Passer au contenu principal

Aug 26, 2026

Email Security Evolved: Protect What Comes In, What Goes Out, and the People in Between

Protect what comes in, what goes out, and the people in between with new Abnormal capabilities for threat detection, data protection, and phishing training.

Attackers have changed the economics of cybercrime. AI gives them the ability to research targets, write convincing messages, and adapt their tactics at a speed and scale that traditional defenses were never designed to match. The most effective attacks are no longer recognized by known malware, suspicious domains, or familiar signatures. They look like normal business activity, until they do not.

That shift is why we built Abnormal around behavior. Instead of asking only whether a message, sender, or domain is known to be bad, our behavioral AI learns how people and organizations normally communicate and identifies the moments when that pattern changes. This foundation allows Abnormal to stop sophisticated inbound attacks precisely without creating more work for security teams.

But inbound detection is only one part of the problem. The role of email security is expanding. Security teams still need to stop sophisticated inbound attacks, but they are increasingly looking to the same security platform to address outbound data loss, employee phishing risk, and the need for greater control over automated detection. Securing email now means addressing risk from multiple directions: the threats coming in, the sensitive information going out, and the people attackers continue to target.

Today, we are enhancing the Abnormal email security platform across all three surfaces:

  • Control Center: Turn organization-specific knowledge into detection decisions through precise rules and custom AI models.

  • Email DLP Rules: Define explicit outbound data-loss policies and let an AI Triage Agent review matches in context, auto-clearing false positives.

  • AI Phishing Coach: Calibrate security training to how each employee is targeted with phishing attacks, instead of delivering the same simulation on a fixed calendar.

Together, these capabilities augment how Abnormal helps organizations manage email risk, from the threats coming in, to sensitive data going out, to the employees attackers target.

Control Center: Control Without Code

Fal.Con_Master_Blog_Screenshot_1.png
The new Control Center gives security teams control without the code.

Behavioral AI gives security teams protection that keeps pace as their environment and the threats targeting it change. But security teams also have policies, priorities, and context unique to their organization. Control Center gives them a direct way to put that knowledge into action, with visibility into how each decision is made.

Control Center, a new no-cost capability of Inbound Email Security, layers new control and visibility on top of Abnormal’s detection engine while keeping behavioral AI at the core of protection. It brings together two complementary control surfaces:

  • Custom AI Models (Generally Available): Create organization-specific detection models from simple descriptions. Teams can teach Abnormal to recognize evolving patterns unique to their business without building a detection-engineering project from scratch.

  • Custom Rules (Early Access): Define precise conditions to block or allow email using more than 50 message attributes, then validate those rules with real examples. 

Control Center shows which layer made each decision (the core AI, a custom model, or a custom rule). That transparency helps teams investigate faster, tune protection with confidence, and explain how automated decisions fit their organization’s policies.

Control Center gives teams control where they need it without asking them to become detection engineers. Behavioral AI handles the dynamic work of understanding behavior and recognizing threats, while security teams can define the conditions they know, describe the patterns they recognize, and apply explicit control when their environment demands it.

Custom AI Models will become Generally Available and Custom Rules will be available in Early Access starting August 31.

Learn More About Control Center

Email DLP Rules: Catch Real Data Loss Without the Distraction of False Positives

Fal.Con_Master_Blog_Product_Screenshot_2.png
Email DLP Rules employs a triage agent to review flagged matches in context.

Every email DLP tool can flag a policy violation. The harder problem is surfacing the outbound messages that actually put data at risk, without drowning security teams in false positives and manual review. For example, one customer told us that a single email DLP rule in place at their organization flagged 12,000 emails as credit card numbers in six months, and nearly all of the detections turned out to be false positives. A SOC analyst had to manually review each detection and evaluate them by hand, which took hours. 

Traditional email DLP tools can spot patterns that may signal sensitive data, but judging business context is often the harder problem. Abnormal is solving this problem with Email DLP Rules.

Email DLP Rules combines explicit policy controls with contextual review: security teams can define outbound rules using regex, phrase matching, metadata conditions, Boolean logic, and exclusions, while the AI Triage Agent reviews flagged matches for business context.

The agent evaluates the rule’s intent, the sender, and the surrounding message context. It auto-releases benign messages and quarantines likely violations, while recording every verdict in the Outbound Log for audit visibility.

Email DLP Rules gives organizations a practical way to enforce outbound policy without taking on the triage burden that many DLP deployments encounter at scale. With Abnormal, the Triage Agent takes on that burden instead. Teams can define explicit policies, express and tune exceptions in plain language, and review transparent, plain-language reasoning behind every verdict the Triage Agent delivers. 

Email DLP Rules is available in Early Access starting August 31.

Learn More About Email DLP Rules

AI Phishing Coach: Train People How and Where They’re Targeted

Fal.Con_Master_Blog_Screenshot_3.png
AI Phishing Coach administrators can now deploy targeted and customized Simulation and Training Campaigns from simple prompts.

Most security awareness programs still run on a calendar. Every employee receives the same training at the same frequency, regardless of their current risk exposure, the real-world attacks they have encountered, or the prior engagement they have demonstrated.

That stale model is increasingly disconnected from how attacks work. Attackers personalize their lures, change channels, and follow up when a target does not respond. Training should be able to do the same.

That’s why we’re enhancing AI Phishing Coach with new capabilities that transform training, making it more personalized, proactive, and responsive to changing behavior patterns. Precision Training automatically adjusts simulation frequency and difficulty based on how each employee responds, assigns reinforcement training when additional education is warranted, and reduces frequency as employees demonstrate stronger behaviors. In-Thread Follow-Up re-engages employees who ignore a simulation, while QR Code simulations have been added to the growing library of simulation types to prepare employees for this increasingly common threat.

For those organizations that require more control, Attack Creator, Training Creator, and Campaign Creator allow administrators to generate custom simulations and training content from a plain-language prompt, then deploy campaigns to address emerging threats and business-specific scenarios.

Together, these capabilities turn real attack intelligence and individual training outcomes into a program that continuously recalibrates to deliver the right training in the right amount and at the right time. Every employee trains differently. Now AI Phishing Coach can train them accordingly.

All new AI Phishing Coach features become Generally Available August 31.

Learn More About AI Phishing Coach

A New Control Plane for Email Risk

These launches are connected by a simple thesis: security teams should not have to choose between AI that adapts to their environment and controls they can understand and direct.

Control Center makes behavioral detection more transparent and configurable. Email DLP Rules brings intelligent review to outbound data protection. AI Phishing Coach makes phishing training responsive to what attackers are actually targeting.

As enterprises consolidate their security stack, they need more than another collection of point features. They need a platform that can understand normal, recognize meaningful change, and help security teams act without adding unnecessary operational burden.

Join Us at Fal.Con

At Fal.Con from August 31 to September 3, we’ll show how Abnormal is extending behavioral AI across detection, data loss prevention, and phishing risk management.

Book a meeting with our team at Fal.Con to see the new capabilities in action and learn how Abnormal can help protect what is coming in, what is going out, and the people in between.

Book a Meeting at Fal.Con

The above is intended to outline our general product direction. It is intended for information purposes only, and may not be incorporated into any contract. It is not a commitment to deliver any material, code, or functionality, and should not be relied upon in making purchasing decisions. The development, release, and timing of any features or functionality described for Abnormal AI’s products remain at the sole discretion of Abnormal AI and is subject to change.

Protect Against Evolving Email Threats

See how behavioral AI detects attacks that legacy defenses miss.