The Business of Cyber Security

Email and Collaboration Security

On December 8, 2025, Proofpoint closed its $1.8B acquisition of Hornetsecurity — a German Microsoft-365-security vendor with ~$200M ARR (growing ~20%), 125,000 customers and 12,000 MSP partners — extending its reach into the SMB/MSP channel that its enterprise install base did not cover. In the same window, Abnormal Security crossed ~$200M ARR growing 100%+ YoY at a $5.1B valuation, re-rating the category on the basis of behavioral AI. The two moves reflect one dynamic: email security is shifting from a legacy gateway architecture toward an AI-native, API-delivered model, under the competitive weight of Microsoft, which owns the inbox and includes a "good enough" version inside E5. Email remains the leading attack vector — the entry point for the majority of breaches and nearly all ransomware — so demand is structural; the open question is who captures the value as the architecture changes.

What email and collaboration security covers

Email security protects the channel through which most attacks begin — phishing, business email compromise (BEC), credential theft, malware delivery, and increasingly AI-generated social engineering — plus the adjacent collaboration surfaces (Teams, Slack, Zoom, SharePoint) that have become attack vectors in their own right. The domain is in the middle of an architectural transition across four models:

What ties it together: the buyer is not purchasing a filter but the prevention of fraudulent wire transfers and of phishing clicks that lead to ransomware events. Email is among the lowest-cost, highest-return lines in the security budget because it sits on the highest-frequency attack path — which is why Microsoft aims to own it, and why the AI-native challengers can charge a premium for catching what the bundle misses.

How each type of vendor operates

Vendor Owner Architecture Differentiation / economics
Microsoft (Defender for O365) MSFT Platform bundle The inbox owner; baseline filtering bundled into E5 — the central competitive factor for third-party vendors; not sold standalone, sold as part of the seat
Abnormal Security Private (VC; $5.1B, Aug'24) ICES (API/AI) Category-definer of behavioral-AI email security; ~$200M ARR, 100%+ YoY; lands on top of Microsoft as the "catch what E5 misses" layer; expanding into account takeover, AI agents ("AI security mailbox"), and broader human-behavior security — the re-rating bellwether
Proofpoint Thoma Bravo (~$12.3B take-private, 2021) SEG → platform The enterprise gateway incumbent; broad platform (email, DLP, insider risk, security awareness); bought Hornetsecurity ($1.8B, Dec'25) to finally reach SMB/MSP; the PE-owned scaled incumbent racing to modernize before ICES erodes the core
Mimecast Permira (~$5.8B, 2022) SEG → platform Mid-market/enterprise gateway + archiving/resilience heritage; launched full M365 API deployment in 2026 to narrow the ICES gap; PE-owned, exit-clock asset extending into human-risk management (bought Elevate/Aware)
Cisco (Email Threat Defense) CSCO SEG (IronPort) Email folded into the Splunk-era security platform ($28B Splunk close); cross-correlates mail + endpoint + SIEM — the platform-bundle play from a networking giant
Barracuda KKR (~$4B, 2022) SEG + MSP SMB/mid-market email & network security; strong MSP channel; active strategic acquirer — acquired Evo Security (multi-tenant IAM/PAM for MSPs, announced Jul 2026), extending the BarracudaONE platform from email/network into identity security
Sublime Security / Material Security Private (VC) ICES (API/AI) Challengers to Abnormal: Sublime's detection-as-code/open approach; Material's post-delivery remediation + data-at-rest protection in the mailbox — the next-wave ICES supply
AegisAI Private (VC; $49M raised) ICES (API/AI) AI-native inbox defense built on proprietary LLMs and autonomous "defense agents"; founded by the team behind Google's reCAPTCHA, Safe Browsing, and Web Risk; positioned specifically against AI-generated spear phishing — the newest venture-scale ICES entrant
Check Point (Avanan / Harmony Email) CHKP ICES API-native email bought early (Avanan, 2021) and folded into Harmony — the platform-vendor ICES answer
Hornetsecurity Proofpoint (was PE/VC) MSP/SMB M365 security built for MSPs; ~$200M ARR, 125k customers via 12k MSPs — the channel asset Proofpoint paid $1.8B for
Cloudflare (Area 1) / Mimecast / others various ICES-ish Cloudflare's Area 1 email security delivered from its edge; the network-platform angle on email

The vendor groups differ along consistent lines. The SEGs compete on incumbency and breadth but are architecturally exposed. Proofpoint and Mimecast own thousands of enterprise relationships, archiving/compliance hooks, and MX-record stickiness — but their core gateway design assumes mail flows through them, a premise that weakens each year as Microsoft does more filtering natively and ICES tools deploy behind the inbox without touching the MX record. Both are PE-owned and both are adding API deployment, human-risk management, and SMB channel. The ICES challengers compete on detection efficacy and deployment speed — they catch the socially-engineered, payload-free BEC that signature-based gateways miss, and they install in minutes alongside Microsoft rather than replacing it — which is why Abnormal can grow 100%+ and command a $5.1B valuation. They sell alongside Microsoft's bundle and must continually demonstrate that they catch enough incremental threats to justify a line item on top of E5. Microsoft is the default choice for any buyer that decides baseline filtering is sufficient, and its filtering improves each year. The MSP/SMB layer is a distinct business — channel-led, high-volume, low-ACV, won on partner economics and ease of management, which is the asset Proofpoint acquired in Hornetsecurity. The structural question for the domain: does the AI-native ICES model displace the gateway and become the new platform, does Microsoft's bundle commoditize third-party email security into a thin premium layer, or do the PE-owned SEGs re-platform into broad "human risk" suites before either happens?

Where the value pool is migrating

Email security — value migrating from gateway to AI-native (under the bundle) low mid high value / growth SEG Proofpoint/Mimecast large, declining ↓ ICES / AI Abnormal +100% ~$200M ARR ↑ MSFT E5 Defender O365 bundled, free-ish MSP/SMB Hornetsecurity →Proofpoint $1.8B
Directional (illustrative, not to scale): the value pool is migrating from the legacy gateway (SEG) toward AI-native API delivery (ICES) and the MSP/SMB channel, all under the gravity of Microsoft's bundled Defender for Office 365. Total email-security market est. ~$5.9B (2026) → ~$11B (2031), ~12–13% CAGR. Sources: Mordor Intelligence — email security market; Abnormal — ARR milestone; SecurityWeek — Proofpoint/Hornetsecurity $1.8B.

Signature deals & events

The bear case

The email-security bull case is straightforward: email is the leading attack vector, demand is structural and non-cyclical, AI increases both the attacks (fluent BEC, deepfake voice/video) and the defenses (behavioral models), and the architecture is changing in a way that creates a significant displacement opportunity for an AI-native winner. The bear case has three prongs. First, Microsoft's bundle is the dominant competitive factor. Defender for Office 365 is bundled into the E5 license enterprises already buy and improves every year; every third-party email vendor sells a premium layer on top of a product Microsoft has an incentive to make redundant, and once the bundle is sufficient for the median CISO, third-party email security compresses to a thin specialty line. Second, the newer architecture may itself become a feature. Abnormal's behavioral-AI layer is the kind of capability a platform (Microsoft, Palo Alto, CrowdStrike) can build or buy and fold into a suite; ICES re-rated the category, but re-rating is not the same as building a durable standalone platform, and the same API access that admits Abnormal admits Microsoft and every CNAPP/SecOps platform. Third, the SEGs are declining assets carrying real debt. Proofpoint and Mimecast are large, PE-owned, levered businesses whose core architecture is exposed to the cloud transition; if the re-platforming into "human risk" does not outpace the gateway's decline, the LBO math becomes difficult. Falsifiable test: whether Abnormal sustains its growth past $500M ARR and reaches a public listing as an independent platform, or whether its net-new growth decelerates as Microsoft's bundle improves and platform vendors ship competent behavioral email modules. If Abnormal's growth holds and Microsoft does not close the efficacy gap, the AI-native displacement thesis holds; if Microsoft's filtering catches up and ICES compresses into a premium add-on, "email security is a durable standalone market" weakens to "email security is a feature of the inbox owner and the SecOps platform."

Cross-references: Vendors, SecOps & SIEM, Data Security, AI Security, Product & Competitive Strategy, Deals & Comps, Valuation, Commercial Due Diligence.


Updated 2026-08-16 18:13 UTC · © El Dorado Capital · el-doradocapital.com · Market intelligence for informational purposes only; not investment advice.