The Lab
The email gaps Microsoft and Google leave open
Frank De Pasquale ·

Most Australian businesses run Microsoft 365 or Google Workspace with the native email security switched on and configured the way it should be. That layer is good, and it catches the bulk of what arrives, quietly, every day. In my experience the question is rarely whether it works. It is what it was never shaped to catch.
Business email compromise is now the costliest cybercrime reported by Australian businesses, and in a single year the average cost of cybercrime to a large business rose by 219% (ASD Annual Cyber Threat Report 2024-25). Email still sits behind roughly one in three business cybercrime reports. The volume is handled. The cost is in the mail that looks clean.
The mail with nothing to scan
A filter is built to find something: a bad attachment, a known-bad link, a sender that fails authentication. The mail getting through now carries none of that. A lure that once took a person hours is assembled in seconds, in fluent English, personalised from a target's public footprint, and it asks for a reply. Independent testing put the click-through rate on AI-generated phishing at 54%, against 12% for the older, clumsier attempts (Microsoft Digital Defense Report 2025). There is nothing in the message for a scanner to object to, because the message is just words.
The account that is already trusted
The second gap opens after someone is already in. Once an account has been taken over, the mail stops arriving from outside. It comes from a colleague, on a real thread, from an address that passes every check because it genuinely is theirs. An attacker can sit in there quietly, reading the flow, learning the tone, waiting to send the one email that moves money from a name the recipient already trusts. A filter tuned to what is coming in is looking the wrong way.
Microsoft and Google run email security as one product among hundreds. A specialist runs it as the only product they have. That is usually where the difference sits, and it shows up in exactly these two places.
- The mail with nothing to scan — an AI-written lure with no bad attachment or link to flag.
- The account that is already trusted — mail sent from a genuine, already-compromised inbox.
We publish Frank's read on each market to the Lab as we test it. Get it in your inbox →
Foundation, then a layer on top
The way this works now is additive. You keep every native defence turned on, Microsoft or Google does everything it does, and a specialised email security layer sits directly behind it, reads what native let through, and learns on what it missed. Only mail that layer judges safe carries on to the inbox. Because it sits behind the filter, it is also watching the mail that moves between your own people, which is where the second gap lives.
Neither layer is foolproof. There is no foolproof. What changes is the size of what gets through, and on the platforms we road test that reduction tends to be substantial.

See it in your own environment
This is one of the few areas in security where you do not have to take it on faith. A specialised layer can run in monitor-only mode alongside what you already have, in about fifteen minutes, without touching the flow of mail. Within a few days it will usually surface the malicious email reaching your own inboxes that the native layer marked safe. That is the number worth having: not whether the native settings are on, but what is getting past them today.
If that is worth seeing for your own mail flow, we start with a short assessment.
The cost climbs faster than the coverage
Two figures already cited above, together.
219%
rise in cybercrime cost to large AU businesses, year on year
54%
click-through on AI-generated phishing, against 12% for older attempts
ASD Annual Cyber Threat Report 2024-25; Microsoft Digital Defense Report 2025
See what's getting past your filter
Native filtering catches volume. It was never built for a lure with nothing to scan, or mail from an account that's already yours.
A specialist layer runs monitor-only behind what you already have and shows what's getting through today.
No changes to how mail moves.
See email securityVendor-independent testing, run against your own mail flow.