but also transform user experience and operational efficiency.




