Email Security Needs Proof, Not Static Detection: Takeaways from SACR's Email Security Report

SACR’s new report explains why today's email threats require more than static detection, and why context, investigation, and proof matter more than ever. 
4 min read
Last updated July 20, 2026

Varonis security brief

  • Perimeter-based email defenses miss AI-generated attacks that carry no obvious malicious link or attachment.
  • A new report from Software Analyst Cyber Research (SACR) says email security must shift from detecting bad messages to investigating how an attack unfolds.
  • SACR highlights Varonis Interceptor as an example of this shift because it uses an AI Phishing Sandbox that follows an attack through to the credential-harvesting page a user would actually land on.

Email security is undergoing a fundamental shift — from static defense to an approach built around identity, context, and evidence — now that attackers have learned to exploit trust, identity, and human judgment to circumvent traditional perimeter-based detection.

Software Analyst Cyber Research (SACR) illustrates why in a new report titled From Perimeter to Proof: The New Architecture of Email Security. In it, Anna Perrone, Research Associate/Business Process Analyst at SACR, examines a new generation of email security architectures designed to address the business workflows attackers now regularly exploit through email.

Perrone looks at key vendors that represent the new generation of email security, including Varonis Interceptor. The email security solution is highlighted for approaching phishing not as a standalone email problem, but as the first stage of a broader attack chain that can lead to credential theft, data exposure, privilege escalation, or business-process compromise.

Perimeter-based email security is not enough 

Traditional email security was built around static detection and perimeter-based defenses. These solutions identify known threats, flag suspicious messages, and rely on users or downstream controls to respond. But this model is increasingly ineffective against modern attacks

The report identifies context as the core gap in that model. Perimeter-based, content-detection-driven systems are designed to catch known indicators at the point of entry. These solutions have limited ability to evaluate attacks that lack obvious signals like malicious links or attachments. As attackers increasingly use AI to create novel attacks that abuse trusted relationships and communication patterns, context becomes the deciding factor in whether an interaction is legitimate or malicious. 

Software Analyst Cyber Research (SACR) advocates for a fundamental shift in email security from static defense to protections that examine the entire business workflow.

SACR-Why Email Sec is Changing

Software Analyst Cyber Research (SACR) advocates for a fundamental shift in email security from static defense to protections that examine the entire business workflow.

Email security must move from binary blocking to contextual understanding

Because attackers have adapted to the controls organizations already deployed, SACR argues that email security must expand what it's expected to understand — from binary blocking to a contextual read on identity, relationships, workflow, intent, and behavior.

That context matters because many modern attacks are designed to look ordinary at the message level. A vendor invoice, password reset, shared document, or executive request may not contain an obvious malicious attachment or known-bad link. The risk comes from how the message fits into a broader pattern: who appears to be involved, what action is being requested, whether the workflow makes sense, and how the interaction could expose credentials, data, or business processes if the user engages.

Many of the most damaging attacks today look different. They exploit established relationships, legitimate infrastructure, identity workflows, and human decision-making under pressure. As a result, the current attack surface is not simply bad email; it is business workflow abused through email.

Anna Perrone, Research Associate/Business Process Analyst at Software Analyst Cyber Research (SACR)

Varonis Interceptor: from detection to investigation 

The SACR report highlights Varonis Interceptor as a leading example of the shift it sees reshaping the email security market.

According to the report, Varonis approaches phishing not as a standalone messaging problem, but as the first stage of a broader attack chain that often culminates in credential theft, data exposure, privilege escalation, or business-process compromise. That framing, SACR argues, requires more than determining whether a single message is malicious — it requires understanding how attacks work, not simply whether they exist. 

The report describes Interceptor's architecture as built around that premise. Rather than relying on one detection method, the platform analyzes inbound communications using multiple detection layers — language models, visual analysis, infrastructure inspection, URL detonation, and behavioral indicators — to build a fuller picture of an attack before reaching a verdict. 

Varonis represents one of the clearest examples of a broader shift occurring within email security: the movement from detection toward investigation.

Anna Perrone, Research Associate/Business Process Analyst at Software Analyst Cyber Research (SACR) 

 

To illustrate why this matters, the report walks through a scenario: a QR-code phishing attack that starts in an email, directs the user toward a trusted cloud service, routes them through several redirects, and ultimately lands on a credential-harvesting page built to mimic a familiar business application. At each individual step, the infrastructure involved looks legitimate, which is why the report argues that understanding how the stages connect matters more than evaluating any one link or domain in isolation. 

Varonis Interceptor’s AI Phishing Sandbox tests every potential action a user could take, applying zero trust to detect sophisticated email-based attacks.  

Browser security_Switchback_2x

Varonis Interceptor’s AI Phishing Sandbox tests every potential action a user could take, applying zero trust to detect sophisticated email-based attacks.  

This exact challenge is one that SACR says Interceptor addresses with its AI Phishing Sandbox. The report notes it's designed to interact with phishing pages the way a person would. Interceptor follows every redirect, working through credential-capture forms, and surfacing multi-step attack paths to determine what a user would actually encounter if they followed the attack through to the end. 

The report notes this extends beyond the inbox as well: Interceptor's browser-oriented capabilities let it observe what users encounter after clicking a link, rather than stopping at the message itself. This gives security teams visibility into the full user journey that message inspection alone would miss. 

Why SACR says this matters now 

  1. Phishing is becoming an identity and data problem, not just an inbox problem. 

    The report points to Interceptor's data-security lineage as a distinct advantage: Varonis' data-centric background gives it a natural path into the questions that matter once an account is compromised — what sensitive data that account could reach, and whether the incident created broader exposure. 

  2. Attacks no longer stay in one place. 

    SACR's broader thesis is that today's attacks rarely stop at the inbox — a phishing email can lead to credential theft, identity compromise, and data exposure in the same incident. The report positions Interceptor as built to help teams answer the questions that follow: how the attack was delivered, what infrastructure was involved, whether users interacted with it, and what other systems may have been touched. 

  3. AI has changed what a "suspicious" email looks like. 

    The report ties this to its broader argument that generative AI has changed the cost structure of phishing, producing messages that are more personalized, more grammatically clean, and harder to distinguish from legitimate business communication. SACR frames Interceptor's multimodal, behavior-based analysis as a direct response to the fact that static, template-based detection struggles once every message can look slightly different. 

The future of email security is proof-driven 

SACR's report concludes that the future of email security won't be defined by a single architecture, but by how effectively different approaches help organizations understand attacks, respond efficiently, and reduce risk across an increasingly complex communication environment.

Central to that argument is a shift the report identifies across the market as a whole: explainability is becoming a procurement requirement. Organizations need to know why a platform reached a conclusion, what evidence backs it up, and how a response decision can be defended to executives, auditors, regulators, and cyber insurers. 

Varonis Interceptor is presented in the report as one vendor built around that emerging generation of email security. Varonis applies an approach SACR characterizes as treating phishing detection, investigation, evidence generation, and remediation as connected parts of a single workflow, rather than isolated detection events. 

Modernize your email security for today's threat landscape

Learn how Varonis Interceptor prevents never-before-seen threats. 
1
Schedule a demo of Varonis Interceptor to see how it can protect your inbox.
2
Explore Interceptor's capabilities, including the AI Phishing Sandbox that follows every redirect a phishing link takes, the same way a user would.
3
Follow us on LinkedIn, YouTube, and X for ongoing coverage of phishing, identity risk, and email security.

Try Varonis free.

Get a detailed data risk report based on your company’s data.
Deploys in minutes.

Keep reading

Varonis tackles hundreds of use cases, making it the ultimate platform to stop data breaches and ensure compliance.

abuse-of-microsoft-dynamics-redirects-delivers-phishing-payloads-at-scale
Abuse of Microsoft Dynamics Redirects Delivers Phishing Payloads at Scale
Varonis Interceptor stopped a phishing campaign abusing Microsoft Dynamics redirects, highlighting how attackers are leveraging trusted SaaS infrastructure to evade email defenses.
cybercrime-predictions-for-2026:-what-we’re-seeing-from-the-frontlines
Cybercrime Predictions for 2026: What We’re Seeing from the Frontlines
Discover how AI-powered cyber threats, malicious LLMs, and advanced phishing are reshaping security and demanding smarter, data-centric defenses in 2026.
phishing-attacks:-types,-statistics,-and-prevention
Phishing Attacks: Types, Statistics, and Prevention
Discover the latest phishing attack types, key statistics, and proven prevention strategies to protect organizations across email, messaging apps, and collaboration platforms.