Tekspace Cyber Lab Presents

Email Security

A Cyber SaaS Analysis 2026
Get future research sooner. We never share or sell your data.

An Australian-first. Real research, by real cyber operators.

Tekspace has spent years inside the systems that keep Australian businesses secure. In a market crowded with solutions that all promise protection, we know the outcomes that matter. Until now, that research has stayed in-house.

This report changes that. In collaboration with our partners, we look at email as a threat vector, study what businesses actually need from an email security solution, and evaluate the leading vendors in the space.

Thank you to Parabellum, ASI Solutions, Securelogic and the team behind the scenes (see Addendum for credits). Together, this work helps us deliver on our focus to protect people and data with simple, impactful cybersecurity.

Portrait photo of Frank De Pasquale
Frank De Pasquale
CEO at Tekspace

Threat Context

Insights from Parabellum Logo

CREST Pen Test certification badge. OffSec OSCE3 certification badge OffSec OSCE certification badge OffSec OSCP certification badge OffSec OSEP certification badge OffSec OSWE certification badge OffSec OSED certification badge OffSec OSWP certification badge

Email remains the dominant entry point for 57% of reported breaches in Australian organisations.1

It is tempting to picture the people behind those breaches as state agencies. A few are. Most are not. They are criminal businesses, run for profit, using email as a low-barrier, high-yield route to initial access, reconnaissance and persistence. The aim is simple: get into an organisation at scale, take money, and move to the next one. That reframing matters, because it tells you what you are actually defending against day to day.

Email is their default for the same reason a burglar tries the back door before the front. It is the most common way in, and it is rarely locked properly. As a keystone of communication, it is also a delivery mechanism for malware, credential harvesting and social engineering, and that risk is rising. From ASD's ACSC data, Australian entities reported double the Business Email Compromise (BEC) attacks of 2023-24.2

With attackers exploiting both trust and technology, Australian businesses are under real pressure to secure their email environments.

Email threats are on the rise in Australia

This chart illustrates findings from ASD and ACSC reports, ordering email exploits according to prevalence of use against Australian organisations in 2025.

45%

Business email compromise

The most used method, with heavy use against organisations in the construction and finance sectors.3

 
30%

Spear phishing (with malicious attachments)

Prevalence of use against industrial organisations (1M attacks in Q1 2025) and the mining sector.4

 
15%

Calendar / invitation phishing

A rising method in the legal and financial services sectors as part of document lures.5,6

 
10%

Trusted platform exploitation

Attackers misuse well-known services such as Microsoft 365, Google and Cloudflare so a harmful link or file appears safe. VIPRE's Q1 2026 analysis of 1.8 billion emails found attackers increasingly favouring these trusted platforms precisely because the names disarm the reader.7

 

The attacker now does the homework for free

What generative AI changed is not whether these attacks happen, but how cheaply they can be run well. An attacker can scan an industry for the right kind of target, profile a named individual from what is public about them, switch to a softer target when the first one holds firm, and write a convincing lure in the right tone. That used to be days of human effort. Now it is automated and close to free, which makes campaigns cheaper, faster and far more believable. Four patterns show up repeatedly in Australian inboxes:

Abstract artwork depicting mid campaign defence

Mid-Campaign Defence Response

Attackers change tactics mid-attack when they detect controls blocking them, so the threat adapts after it lands rather than staying still.8

Abstract artwork depicting AI deepfake hybrids

AI Deepfake Hybrids

Email scams paired with AI-generated voices, images or identities to make the request look believable, including cloned executive audio.9,10

Abstract artwork depicting chained quishing

Chained Quishing

QR codes that route a target through several staged sites, slipping past filters and building trust one step at a time.11,12

Abstract artwork depicting polymorphic AI payloads

Polymorphic AI Payloads

Malicious emails that use AI to rewrite themselves so they look different every time, defeating signature-based detection.13,14

The hardest part is seeing what already gets through

Threats adapt, product features change, and IT teams scramble to keep their stack current. In Australia, moving to better tooling often stalls, for reasons that have little to do with awareness.

The first blocker is time. In-house teams and MSPs run whole-of-business IT, with no room to test, run a proof of concept, or socialise a new solution. The second is cost. Under budget pressure, businesses settle for legacy filtering or a Secure Email Gateway (SEG) and hope it holds. Against an average self-reported cost of cybercrime of $80,850 per Australian business in FY2024-25, the cheap option is often the expensive one.15

There is also an over-reliance on native protection. Businesses assume Microsoft or Google has email covered. Both are good, and neither is enough on its own, particularly where default settings were never tuned. Even when a business does adopt a stronger solution, it is often run at a fraction of its capacity, paying for features it never switches on.

All of this makes choosing hard. The market holds more than 200 email security products, most described in language that assumes context Australian buyers do not have.16 It is why this research exists: to give teams the scaffolding to make deliberate, not reactive, choices.

The deeper problem is time. A breach a weak stack never surfaces is measured not in days but in months. Mandiant's M-Trends 2026 puts global median dwell time at 14 days, and access now changes hands between criminal crews in as little as 22 seconds as the market industrialises.17 Speed like that only pays off against organisations that cannot see what is happening in their own mail.

Which is the uncomfortable part. The most common thing we find is that organisations do not know how much is already reaching their people. They believe their controls are holding. Run a monitor-only trial against a live environment, and within days you can be looking at malicious mail sitting in real inboxes that those controls marked as safe. That gap, between what a team believes is getting through and what actually is, is the problem a dedicated email security layer exists to close. Network and endpoint tools were never built to see inside the inbox. This one is.

Security Outcomes

With the threat context as a backdrop, what do information technology professionals prioritise when considering a new email security solution?

  • Frank De Pasquale, Chief Executive Officer at Tekspace
  • Matt Flack, Chief Services Officer at ASI Solutions
  • Francisco Vera, Managing Director at Securelogic Solutions

The top 4

Every organisation has its own priorities. Yet time and again, these are the outcomes that rise to the top.

1

Efficacy

The ability to achieve the intended protective outcome in real-world use.

2

Operational Efficiency

Silent operation, with minimal false positives and false negatives.

3

Reporting and Analytics

Clear visibility into platform data for end-users, IT professionals and executive leaders.

4

User Experience

Powerful features that are simple to use by end-users and IT professionals alike.

Product Landscape

The Tekspace Cyber Continuum™ ranks 17 of the leading email security vendors on one transparent, measurable spectrum. To build it, we normalised the field down to 39 capabilities and ranked each by its technical depth, so vendors are compared like for like rather than on the size of their marketing claims.

It gives a picture of feature maturity within the space, then maps vendors according to their capabilities. In doing so, we can see which solutions are most likely to achieve the outcomes that Australian organisations prioritise.

Broad

  • Mesh Icon
    Mesh
  • Hortnet (formerlly Vade) Icon
    Hornet
  • Graphus Icon
    Graphus
  • Material Icon
    Material
  • Sublime Icon
    Sublime

Features

  • Access Management
  • Advanced Threat Protection (ATP)
  • Anti-Malware
  • Anti-Phishing
  • Anti-Spam
  • Incident Data Management
  • Allow and Block Lists
  • Breach Detection Alerts
  • Activity Monitoring / Auditing
  • Compliance
  • Safe Banners
  • Autonomous Task Execution
  • (AI) Proactive Assistance
  • Internal to Internal Monitoring
  • Quarantine

Comprehensive

See Vendors and Features
Sophos Icon
Paubox Icon
SpamTitan Icon
Ironscales Icon
Cloudflare Icon
Mimecast Icon
Barracuda Icon
Proofpoint Icon

Broad

  • Sophos Icon
    Sophos
  • Paubox Icon
    Paubox
  • SpamTitan Icon
    SpamTitan
  • Ironscales Icon
    Ironscales
  • Cloudflare Icon
    Cloudflare
  • Mimecast Icon
    Mimecast
  • Barracuda Icon
    Barracuda
  • Proofpoint Icon
    Proofpoint

Features

  • Account Takeover Prevention
  • Threat Intelligence Reporting
  • Targeted Attack Prevention
  • Email Archiving
  • Single Sign-On
  • Outbound Email Monitoring
  • Policy Enforcement
  • Real-Time Detection
  • Reporting and Monitoring (General)
  • API-based Architecture
  • Email Encryption
  • Data Loss Prevention

Comprehensive

See Vendors and Features
KnowBe4 Egress Icon
Darktrace Icon
Abnormal Icon
Check Point Harmony Icon

Comprehensive

  • KnowBe4 Egress Icon
    KnowBe4 Egress
  • Darktrace Icon
    Darktrace
  • Abnormal Icon
    Abnormal
  • Check Point Harmony Icon
    Check Point Harmony

Features

  • (AI) Adaptive Learning
  • Data Exfiltration Detection
  • Reporting (User Management)
  • Digital Signatures
  • End User Self Service Quarantine
  • URL Re-Writing and Sandboxing
  • DMARC, SPF and DKIM Management
  • Reporting and Monitoring (Encryption)
  • APIs and SDKs
  • SMTP Mail Relay
  • User-Controlled Email Access Revocation
  • (AI) Anomoly Detection

Conclusion

Email is where cybersecurity strategy for most Australian organisations begins.

The threat landscape keeps shifting, and the product you choose has a material impact on whether your business stays ahead of it. Efficacy, operational efficiency, reporting and analytics, and user experience are the four outcomes that separate the most effective solutions from the rest.

We hope this research helps you make deliberate, not reactive, choices.

Want a tailored short-list? We help with that.

A logo on a chart is not a reflection of how a product truly fits your environment with your team.

Book a session Free. If we can't find a match, we exit your journey.

Addendum

Credits

In launching this report, Tekspace would like to acknowledge contributions from the following teams and individuals.

Prepared by

  • Frank De Pasquale, CEO at Tekspace
  • George Hagivassilis, CCO at Tekspace
  • Mike Ross, Service Director at Tekspace
  • Finn Astle, Marketing Specialist at Tekspace

Contributions from

  • Martin Dybalski, Director, Parabellum
  • Stuart Shanahan, Director of Technical Services, Parabellum
  • Kris Bowen, Senior Offensive Security Consultant, Parabellum
  • Francisco Vera, Managing Director at Securelogic Solutions
  • Matt Flack, Chief Services Officer at ASI Solutions
  • Alison Bourke, Fractional CMO at The Launch Project
  • Romain Pondard, Founder at Klippable
  • Daniela Moreno, Head of Content at Klippable

References

  1. Practice Protect AU (2025), The devil is still in the email: what BEC looks like in 2025.
  2. Australian Signals Directorate (2025), ASD Annual Cyber Threat Report 2024-25.
  3. Practice Protect AU (2025), The devil is still in the email: what BEC looks like in 2025.
  4. SecurityBrief Australia (2025), Email attacks surge in APAC, phishing up by 30% in 2024.
  5. Riposte Cybersecurity Consultancy (2025), Phishing threats in Australia's legal sector.
  6. Integris (2025), 2025 Integris report: law firms, cybersecurity and AI — what clients really think.
  7. VIPRE Security Group (2026), Q1 2026 Email Threat Trends Report (1.8 billion emails analysed; attackers favouring trusted platforms).
  8. VIPRE Security Group (2026), Q1 2026 Email Threat Trends Report.
  9. DeepStrike (2025), AI cybersecurity threats 2025: how to survive the AI arms race.
  10. Abnormal Security (2024), H1 2024 Phishing Frenzy: C-suite receives 42x more QR code attacks than average employee.
  11. Abnormal Security (2024), H1 2024 Phishing Frenzy.
  12. Riposte Cybersecurity Consultancy (2025), Phishing threats in Australia's legal sector.
  13. DeepStrike (2025), AI cybersecurity threats 2025: how to survive the AI arms race.
  14. VIPRE Security Group (2026), Q1 2026 Email Threat Trends Report.
  15. Australian Signals Directorate (2025), ASD Annual Cyber Threat Report 2024-25 ($80,850 average self-reported cost of cybercrime per business, FY2024-25).
  16. Keepnet Labs (2024), Navigating the email security market in 2025 (200+ email security products).
  17. Mandiant / Google Cloud (2026), M-Trends 2026 (global median dwell time 14 days, up from 11; initial-access hand-off in as little as 22 seconds).

Scope

Tekspace’s Cyber SaaS Analysis Report 2026 is not an exhaustive survey of every email security product in Australia. Instead, it focuses on solutions that are widely regarded as either market leaders, or strong emerging players.

Feature Granularity Model

At the outset, we aimed to produce an analysis that is both strategic and practical. It needs to be useful to all IT leaders, regardless of how familiar they are with a given product domain.

In doing so, we gave consideration to how products are compared against one another.

Comparison at a superficial level is too shallow and doesn't give insight as to differentiation between products. At the same time, diving into technical minutiae can often mean losing focus of how products are meaningfully different.

As such, we conduct our evaluation at what we call Level 2: The Functional Group.

In doing so, we can consistently assess whether a product's capabilities are more or less likely to help IT leaders achieve their desired outcomes.

Domain Level 1
The Module
Level 2
The Functional Group
Level 3
The Micro-Feature
Grocery Fruit Banana Sold in bunches of 5
Automotive Car Wheels 5 spokes, 5 lug nuts
Education Course Mathematics Weekly problem sets
Healthcare Clinic GP Consultations 15 Minute Standard Appointment

Disclaimers

Where commercial relationships exist, we apply the same evaluation criteria we use for all technologies, including tools we do not resell. We recognise the importance of independence in this research, and do not let commercial relationships affect our framework.

Findings reflect our professional judgement at the time of publication, based on the data available to us. Product capabilities and roadmaps change, so organisations should treat this report as a guide to practical decision making, not as a substitute for their own due diligence.

If you have identified errors in this report, or wish to have another product assessed, please contact our team.

Contact our team
Close

Focused

  • Mesh Icon
    Mesh
  • Hortnet (formerlly Vade) Icon
    Hornet
  • Graphus Icon
    Graphus
  • Material Icon
    Material
  • Sublime Icon
    Sublime

Features

  • Access Management
  • Advanced Threat Protection (ATP)
  • Anti-Malware
  • Anti-Phishing
  • Anti-Spam
  • Incident Data Management
  • Allow and Block Lists
  • Breach Detection Alerts
  • Activity Monitoring / Auditing
  • Compliance
  • Safe Banners
  • Autonomous Task Execution
  • (AI) Proactive Assistance
  • Internal to Internal Monitoring
  • Quarantine
Close

Broad

  • Sophos Icon
    Sophos
  • Paubox Icon
    Paubox
  • SpamTitan Icon
    SpamTitan
  • Ironscales Icon
    Ironscales
  • Cloudflare Icon
    Cloudflare
  • Mimecast Icon
    Mimecast
  • Barracuda Icon
    Barracuda
  • Proofpoint Icon
    Proofpoint

Features

  • Account Takeover Prevention
  • Threat Intelligence Reporting
  • Targeted Attack Prevention
  • Email Archiving
  • Single Sign-On
  • Outbound Email Monitoring
  • Policy Enforcement
  • Real-Time Detection
  • Reporting and Monitoring (General)
  • API-based Architecture
  • Email Encryption
  • Data Loss Prevention
Close

Comprehensive

  • KnowBe4 Egress Icon
    KnowBe4 Egress
  • Darktrace Icon
    Darktrace
  • Abnormal Icon
    Abnormal
  • Check Point Harmony Icon
    Check Point Harmony

Features

  • (AI) Adaptive Learning
  • Data Exfiltration Detection
  • Reporting (User Management)
  • Digital Signatures
  • End User Self Service Quarantine
  • URL Re-Writing and Sandboxing
  • DMARC, SPF and DKIM Management
  • Reporting and Monitoring (Encryption)
  • APIs and SDKs
  • SMTP Mail Relay
  • User-Controlled Email Access Revocation
  • (AI) Anomoly Detection
Get future research