Tekspace Cyber Lab Presents

Email Security

A Cyber SaaS Analysis 2026
Get future research sooner. We never share or sell your data.

An Australian-first. Real research, by real cyber operators.

Tekspace has spent years inside the systems that keep Australian businesses secure. In a market crowded with solutions that all promise protection, we know the outcomes that matter. Until now, that research has stayed in-house.

This report changes that. In collaboration with our partners, we look at email as a threat vector, study what businesses actually need from an email security solution, and evaluate the leading vendors in the space.

Thank you to Parabellum, ASI Solutions, Securelogic and the team behind the scenes (see Addendum for credits). Together, this work helps us deliver on our focus to protect people and data with simple, impactful cybersecurity.

Portrait photo of Frank De Pasquale
Frank De Pasquale
CEO at Tekspace

Threat Context

Insights from Parabellum Logo

CREST Pen Test certification badge. OffSec OSCE3 certification badge OffSec OSCE certification badge OffSec OSCP certification badge OffSec OSEP certification badge OffSec OSWE certification badge OffSec OSED certification badge OffSec OSWP certification badge

Email remains the dominant entry point for 57% of reported breaches in Australian organiations.1

Threat actors, particularly state-sponsored APTs (Advanced Persistent Threats) are leveraging email as a low-barrier, high-yield vector for initial access, reconnaissance and persistence.

A keystone of communication, email is a delivery mechanism for malware, credential harvesting and social engineering campaigns, and that risk is increasing. From ASD's ACSC data, Australian entities experienced doubled Business Email Compromise (BEC) attacks compared to 2023-24.2

With APTs exploiting trust and technology, Australian businesses are under immense pressure to secure their email environments.

Email threats are on the rise in Australia

This chart illustrates findings from ASD and ACSC reports, ordering email exploits according to prevalence of use against Australian organisations in 2025.

45%

Business email compromise

The most used method, with heavy use against organisations in the construction and finance sectors.3

 
30%

Spear phishing (with malicious attachments)

Prevalence of use against industrial organisations (1M attacks in Q1 2025) and the mining sector.4

 
15%

Calendar / invitation phishing

Rising method in the legal and financial services sectors as part of document lures.5,6

 
10%

Trusted platform exploitation

Attackers misuse well-known services (e.g.: Microsoft 365, Google) to make harmful links or files appear safe. 449% increase in phone-linked variants.7

 

As tech changes, new email threats emerge

While the common methods of email exploit are on the rise in Australia, threat actors are also utilising the technology we can all access; creating campaigns that are advanced, capable and accessible.

Abstract artwork depicting mid campaign defence

Mid-Campaign Defense Response

Attackers now change their tactics mid-attack when they detect security controls blocking them, making the threat harder to stop.7

Abstract artwork depicting AI deepfake hybrids

AI Deepfake Hybrids

Criminals combine fake AI-generated voices, images or identities with email scams to make their messages look more believable.8,9

Abstract artwork depicting chained quishing

Chained Quishing

A scam that uses QR codes to send people through several staged websites, helping the attacker slip past security filters and build trust step by step.10,11

Abstract artwork depicting polymorphic AI payloads

Polymorphic AI Payloads

Malicious emails that use AI to rewrite themselves automatically so they look different every time, helping them avoid detection.12,13,14

Low maturity products amplify APT dwell times by 200%

APTs adapt, the Cyber SaaS features change and IT professionals scramble to assess their cyber stack. But in Australia, early adoption of next-gen technology can stall.

Why? The first blocker is time. In-house cyber teams and MSSP's are managing whole-of-business IT, so there's no time to test, run PoC's, or socialise a new solution.

Cost pressure saw budget buying. Businesses settle for legacy filtering or Secure Email Gateways (SEGs). The average self-reported cost of cybercrime for businesses in FY2024-25 is $80,85015. How much are you saving on a cheap solution?

A trend we see globally is an over reliance on trusted vendors. Businesses believe they are secured with Microsoft and Google's native features. Far from it, Google let's in 3,000 malicious emails into an average inbox per year.16

And when businesses did adopt a better solution. A lack of vendor created blockers implementing the solution at full capacity. So, businesses pay for features they don't use.

Because of all this, it is difficult for leaders to assess and choose cyber solutions. The email security market alone has more than 200 different products17. With very little specific context (e.g NIS2 Governance), and irrelevant data governance in AU environments.14

So, how do we secure Australia's emails? When CISO's are overruled by budget, procurement cycles, and too many see IT security as a box ticking exercise. The solution for IT leaders is clear. It's why this research exists. Helping Australian teams and beyond with the scaffolding to make deliberate, not reactive, choices14.

Cybersecurity will be the next-generation's biggest business priority. Email is the first point of entry for disaster.

Security Outcomes

With the threat context as a backdrop, what do information technology professionals prioritise when considering a new email security solution?

  • Frank De Pasquale, Chief Executive Officer at Tekspace
  • Matt Flack, Chief Services Officer at ASI Solutions
  • Francisco Vera, Managing Director at Securelogic Solutions

The top 4

Every organisation has its own priorities. Yet time and again, these are the outcomes that rise to the top.

1

Efficacy

Ability to achieve the intended protective outcome in real-world use.

2

Operational Efficiency

Silent operation with minimal false positives and false negatives that disrupt end-users.

3

Reporting and Analytics

Robust visibility into platform data for end-users, IT professionals and executive leaders.

4

User Experience

Powerful features that are simple to use by end-users and IT professionals alike.

Product Landscape

The Tekspace Cyber Continuum™ ranks 18 of the leading Email Security vendors in one transparent, measureable spectrum.

It gives a picture of feature maturity within the space, then maps vendors according to their capabilities. In doing so, we can see which solutions are most likely to achieve the outcomes that Australian organisations prioritise.

Broad

  • Mesh Icon
    Mesh
  • Hortnet (formerlly Vade) Icon
    Hornet
  • Graphus Icon
    Graphus
  • Material Icon
    Material
  • Sublime Icon
    Sublime

Features

  • Access Management
  • Advanced Threat Protection (ATP)
  • Anti-Malware
  • Anti-Phishing
  • Anti-Spam
  • Incident Data Management
  • Allow and Block Lists
  • Breach Detection Alerts
  • Activity Monitoring / Auditing
  • Compliance
  • Safe Banners
  • Autonomous Task Execution
  • (AI) Proactive Assistance
  • Internal to Internal Monitoring
  • Quarantine

Comprehensive

See Vendors and Features
Sophos Icon
Paubox Icon
SpamTitan Icon
Ironscales Icon
Cloudflare Icon
Mimecast Icon
Barracuda Icon
Proofpoint Icon

Broad

  • Sophos Icon
    Sophos
  • Paubox Icon
    Paubox
  • SpamTitan Icon
    SpamTitan
  • Ironscales Icon
    Ironscales
  • Cloudflare Icon
    Cloudflare
  • Mimecast Icon
    Mimecast
  • Barracuda Icon
    Barracuda
  • Proofpoint Icon
    Proofpoint

Features

  • Account Takeover Prevention
  • Threat Intelligence Reporting
  • Targeted Attack Prevention
  • Email Archiving
  • Single Sign-On
  • Outbound Email Monitoring
  • Policy Enforcement
  • Real-Time Detection
  • Reporting and Monitoring (General)
  • API-based Architecture
  • Email Encryption
  • Data Loss Prevention

Comprehensive

See Vendors and Features
KnowBe4 Egress Icon
Darktrace Icon
Abnormal Icon
Check Point Harmony Icon

Comprehensive

  • KnowBe4 Egress Icon
    KnowBe4 Egress
  • Darktrace Icon
    Darktrace
  • Abnormal Icon
    Abnormal
  • Check Point Harmony Icon
    Check Point Harmony

Features

  • (AI) Adaptive Learning
  • Data Exfiltration Detection
  • Reporting (User Management)
  • Digital Signatures
  • End User Self Service Quarantine
  • URL Re-Writing and Sandboxing
  • DMARC, SPF and DKIM Management
  • Reporting and Monitoring (Encryption)
  • APIs and SDKs
  • SMTP Mail Relay
  • User-Controlled Email Access Revocation
  • (AI) Anomoly Detection

Conclusion

Email is the linchpin of modern cybersecurity strategy for Australian organisations.

The threat landscape is evolving, and product selection has a material impact on whether your business stays ahead of it. Efficacy, operational efficiency, robust analytics, and user experience are the four outcomes that separate the most effective solutions from the rest.

We hope this research helps you make deliberate, not reactive, choices.

Want a tailored short-list? We help with that.

A logo on a chart is not a reflection of how a product truly fits your environment with your team.

Book a session Free. If we can't find a match, we exit your journey.

Addendum

Credits

In launching this report, the Tekspace would like to acknowledge contributions from the following teams and individuals.

Prepared by

  • Frank De Pasquale, CEO at Tekspace
  • George Hagivassilis, CCO at Tekspace
  • Mike Ross, Service Director at Tekspace
  • Finn Astle, Marketing Specialist at Tekspace

Contributions from

  • Martin Dybalski, Director, Parabellum
  • Stuart Shanahan, Director of Technical Services, Parabellum
  • Kris Bowen, Senior Offensive Security Consultant, Parabellum
  • Francisco Vera, Managing Director at Securelogic Solutions
  • Matt Flack, Cheif Services Officer at ASI Solutions
  • Alison Bourke, Fractional CMO at The Launch Project
  • Romain Pondard, Founder at Klippable
  • Daniela Moreno, Head of Content at Klippable

References

  1. Australian Signals Directorate (2025), ASD Annual Report 2024-25
  2. Australian Signals Directorate (2025), ASD Annual Report 2024-25
  3. Australian Federal Police (2025), Criminals target construction sector with Business Email Compromise scams
  4. Australian Signals Directorate (2025), Annual Cyber Threat Report 2024-25: fact sheet for businesses and organisations
  5. Practice Protect AU (2025), The devil is still in the email: what BEC looks like in 2025.
  6. Riposte Cybersecurity Consultancy (2025) Phishing threats in Australia's legal sector
  7. SecurityBrief Australia (2025) Email attacks surge in APAC, phishing up by 30% in 2024
  8. Australian Signals Directorate (2025), ASD Annual Report 2024-25.
  9. Australian Institute of Criminality (2024), Cybercrime in Australia 2023-24
  10. DeepStrike (2025), AI cybersecurity threats 2025: how to survive the AI arms race
  11. Keepnet Labs (2024), Navigating the email security market in 2025
  12. Abnormal Security (2024), H1 2024 Phishing Frenzy: C-suite receives 42x more QR code attacks than average employee
  13. Integris (2025) 2025 Integris report: law firms, cybersecurity and AI - what clients really think
  14. Google Threat Intelligence Group, Mandiant & Google Security Operations, (2025) Cybersecurity Forecast 2026
  15. VIPRE Security Group (2025) Cyber threats in 2025: how AI is changing phishing tactics
  16. StrongestLayer (2025) StrongestLayer secures US$5.2M to combat emerging AI-driven email threats
  17. Australian Institute of Criminality (2024), Cybercrime in Australia 2023-24

Scope

Tekspace’s Cyber SaaS Analysis Report 2026 is not an exhaustive survey of every email security product in Australia. Instead, it focuses on solutions that are widely regarded as either market leaders, or strong emerging players.

Feature Granuality Model

At the outset, we aimed to produce an analysis that is both strategic and practical. It needs to be useful to all IT leaders, regardless of how familiar they are with a given product domain.

In doing so, we gave consideration to how products are compared against one another.

Comparison at a superficial level is too shallow and doesn't give insight as to differentiation between products. At the same time, diving into technical minutiae can often mean losing focus of how products are meaningfully differnt.

As such, we conduct our evaluation at what we call, Level 2: The Functional Group.

In doing so, we can consistently assess whether a product's capabilities are more or less likely to help IT leaders achieve their desired outcomes.

Domain Level 1
The Module
Level 2
The Functional Group
Level 3
The Micro-Feature
Grocery Fruit Banana Sold in bunches of 5
Automotive Car Wheels 5 spokes, 5 lug nuts
Education Course Mathematics Weekly problem sets
Healthcare Clinic GP Consultations 15 Minute Standard Appointment

Disclaimers

Where commercial relationships exist, we apply the same evaluation criteria we use for all technologies, including tools we do not resell. We recognise the importance of independence in this research, and do not let commercial relationships affect our framework.

Findings reflect our professional judgement at the time of publication, based on the data available to us. Product capabilities and roadmaps change, so organisations should treat this report as a guide to practical decision making, not as a substitute for their own due diligence.

If you have identified errors in this report, or wish to have another product assessed, please contact our team.

Contact our team
Close

Low Maturity

  • Mesh Icon
    Mesh
  • Hortnet (formerlly Vade) Icon
    Hornet
  • Graphus Icon
    Graphus
  • Material Icon
    Material
  • Sublime Icon
    Sublime

Features

  • Access Management
  • Advanced Threat Protection (ATP)
  • Anti-Malware
  • Anti-Phishing
  • Anti-Spam
  • Incident Data Management
  • Allow and Block Lists
  • Breach Detection Alerts
  • Activity Monitoring / Auditing
  • Compliance
  • Safe Banners
  • Autonomous Task Execution
  • (AI) Proactive Assistance
  • Internal to Internal Monitoring
  • Quarantine
Close

Average Maturity

  • Sophos Icon
    Sophos
  • Paubox Icon
    Paubox
  • SpamTitan Icon
    SpamTitan
  • Ironscales Icon
    Ironscales
  • Cloudflare Icon
    Cloudflare
  • Mimecast Icon
    Mimecast
  • Barracuda Icon
    Barracuda
  • Proofpoint Icon
    Proofpoint

Features

  • Account Takeover Prevention
  • Threat Intelligence Reporting
  • Targeted Attack Prevention
  • Email Archiving
  • Single Sign-On
  • Outbound Email Monitoring
  • Policy Enforcement
  • Real-Time Detection
  • Reporting and Monitoring (General)
  • API-based Architecture
  • Email Encryption
  • Data Loss Prevention
Close

High Maturity

  • KnowBe4 Egress Icon
    KnowBe4 Egress
  • Darktrace Icon
    Darktrace
  • Abnormal Icon
    Abnormal
  • Check Point Harmony Icon
    Check Point Harmony

Features

  • (AI) Adaptive Learning
  • Data Exfiltration Detection
  • Reporting (User Management)
  • Digital Signatures
  • End User Self Service Quarantine
  • URL Re-Writing and Sandboxing
  • DMARC, SPF and DKIM Management
  • Reporting and Monitoring (Encryption)
  • APIs and SDKs
  • SMTP Mail Relay
  • User-Controlled Email Access Revocation
  • (AI) Anomoly Detection
Get future research