Email security under NIS2 

With evolving AI threats, traditional defences are no longer enough 

Email has long been a point of vulnerability for businesses, but the scale and sophistication of attacks are evolving, posing a greater threat than ever before.  

Adding to the challenge is AI, which is helping bad actors iterate and improve their attacks at an unprecedented pace. This is no longer a theory — it’s happening right now.  According to Infosecurity Magazine, phishing attacks doubled in just one year. 

While AI may be fuelling an increase in malicious activity, the good news is that, in the right hands, it’s also helping organisations combat phishing threats. 

In today’s email security “arms race,” having the right tools to counter evolving threats is vital. 

Email security is a priority for SMBs  

In Kaseya’s 2026 Cybersecurity Outlook, two of the top three areas of concern for SMBs were related to email —  and many respondents had already experienced email-based attacks firsthand. 

56% said they had been impacted by phishing attacks, while 40% reported being victims of business email compromise (BEC).  

Looking ahead, businesses continue to view email as a risk. Human error and social engineering ranked as the top concern for 29% of businesses, while 27% identified email itself as a primary threat. But with email being frequently exploited for social engineering attacks, the two are intrinsically linked. 

MSPs surveyed broadly agreed with these concerns but took an even more stark view of future risks. 76% of MSPs believe companies will succumb to a successful phishing attack and 66% to BEC.  

The positive among these concerning stats is that companies see email protection as one of the best applications for AI — with 49% saying email protection is AI’s biggest strength. 

How strong email security supports NIS2 compliance 

Threat prevention forms a core part of NIS2 legislation, moving email security from an IT discussion to a broader boardroom responsibility for security and resiliency. While NIS2 doesn’t directly address email, its principles apply to this and other systems.  

Several areas of NIS2 are supported by effective email security: 

  • Risk analysis & information system security  

Email is at the centre of many threats, including phishing, BEC and malware. It’s vital that risk analysis covers both the email systems themselves as well as the potential ramifications of successful attacks that use email as the method of entry. 

  • Basic computer hygiene and training  

Even with the best tools, emails will slip past automated checks. That’s why it’s vital that employees get regular training on what to look out for and on security best practices. This should be backed up with useful, contextual reminders, such as anti-phishing banners to coach users on each email risks. 

  • Business continuity measures  

If email goes down, what happens next? There are many elements to this, including backup emergency communications (itself a part of NIS2 guidance) as well as secure email backups, so your business can confidently recover from an incident.  

  • Use of multifactor authentication  

This is explicitly flagged in NIS2 and is a vital part of email security. With email offering the ability for bad actors to find their way into other systems, as well as sending malicious communications, MFA provides a sensible core security measure as a first line of defence for email security.   

Companies need to review their security posture to remain compliant with NIS2, and for MSPs, it’s an opportunity to help guide customers on that journey.  

MSPs are concerned about the growing sophistication of attacks 

At a recent Kaseya Connect Local event, two MSP leaders took to the stage to discuss how email threats are evolving.  

“I think the biggest difference is the quality and variation,” said Phil Callowat, Director of Ark ICT Solutions. He admitted the pace of change is “really scary, if I have to be honest.” Explaining how emails in the past were largely limited to adding some branding and pretending to be from a trusted organisation such as a bank, he said “I think the difference now is it’s just so much more imaginative than it ever used to be. It’s getting much more clever at adapting to what you’re likely to fall for.”  

Echoing the concerns around social engineering in combination with phishing attempts, Marvin Miller, Director of 1101, said bad actors were putting the time into doing their homework. “It’s getting smarter and smarter and also more targeted as well. They tend to target your top board members, your directors, your managers — but then also new employees as well. They’re constantly scoping LinkedIn to work out who’s joined a company.” 

Attacks “are coming in thicker and faster” thanks to AI, Miller added, but also said it would help in defending against them. “Leveraging AI, that’s going to help us to keep abreast of it,” he said. 

The right tools are vital to combat modern threats 

While AI may be a threat, with the right tools, it also strengthens the first line of defence. 

  • AI can help protect email in ways that tools previously couldn’t. Features such as conversation analysis can read not just the content but also understand intent.  
  • With computer vision, emails can be “seen” to understand brand impersonation attempts and scan items like QR codes to understand where the destination URL is going and if it’s safe. 
  • AI can combat tricks used by scammers, such as zero-font manipulation, while machine-based learning based on content helps find and identify likely spam or phishing content.  

Learn more about how Kaseya is helping MSPs stay ahead of evolving threats with the tools, insights and guidance featured in our 2026 Kaseya Cybersecurity Outlook: Trends, threats & readiness report.  

Uma plataforma completa para gestão de TI e segurança

Kaseya 365 a solução completa para gerenciar, proteger e automatizar a TI. Com integrações perfeitas entre as principais funções de TI, ele simplifica as operações, reforça a segurança e aumenta a eficiência.

Uma plataforma. Tudo em TI.

Kaseya 365 desfrutam dos benefícios das melhores ferramentas de gerenciamento de TI e segurança em uma única solução.

Conheça o Kaseya 365

Seu sucesso é nossa prioridade número 1

O Partner First é um compromisso com condições flexíveis, risco compartilhado e suporte dedicado para o seu negócio.

Conheça Partner First Pledge

Relatório Kaseya sobre a Situação dos MSP de 2026

Kaseya - Relatório sobre a Situação dos MSPs em 2026

Obtenha insights sobre o MSP para 2026 com mais de 1.000 prestadores de serviços e descubra como aumentar a receita, adaptar-se às pressões do mercado e manter a competitividade.

Faça o download agora

Five cybersecurity priorities every school needs to get right

K-12 and higher education institutions face constant cyberattacks due to limited IT resources. Here are five cybersecurity priorities they should act on now to reduce risk.

Leia a postagem do blog

Standardize, document, automate: Insights from Kaseya Connect Europe

Kaseya Connect Europe 2026 brought together industry leaders to share hard-won lessons. Here are the highlights and insights from key sessions.

Leia a postagem do blog

Será que devemos começar pela resiliência e seguir em sentido inverso a partir daí?

Patrocinado por: Kaseya Este é um artigo de blog escrito pela International Data Corporation (IDC), líder global em inteligência de mercado, que compartilha

Leia a postagem do blog