A decade of email security

A decade of email security
(Image credit: Shutterstock)

Flaws in email security are a leading cause of cybersecurity attacks for many organizations. Whether it's ransomware, business email compromise (BEC) attacks, or a phishing email that leads to cybercriminals gaining access to sensitive data, email is the common denominator.

About the author

Peter Goldstein, chief technology officer and co-founder, Valimail.

According to Google, the average phishing campaign lasts only 12 minutes, making traditional tracing or blocking specific servers less effective and stopping attacks more challenging than ever. Stopping phishing attacks during the global pandemic is even more vital, as we’ve seen email use increase coupled with work from home, creating an even bigger attack surface, This has encouraged hackers to use email as a primary attack vector. Out of all the many vulnerabilities, unauthenticated email domains allowing bad actors to impersonate a person or an organization are the most common, along with being highly unethical, and extremely difficult to detect.

The reality is email security isn’t going away. Here are some of the old and new email requirements taking precedence within the ecosystem, making the simple act of opening an email a less risky proposition.

Email security ten years ago

Email is one of the most successful communications mediums ever invented and its reach continues to grow. Almost 300 billion emails are sent worldwide every day and the number of worldwide users increases at a rate of 3 percent per year. Unfortunately, email is not ready for today’s threats, because it was designed nearly 50 years ago when its current global reach and security challenges were unimaginable. 

In this simpler time, email was sent from a company’s email server, it wasn’t as integrated into business operations, and email receivers were less experienced and less suspicious of the emails they acquired. As a result, hackers didn’t spend as much time and effort disguising their identity. Decades of work by the email industry has mostly contained spam, but phishing and email-based viruses remain massive threats, with email involved in over 90 percent of all cyberattacks. 

Email security today

This notion of securing your email server has changed drastically, especially over the last decade. It no longer makes sense to ask “how do I secure email?” Email insiders are busy developing standards aimed at addressing email’s biggest weakness: that anyone can send an email impersonating someone else. In fact, 89% of all phishing attacks have one thing in common - the sender is not who or what they claim to be. With more effective sender identity management protections in place, we can eliminate these frauds by placing a focus on sender-based email security and email authentication with DMARC.

The standards shaping the future of email are progressively requiring it. This cuts off the majority of email attacks by blocking the most dangerous forms of phishing before anyone has a chance to click on them. It’s also crucial to maintain quality security hygiene by mandating multifactor authentication (MFA) for email accounts as well as all corporate applications. This considerably reduces the risk of account takeover in the event that an employee does get phished.

Security is no longer about building walls around a physical presence. Instead, companies need to secure its brand and domain outside of those 4 walls. This starts with security enhancements like MFA and encryption becoming a top priority for companies today. With so many people working remotely and needing to trust the system, the industry should have at least a basic, minimum email security standard in place and it all starts with DMARC.

  • Peter is an MIT and Stanford-trained technologist who has worked in a variety of software verticals, including security, enterprise, email and video. He has built products and teams at a number of large technology companies, such as RSA Security and Perot Systems, as well as at small startups, like Tout, Securant and Swapt..

Peter Goldstein, chief technology officer and co-founder, Valimail.

Read more
Security padlock in circuit board, digital encryption concept
MFA alone won’t protect you in 2025: the new cybersecurity imperative
A fish hook is lying across a computer keyboard, representing a phishing attack on a computer system
Everything you need to know about phishing
Representational image of a hacker
Email scams vs Phishing - is there a difference?
A digital representation of a lock
Exploits on the rise: How defenders can combat sophisticated threat actors
Man holding a mobile phone with warning notification and spam message icon
Businesses received over 20 billion spam emails this year
Hands typing on a keyboard surrounded by security icons
Your passwords aren't the key to protecting your online identity, your email address is
Latest in Security
A laptop with a red screen with a white skull on it with the message: "RANSOMWARE. All your files are encrypted."
Major ransomware attack sees Tata Technologies hit - 1.4TB dataset with over 730,000 files allegedly stolen
Security
Broadcom releases fixes for multiple VMware security flaws
A graphic showing fleet tracking locations over a city.
Lost & Found tracking site hit by major data breach - over 800,000 could be affected
US President Donald Trump speaks to the press as he signs an executive order to create a US sovereign wealth fund, in the Oval Office of the White House on February 3, 2025, in Washington, DC.
US set to pause cyber-offensive operations against Russia - but CISA says it won't stop
Web DDoS attacks see major surge as AI allows more powerful attacks
Polish space agency says it was hit by a cyberattack
Latest in News
Microsoft UK CEO Darren Hardman AI Tour London 2025
Microsoft - UK can help drive the global AI future, but only with the proper buy-in
Asus Prime OC RTX 5070 graphics card with three fans, shown at an angle
Asus reveals Nvidia RTX 5070 launch pricing, and while one model is at MSRP – thankfully – the others make me want to give up my search for a next-gen GPU
Philips Hue lights being dimmed
Got Philips Hue lights? A free app update delivers these 3 improvements
iPad Air M3
The new iPad Air M3 is good value – but I’d still buy this iPad Pro model instead
Samsung Galaxy Z Fold 6
Samsung shows off a creaseless folding phone display – and it improves on the Galaxy Z Fold 6 design in 3 key ways
A piece of paper with the words 'an HBO Original film' on it next to a pile of snow
Jesse Armstrong’s next HBO Original sounds like another Succession-style satire starring Steve Carrell and Jason Schwartzman