Abnormal Security
Where it sits in your mail flow
Abnormal does not stand in front of your mail. It connects to Microsoft 365 or Google Workspace through the API, learns what normal communication looks like for every person and supplier you deal with, and acts on messages that do not fit, including ones already delivered.
Why current controls miss the expensive attacks
Filtering technology is good at messages carrying something bad. The costly attacks carry nothing bad at all.
A plain request, well written
A business email compromise message has no attachment, no link and no malware. It is a short note asking for an urgent transfer or a change of bank details. There is nothing for a scanner to find because nothing was hidden.
The supplier's account, genuinely
Vendor compromise means the mail comes from the real account, through the real domain, passing every authentication check. Reputation and domain checks all vote yes, and they are not wrong.
Internal mail a gateway never sees
Once an account is taken over, the attacker emails colleagues from inside. That traffic never crosses the perimeter, so a product positioned at the perimeter has no view of it.
What happens between connection and first catch
The mechanism matters here, because it explains both the strength and the limitation.
Connect through the API, not the MX record
Integration is an authorisation rather than a mail routing change. Abnormal states this takes around thirty minutes and requires no MX change or policy migration. The practical consequence is that a trial is genuinely reversible, which is rare in this category.
Build a baseline of normal communication
The platform models who each person actually corresponds with, from where, in what tone, about what, and which suppliers send which kinds of request. This history is what later makes an unusual message stand out despite being technically clean.
Judge identity, context and content together
A message is assessed on all three at once: whether the sender is behaving like themselves, whether the request fits the relationship, and what the language is actually asking for. Any one signal alone produces false positives; the combination is what keeps them down.
Remove what is already delivered
Because it operates inside the mailbox rather than in front of it, the platform can withdraw a message after delivery and remediate a whole campaign across every recipient at once. That is the capability a gateway structurally cannot offer.
What it watches beyond the inbox
The same behavioural approach is applied to the accounts themselves and to the collaboration tools attached to them.
| Area | What it looks for |
|---|---|
| Inbound email | Impersonation, fraudulent requests, credential phishing without a payload |
| Internal email | Lateral phishing sent from a colleague's compromised account |
| Supplier relationships | Requests that break the established pattern with a known vendor |
| Account takeover | Sign-in and mailbox-rule behaviour that indicates a hijacked account |
| Reported messages | Triage of what users report, with the verdict sent back to them |
Where this is worth the second licence
This sits on top of Microsoft or Google protection rather than replacing it, so you are paying for both. That is the decision to make clearly.
A strong fit
Organizations that move money or handle supplier payment details: finance, construction, legal, logistics, anyone paying invoices on terms. The attacks this catches are the ones that end in a wire transfer rather than an encrypted server.
A weaker fit
A small organization with few external relationships and no payment authority worth stealing faces a different threat mix. If nobody at your company can move money on an email, the case for a second email product is much weaker, and the money is better spent on identity controls.
What to check first
Ask what your Microsoft licence already includes, because parts of the higher tiers overlap. Then ask for a trial measured on your own mail: since the integration is API based and reversible, there is little excuse for buying this on a demonstration alone.
Test it on your own mail before deciding
The useful first question is simple: in the last year, how many messages reached someone here asking for a payment or a change of bank details, and what stopped them. That answer usually settles whether this layer is worth adding.
Get in touch with Your Company
Questions about this solution? Reach us directly.