Material Security
The mailbox is a filing cabinet nobody agreed to keep
Material Security treats Microsoft 365 and Google Workspace as what they have become: the largest store of sensitive documents most organizations own. It connects through the API to detect attacks, contain compromised accounts, find the sensitive data already sitting in mailboxes and files, and correct the configuration that left it exposed.
Why current controls miss this
Email security has historically been framed as a delivery problem. Something arrives, a control decides whether it should, and the matter is settled at the moment of delivery. Every gateway, filter and authentication check is built around that instant.
The instant is no longer where the value sits. A mailbox that has been in use for six years contains contracts, identity documents, bank details, password reset links, invoices, board material and the scanned passport somebody sent in 2021. The same is true of the shared drive attached to it.
That means a single account takeover is not primarily an email problem. It is a data breach with a mail client attached. The attacker does not need to send anything at all to cause the damage; reading is sufficient, and reading is silent.
Controls positioned at the perimeter have nothing to say about this. They were asked whether a message should be delivered, and they answered correctly. Nobody asked what would happen if somebody else later opened the mailbox.
The exposure is not the message arriving. It is the archive already sitting there.
The approach
Material connects to the workspace through its API rather than sitting in the mail path, which means it can see what happens after delivery and act on what is already stored. The company describes four functions working together, and the value is in the joins between them rather than in any one alone.
What the platform does
- Detection. Identifies phishing, impersonation and fraudulent requests, including messages that arrive without any malicious payload to scan for.
- Account takeover containment. Correlates a suspicious message with what follows it: new mailbox rules, unusual file access, bulk downloads. That sequence is what distinguishes a compromised account from an unusual day.
- Data protection. Finds sensitive content already held in mailboxes and files, and can require an additional verification step before that content is opened, so a stolen session does not automatically become a stolen archive.
- Posture management. Reports misconfiguration and risky sharing across the tenant: accounts without multi-factor authentication, over-shared files, forwarding rules nobody remembers creating.
The distinguishing idea is that the mailbox itself is a protected store, not just a delivery endpoint.
Evidence to ask for
This category is easy to sell on a story and harder to justify on a number, so it is worth deciding in advance what would convince you. The figure below sets out the sequence a containment product is claiming to interrupt, and each stage is something you can ask a vendor to demonstrate against your own tenant during a trial.
Implementation, and what it replaces
Because deployment is an API authorisation rather than a change to mail routing, a trial can be run and reversed without touching delivery. That materially lowers the cost of evaluating this properly, and there is little reason to accept a demonstration instead.
| Function | Commonly bought as | Question to ask |
|---|---|---|
| Post-delivery detection | A second email security product | What does our Microsoft or Google tier already cover? |
| Account takeover response | Manual work in the admin console | What does the platform do without waiting for us? |
| Sensitive data discovery | A data loss prevention project | How is a false classification corrected, and by whom? |
| Posture and configuration | A periodic audit or spreadsheet | Is anything remediated automatically, or only reported? |
Consolidation is the commercial case, so price the parts separately before accepting the bundle.
Recommendation
This suits organizations whose mailboxes and drives genuinely hold regulated or commercially sensitive material: professional services, healthcare administration, finance, and any business that receives identity documents from customers. In those environments the archive is the asset, and protecting it is a different job from filtering delivery.
It suits less well an organization whose sensitive data lives in line of business systems rather than in email, or one that has not yet completed the basics. If multi-factor authentication is not enforced on every account, that work is cheaper, faster and more effective than any product discussed here, and should come first. A vendor unwilling to say so is not being straight with you.
One further caution. A platform that reads mailbox contents in order to classify them is itself a significant trust decision. Ask where that processing happens, what is retained, who at the vendor can see it, and what the contractual position is. These are reasonable questions and a serious vendor will have documented answers.
Enforce multi-factor authentication first. Then decide whether the archive needs its own protection.
Schedule the readout Request the evaluation planAsk what six years of mail is worth
A useful starting exercise costs nothing: pick one long-serving employee, and list what an attacker would find in their mailbox and drive this afternoon. That list, rather than any feature comparison, tells you whether this is a priority.
Review what the archive holdsGet in touch with Your Company
Questions about this solution? Reach us directly.