How email exploits are evolving in Australia.
What Australian IT leaders prioritise when choosing an email security solution.
18 leading vendors benchmarked on The Tekspace Cyber Continuum™.
Key takeaways, future outlook, and how to act on this research.
An Australian-first. Real research, by real cyber operators.
Tekspace has spent years inside the systems that keep Australian businesses secure. In a market crowded with solutions that all promise protection, we know the outcomes that matter. Until now, that research has stayed in-house.
This report changes that. In collaboration with our partners, we look at email as a threat vector, study what businesses actually need from an email security solution, and evaluate the leading vendors in the space.
Thank you to Parabellum, ASI Solutions, Securelogic and the team behind the scenes (see Addendum for credits). Together, this work helps us deliver on our focus to protect people and data with simple, impactful cybersecurity.
Email remains the dominant entry point for 57% of reported breaches in Australian organiations.1
Threat actors, particularly state-sponsored APTs (Advanced Persistent Threats) are leveraging email as a low-barrier, high-yield vector for initial access, reconnaissance and persistence.
A keystone of communication, email is a delivery mechanism for malware, credential harvesting and social engineering campaigns, and that risk is increasing. From ASD's ACSC data, Australian entities experienced doubled Business Email Compromise (BEC) attacks compared to 2023-24.2
With APTs exploiting trust and technology, Australian businesses are under immense pressure to secure their email environments.
This chart illustrates findings from ASD and ACSC reports, ordering email exploits according to prevalence of use against Australian organisations in 2025.
While the common methods of email exploit are on the rise in Australia, threat actors are also utilising the technology we can all access; creating campaigns that are advanced, capable and accessible.
Attackers now change their tactics mid-attack when they detect security controls blocking them, making the threat harder to stop.7
Criminals combine fake AI-generated voices, images or identities with email scams to make their messages look more believable.8,9
A scam that uses QR codes to send people through several staged websites, helping the attacker slip past security filters and build trust step by step.10,11
Malicious emails that use AI to rewrite themselves automatically so they look different every time, helping them avoid detection.12,13,14
APTs adapt, the Cyber SaaS features change and IT professionals scramble to assess their cyber stack. But in Australia, early adoption of next-gen technology can stall.
Why? The first blocker is time. In-house cyber teams and MSSP's are managing whole-of-business IT, so there's no time to test, run PoC's, or socialise a new solution.
Cost pressure saw budget buying. Businesses settle for legacy filtering or Secure Email Gateways (SEGs). The average self-reported cost of cybercrime for businesses in FY2024-25 is $80,85015. How much are you saving on a cheap solution?
A trend we see globally is an over reliance on trusted vendors. Businesses believe they are secured with Microsoft and Google's native features. Far from it, Google let's in 3,000 malicious emails into an average inbox per year.16
And when businesses did adopt a better solution. A lack of vendor created blockers implementing the solution at full capacity. So, businesses pay for features they don't use.
Because of all this, it is difficult for leaders to assess and choose cyber solutions. The email security market alone has more than 200 different products17. With very little specific context (e.g NIS2 Governance), and irrelevant data governance in AU environments.14
So, how do we secure Australia's emails? When CISO's are overruled by budget, procurement cycles, and too many see IT security as a box ticking exercise. The solution for IT leaders is clear. It's why this research exists. Helping Australian teams and beyond with the scaffolding to make deliberate, not reactive, choices14.
Cybersecurity will be the next-generation's biggest business priority. Email is the first point of entry for disaster.
With the threat context as a backdrop, what do information technology professionals prioritise when considering a new email security solution?
Every organisation has its own priorities. Yet time and again, these are the outcomes that rise to the top.
Ability to achieve the intended protective outcome in real-world use.
Silent operation with minimal false positives and false negatives that disrupt end-users.
Robust visibility into platform data for end-users, IT professionals and executive leaders.
Powerful features that are simple to use by end-users and IT professionals alike.
The Tekspace Cyber Continuum™ ranks 18 of the leading Email Security vendors in one transparent, measureable spectrum.
It gives a picture of feature maturity within the space, then maps vendors according to their capabilities. In doing so, we can see which solutions are most likely to achieve the outcomes that Australian organisations prioritise.
Email is the linchpin of modern cybersecurity strategy for Australian organisations.
The threat landscape is evolving, and product selection has a material impact on whether your business stays ahead of it. Efficacy, operational efficiency, robust analytics, and user experience are the four outcomes that separate the most effective solutions from the rest.
We hope this research helps you make deliberate, not reactive, choices.
A logo on a chart is not a reflection of how a product truly fits your environment with your team.
Book a session Free. If we can't find a match, we exit your journey.In launching this report, the Tekspace would like to acknowledge contributions from the following teams and individuals.
At the outset, we aimed to produce an analysis that is both strategic and practical. It needs to be useful to all IT leaders, regardless of how familiar they are with a given product domain.
In doing so, we gave consideration to how products are compared against one another.
Comparison at a superficial level is too shallow and doesn't give insight as to differentiation between products. At the same time, diving into technical minutiae can often mean losing focus of how products are meaningfully differnt.
As such, we conduct our evaluation at what we call, Level 2: The Functional Group.
In doing so, we can consistently assess whether a product's capabilities are more or less likely to help IT leaders achieve their desired outcomes.
| Domain | Level 1 The Module |
Level 2 The Functional Group |
Level 3 The Micro-Feature |
|---|---|---|---|
| Grocery | Fruit | Banana | Sold in bunches of 5 |
| Automotive | Car | Wheels | 5 spokes, 5 lug nuts |
| Education | Course | Mathematics | Weekly problem sets |
| Healthcare | Clinic | GP Consultations | 15 Minute Standard Appointment |
Where commercial relationships exist, we apply the same evaluation criteria we use for all technologies, including tools we do not resell. We recognise the importance of independence in this research, and do not let commercial relationships affect our framework.
Findings reflect our professional judgement at the time of publication, based on the data available to us. Product capabilities and roadmaps change, so organisations should treat this report as a guide to practical decision making, not as a substitute for their own due diligence.
If you have identified errors in this report, or wish to have another product assessed, please contact our team.
Contact our team