With evolving AI threats, traditional defences are no longer enough
Email has long been a point of vulnerability for businesses, but the scale and sophistication of attacks are evolving, posing a greater threat than ever before.
Adding to the challenge is AI, which is helping bad actors iterate and improve their attacks at an unprecedented pace. This is no longer a theory — it’s happening right now. According to Infosecurity Magazine, phishing attacks doubled in just one year.
While AI may be fuelling an increase in malicious activity, the good news is that, in the right hands, it’s also helping organisations combat phishing threats.
In today’s email security “arms race,” having the right tools to counter evolving threats is vital.
Email security is a priority for SMBs
In Kaseya’s 2026 Cybersecurity Outlook, two of the top three areas of concern for SMBs were related to email — and many respondents had already experienced email-based attacks firsthand.
56% said they had been impacted by phishing attacks, while 40% reported being victims of business email compromise (BEC).
Looking ahead, businesses continue to view email as a risk. Human error and social engineering ranked as the top concern for 29% of businesses, while 27% identified email itself as a primary threat. But with email being frequently exploited for social engineering attacks, the two are intrinsically linked.
MSPs surveyed broadly agreed with these concerns but took an even more stark view of future risks. 76% of MSPs believe companies will succumb to a successful phishing attack and 66% to BEC.
The positive among these concerning stats is that companies see email protection as one of the best applications for AI — with 49% saying email protection is AI’s biggest strength.
How strong email security supports NIS2 compliance
Threat prevention forms a core part of NIS2 legislation, moving email security from an IT discussion to a broader boardroom responsibility for security and resiliency. While NIS2 doesn’t directly address email, its principles apply to this and other systems.
Several areas of NIS2 are supported by effective email security:
- Risk analysis & information system security
Email is at the centre of many threats, including phishing, BEC and malware. It’s vital that risk analysis covers both the email systems themselves as well as the potential ramifications of successful attacks that use email as the method of entry.
- Basic computer hygiene and training
Even with the best tools, emails will slip past automated checks. That’s why it’s vital that employees get regular training on what to look out for and on security best practices. This should be backed up with useful, contextual reminders, such as anti-phishing banners to coach users on each email risks.
- Business continuity measures
If email goes down, what happens next? There are many elements to this, including backup emergency communications (itself a part of NIS2 guidance) as well as secure email backups, so your business can confidently recover from an incident.
- Use of multifactor authentication
This is explicitly flagged in NIS2 and is a vital part of email security. With email offering the ability for bad actors to find their way into other systems, as well as sending malicious communications, MFA provides a sensible core security measure as a first line of defence for email security.
Companies need to review their security posture to remain compliant with NIS2, and for MSPs, it’s an opportunity to help guide customers on that journey.
MSPs are concerned about the growing sophistication of attacks
At a recent Kaseya Connect Local event, two MSP leaders took to the stage to discuss how email threats are evolving.
“I think the biggest difference is the quality and variation,” said Phil Callowat, Director of Ark ICT Solutions. He admitted the pace of change is “really scary, if I have to be honest.” Explaining how emails in the past were largely limited to adding some branding and pretending to be from a trusted organisation such as a bank, he said “I think the difference now is it’s just so much more imaginative than it ever used to be. It’s getting much more clever at adapting to what you’re likely to fall for.”
Echoing the concerns around social engineering in combination with phishing attempts, Marvin Miller, Director of 1101, said bad actors were putting the time into doing their homework. “It’s getting smarter and smarter and also more targeted as well. They tend to target your top board members, your directors, your managers — but then also new employees as well. They’re constantly scoping LinkedIn to work out who’s joined a company.”
Attacks “are coming in thicker and faster” thanks to AI, Miller added, but also said it would help in defending against them. “Leveraging AI, that’s going to help us to keep abreast of it,” he said.
The right tools are vital to combat modern threats
While AI may be a threat, with the right tools, it also strengthens the first line of defence.
- AI can help protect email in ways that tools previously couldn’t. Features such as conversation analysis can read not just the content but also understand intent.
- With computer vision, emails can be “seen” to understand brand impersonation attempts and scan items like QR codes to understand where the destination URL is going and if it’s safe.
- AI can combat tricks used by scammers, such as zero-font manipulation, while machine-based learning based on content helps find and identify likely spam or phishing content.
Learn more about how Kaseya is helping MSPs stay ahead of evolving threats with the tools, insights and guidance featured in our 2026 Kaseya Cybersecurity Outlook: Trends, threats & readiness report.



