StopSecuring
Email.
Start securing the cloud workspace.
You're defending the inbox while attackers target the workspace. The real risk lives in accounts, sessions, files, and connected apps.
The companies defining the AI era secure their cloud workspace with Material.
The most defended door in security keeps losing the house.

Two decades of secure email gateways and awareness training made the inbox the most scrutinized square inch in security. Yet for all that, Verizon's 2026 DBIR notes phishing's share of initial access "has barely moved over the past few years."

And phishing is no longer the only way into the cloud workspace: credential abuse now touches 39% of breach progressions, more than any other initial-access vector. The inbox was the perimeter when email was where work lived. Work moved. Attackers moved with it.

Workpace Security Playbook
Four reasons to stop securing email
.

Modern, AI-driven attacks deliberately span email, identities, data, and connected apps. Defending any single layer in isolation leaves the rest exposed.
01.
Catch rate doesn't decide the outcome. 

The blast radius after delivery does.
02.
Inbound email tools go quiet at delivery. 

They have nothing to say about sessions, mail rules, OAuth grants, or data at rest.
03.
The risk has moved. 

Salesloft Drift, Composio, and Vercel touched the inbox only after a compromised token opened the workspace.
04.
The attack surface has expanded.

AI agents operate across the entire cloud workspace, not just email.
01.
.
Catch rate doesn't decide the outcome. 

The blast radius after delivery does.
02.
.
Inbound email tools go quiet at delivery. 

They have nothing to say about sessions, mail rules, OAuth grants, or data at rest.
03.
.
The risk has moved. 

Salesloft Drift, Composio, and Vercel touched the inbox only after a compromised token opened the workspace.
04.
.
The attack surface has expanded.

AI agents operate across the entire cloud workspace, not just email.
13x
Increase in phishing volume in the post-AI era.
25%
Increase in phishing volume in the post-AI era.
45%
Increase in phishing volume in the post-AI era.
1,100%
Increase in phishing volume in the post-AI era.
How AI broke the economics of the inbox

For years, email-centric security bet that filtering could outpace attacker volume. Generative AI ended that bet, not by making phishing smarter than filters, but by making infinite, polished variation effectively free.

By April 2025, at least 51% of spam and 14% of business email compromise attempts were LLM-generated, drawn from an academic study of 481,558 real malicious emails. In the largest campaign clusters, up to 79% of messages were LLM-written rewrites, engineered to slip past signature and volume-based filters.

Every heuristic your users were trained on is gone: the typos, the broken English, the clumsy urgency.

The metric that matters isn't your catch rate. It's the blast radius of the phish that inevitably lands, and that's a question about your workspace, not your gateway.

.

Your workspace is far more than just the inbox.
The workspace isn't just where attacks land; it's an attack surface that has been quietly compounding on its own. Shared files, OAuth apps, app-specific passwords, magic links, and more.
MAIL
FILES
ACCOUNTS
SESSIONS
CONNECTED APPS
Chaim Sanders
CISO, Lyft
"Zombie connections, technically authorized, practically abandoned, and invisible to most of the controls we rely on."
SHARED DRIVES
1 in 4
Drive files contain sensitive data. In one eight-month window, total files grew ~400% and sensitive files grew over 1,100%.
.
.
.
CONNECTED APPS
47%
Of connected apps showed no activity in 90 days yet keep live tokens. Over 1,000 "zombie" apps have zero users, 43.5% with sensitive or restricted scopes.
.
.
.
SHADOW AI
91%
Of AI apps connected to corporate workspaces appeared in the last 16 months. More than half hold sensitive scopes. Most were never formally approved.
.
.
.
Secure the workspace, not the message

"Stop securing email" doesn't mean turn off your filters. It means stop treating the inbox as the perimeter and start defending the workspace as one interconnected system: mail, files, accounts, sessions, and connected apps.

THE HYDRA PROBLEM

Cut off one head and two grow back. Securing email alone spawns risk everywhere else. You have to 
defeat the whole creature at once.
The Playbook
01
Grade on blast radius
Email isn't the only path to an account takeover. Measure what an attacker can do once inside, not phishing catch rate alone.
02
Protect data where it lives
Years of PII, credentials, and contracts sit in mailboxes and Drive at rest. A compromised account should yield a locked vault, not an open archive.
03
Govern the grants
Inventory OAuth connections, revoke on offboarding, set a 90-day dormancy threshold, and build a sanctioned path for AI tools before the next wave arrives.
04
Contain the account
Account takeover is a when, not an if. Detection and response inside the workspace turns an incident into a non-event.
05
Demand one view
Email, files, and identity aren't three products' worth of problems, they're one attack path. Point tools that each watch one door leave the hallways dark.
For a lean team, one platform watching one interconnected surface is less work than five tools watching five fragments. It's a reallocation of attention toward where breaches actually unfold.
Get the full playbook →
Security leaders have already moved past the inbox

THE CISOs

"The team at Material Security has built a really interesting product that completely bypasses how everybody has thought about email security historically."
Troy Wilkinson
CISO, Interpublic Group (IPG)

"Expanding beyond email to secure the entire cloud workspace is a game changer. Very impressive to see a platform that meets the reality of how work gets done today."

Erik Wille
CISO, Cabinetworks Group

"In a past life, I was an Incident Responder helping many victim companies. Material Security would have been a difference maker in stymying the attackers."

Ernest Liu
CISO, UTA

The Press & Industry

"Expanding beyond email to secure the entire cloud workspace is a game changer. Very impressive to see a platform that meets the reality of how work gets done today."

Erik Wille
CISO, Cabinetworks Group

"Expanding beyond email to secure the entire cloud workspace is a game changer. Very impressive to see a platform that meets the reality of how work gets done today."

Erik Wille
CISO, Cabinetworks Group

"In a past life, I was an Incident Responder helping many victim companies. Material Security would have been a difference maker in stymying the attackers."

Ernest Liu
CISO, UTA

The Bottom Line

Email security fought its war to a permanent draw.The war moved.
Secure the cloud workspace, the email, files, and accounts your company actually runs on. Or, accept that the most important part of your attack surface is the part nobody's watching.
Detection and response across email, files, connected apps, and accounts in Google Workspace and Microsoft 365, deployed via API in minutes, with no MX record changes.
© 2026 Material Security · material.security
Sources
Verizon, 2026 Data Breach Investigations Report. Hao, W. et al., "Characterizing the Prevalence of LLM-Generated Malicious Emails," Proc. ACM Internet Measurement Conference (IMC '25). Material Security, OAuth & Google Workspace Risk Report; "Automating OAuth Grant Management"; "Exploring Sensitive Data Trends." SlashNext, The State of Phishing 2023. Figures reflect the cited research; customer quotes reproduced with permission.
Privacy Preference Center

By clicking “Accept”, you agree to the storing of cookies on your device to enhance site navigation, analyze site usage, and assist in our marketing efforts. View our Privacy Policy for more information.

New