Back to main siteBack Contact us
Solution brief

Material Security

Email Security

The mailbox is a filing cabinet nobody agreed to keep

Material Security treats Microsoft 365 and Google Workspace as what they have become: the largest store of sensitive documents most organizations own. It connects through the API to detect attacks, contain compromised accounts, find the sensitive data already sitting in mailboxes and files, and correct the configuration that left it exposed.

I

Why current controls miss this

Email security has historically been framed as a delivery problem. Something arrives, a control decides whether it should, and the matter is settled at the moment of delivery. Every gateway, filter and authentication check is built around that instant.

The instant is no longer where the value sits. A mailbox that has been in use for six years contains contracts, identity documents, bank details, password reset links, invoices, board material and the scanned passport somebody sent in 2021. The same is true of the shared drive attached to it.

That means a single account takeover is not primarily an email problem. It is a data breach with a mail client attached. The attacker does not need to send anything at all to cause the damage; reading is sufficient, and reading is silent.

Controls positioned at the perimeter have nothing to say about this. They were asked whether a message should be delivered, and they answered correctly. Nobody asked what would happen if somebody else later opened the mailbox.

The exposure is not the message arriving. It is the archive already sitting there.

II

The approach

Material connects to the workspace through its API rather than sitting in the mail path, which means it can see what happens after delivery and act on what is already stored. The company describes four functions working together, and the value is in the joins between them rather than in any one alone.

What the platform does

  • Detection. Identifies phishing, impersonation and fraudulent requests, including messages that arrive without any malicious payload to scan for.
  • Account takeover containment. Correlates a suspicious message with what follows it: new mailbox rules, unusual file access, bulk downloads. That sequence is what distinguishes a compromised account from an unusual day.
  • Data protection. Finds sensitive content already held in mailboxes and files, and can require an additional verification step before that content is opened, so a stolen session does not automatically become a stolen archive.
  • Posture management. Reports misconfiguration and risky sharing across the tenant: accounts without multi-factor authentication, over-shared files, forwarding rules nobody remembers creating.

The distinguishing idea is that the mailbox itself is a protected store, not just a delivery endpoint.

III

Evidence to ask for

This category is easy to sell on a story and harder to justify on a number, so it is worth deciding in advance what would convince you. The figure below sets out the sequence a containment product is claiming to interrupt, and each stage is something you can ask a vendor to demonstrate against your own tenant during a trial.

Credential taken day 0 Sign-in succeeds minutes later Rule created quietly Archive read six years of mail Data leaves breach notice containment is claimed here
Exhibit A. The window between a successful sign-in and the archive being read is the entire product claim. Ask for it to be demonstrated, with timings, on your own tenant.
IV

Implementation, and what it replaces

Because deployment is an API authorisation rather than a change to mail routing, a trial can be run and reversed without touching delivery. That materially lowers the cost of evaluating this properly, and there is little reason to accept a demonstration instead.

FunctionCommonly bought asQuestion to ask
Post-delivery detectionA second email security productWhat does our Microsoft or Google tier already cover?
Account takeover responseManual work in the admin consoleWhat does the platform do without waiting for us?
Sensitive data discoveryA data loss prevention projectHow is a false classification corrected, and by whom?
Posture and configurationA periodic audit or spreadsheetIs anything remediated automatically, or only reported?

Consolidation is the commercial case, so price the parts separately before accepting the bundle.

V

Recommendation

This suits organizations whose mailboxes and drives genuinely hold regulated or commercially sensitive material: professional services, healthcare administration, finance, and any business that receives identity documents from customers. In those environments the archive is the asset, and protecting it is a different job from filtering delivery.

It suits less well an organization whose sensitive data lives in line of business systems rather than in email, or one that has not yet completed the basics. If multi-factor authentication is not enforced on every account, that work is cheaper, faster and more effective than any product discussed here, and should come first. A vendor unwilling to say so is not being straight with you.

One further caution. A platform that reads mailbox contents in order to classify them is itself a significant trust decision. Ask where that processing happens, what is retained, who at the vendor can see it, and what the contractual position is. These are reasonable questions and a serious vendor will have documented answers.

Enforce multi-factor authentication first. Then decide whether the archive needs its own protection.

Schedule the readout Request the evaluation plan
In short

Ask what six years of mail is worth

A useful starting exercise costs nothing: pick one long-serving employee, and list what an attacker would find in their mailbox and drive this afternoon. That list, rather than any feature comparison, tells you whether this is a priority.

Review what the archive holds

Get in touch with Your Company

Questions about this solution? Reach us directly.