Email and Collaboration Security
On December 8, 2025, Proofpoint closed its $1.8B acquisition of Hornetsecurity — a German Microsoft-365-security vendor with ~$200M ARR (growing ~20%), 125,000 customers and 12,000 MSP partners — extending its reach into the SMB/MSP channel that its enterprise install base did not cover. In the same window, Abnormal Security crossed ~$200M ARR growing 100%+ YoY at a $5.1B valuation, re-rating the category on the basis of behavioral AI. The two moves reflect one dynamic: email security is shifting from a legacy gateway architecture toward an AI-native, API-delivered model, under the competitive weight of Microsoft, which owns the inbox and includes a "good enough" version inside E5. Email remains the leading attack vector — the entry point for the majority of breaches and nearly all ransomware — so demand is structural; the open question is who captures the value as the architecture changes.
What email and collaboration security covers
Email security protects the channel through which most attacks begin — phishing, business email compromise (BEC), credential theft, malware delivery, and increasingly AI-generated social engineering — plus the adjacent collaboration surfaces (Teams, Slack, Zoom, SharePoint) that have become attack vectors in their own right. The domain is in the middle of an architectural transition across four models:
- Secure Email Gateway (SEG) — the legacy architecture. The gateway sits in front of the mail server: the MX record is re-pointed so all mail flows through the vendor's cloud, gets scanned, and is then delivered. This design fit the era when email lived on-prem (Exchange) and the perimeter was a defined boundary. Proofpoint, Mimecast, Cisco (IronPort heritage), Barracuda, Fortinet. Sticky and MX-record-anchored, but architecturally exposed as email moved to Microsoft 365 and Google Workspace.
- Integrated Cloud Email Security (ICES) — the newer architecture. API-native tools that connect behind the inbox via the Microsoft Graph / Google APIs, ingest signal about every message and user, and use behavioral AI to detect anomalies (a sender that never wires money; a login pattern that is implausible). No MX-record change, deploys in minutes, sits alongside Microsoft's own filtering rather than replacing it. Abnormal Security (the category-definer), Sublime Security, Material Security, plus Microsoft-365-native challengers. The fast-growing value pool.
- The platform bundle — Microsoft (and Google). Microsoft Defender for Office 365 ships inside the E5 license that enterprises already buy; Google adds native protection to Workspace. "Free with the suite" is the central competitive factor the third-party market contends with.
- MSP/SMB-channel email security. Email is the one security product every small business buys, almost always through an MSP. Hornetsecurity (now Proofpoint), Barracuda, Avanan (Check Point), Guardz, and the MSP-distribution motion — a structurally different, channel-led business from the enterprise platforms.
What ties it together: the buyer is not purchasing a filter but the prevention of fraudulent wire transfers and of phishing clicks that lead to ransomware events. Email is among the lowest-cost, highest-return lines in the security budget because it sits on the highest-frequency attack path — which is why Microsoft aims to own it, and why the AI-native challengers can charge a premium for catching what the bundle misses.
How each type of vendor operates
| Vendor | Owner | Architecture | Differentiation / economics |
|---|---|---|---|
| Microsoft (Defender for O365) | MSFT | Platform bundle | The inbox owner; baseline filtering bundled into E5 — the central competitive factor for third-party vendors; not sold standalone, sold as part of the seat |
| Abnormal Security | Private (VC; $5.1B, Aug'24) | ICES (API/AI) | Category-definer of behavioral-AI email security; ~$200M ARR, 100%+ YoY; lands on top of Microsoft as the "catch what E5 misses" layer; expanding into account takeover, AI agents ("AI security mailbox"), and broader human-behavior security — the re-rating bellwether |
| Proofpoint | Thoma Bravo (~$12.3B take-private, 2021) | SEG → platform | The enterprise gateway incumbent; broad platform (email, DLP, insider risk, security awareness); bought Hornetsecurity ($1.8B, Dec'25) to finally reach SMB/MSP; the PE-owned scaled incumbent racing to modernize before ICES erodes the core |
| Mimecast | Permira (~$5.8B, 2022) | SEG → platform | Mid-market/enterprise gateway + archiving/resilience heritage; launched full M365 API deployment in 2026 to narrow the ICES gap; PE-owned, exit-clock asset extending into human-risk management (bought Elevate/Aware) |
| Cisco (Email Threat Defense) | CSCO | SEG (IronPort) | Email folded into the Splunk-era security platform ($28B Splunk close); cross-correlates mail + endpoint + SIEM — the platform-bundle play from a networking giant |
| Barracuda | KKR (~$4B, 2022) | SEG + MSP | SMB/mid-market email & network security; strong MSP channel; active strategic acquirer — acquired Evo Security (multi-tenant IAM/PAM for MSPs, announced Jul 2026), extending the BarracudaONE platform from email/network into identity security |
| Sublime Security / Material Security | Private (VC) | ICES (API/AI) | Challengers to Abnormal: Sublime's detection-as-code/open approach; Material's post-delivery remediation + data-at-rest protection in the mailbox — the next-wave ICES supply |
| AegisAI | Private (VC; $49M raised) | ICES (API/AI) | AI-native inbox defense built on proprietary LLMs and autonomous "defense agents"; founded by the team behind Google's reCAPTCHA, Safe Browsing, and Web Risk; positioned specifically against AI-generated spear phishing — the newest venture-scale ICES entrant |
| Check Point (Avanan / Harmony Email) | CHKP | ICES | API-native email bought early (Avanan, 2021) and folded into Harmony — the platform-vendor ICES answer |
| Hornetsecurity | Proofpoint (was PE/VC) | MSP/SMB | M365 security built for MSPs; ~$200M ARR, 125k customers via 12k MSPs — the channel asset Proofpoint paid $1.8B for |
| Cloudflare (Area 1) / Mimecast / others | various | ICES-ish | Cloudflare's Area 1 email security delivered from its edge; the network-platform angle on email |
The vendor groups differ along consistent lines. The SEGs compete on incumbency and breadth but are architecturally exposed. Proofpoint and Mimecast own thousands of enterprise relationships, archiving/compliance hooks, and MX-record stickiness — but their core gateway design assumes mail flows through them, a premise that weakens each year as Microsoft does more filtering natively and ICES tools deploy behind the inbox without touching the MX record. Both are PE-owned and both are adding API deployment, human-risk management, and SMB channel. The ICES challengers compete on detection efficacy and deployment speed — they catch the socially-engineered, payload-free BEC that signature-based gateways miss, and they install in minutes alongside Microsoft rather than replacing it — which is why Abnormal can grow 100%+ and command a $5.1B valuation. They sell alongside Microsoft's bundle and must continually demonstrate that they catch enough incremental threats to justify a line item on top of E5. Microsoft is the default choice for any buyer that decides baseline filtering is sufficient, and its filtering improves each year. The MSP/SMB layer is a distinct business — channel-led, high-volume, low-ACV, won on partner economics and ease of management, which is the asset Proofpoint acquired in Hornetsecurity. The structural question for the domain: does the AI-native ICES model displace the gateway and become the new platform, does Microsoft's bundle commoditize third-party email security into a thin premium layer, or do the PE-owned SEGs re-platform into broad "human risk" suites before either happens?
Where the value pool is migrating
Signature deals & events
- Proofpoint → Hornetsecurity ($1.8B, closed Dec 8 2025) — the enterprise gateway incumbent (Thoma Bravo-owned) buying its way into the SMB/MSP channel it never had; Hornetsecurity (~$200M ARR, +20%, 125k customers, 12k MSPs) becomes a dedicated M365-security business unit. The clearest signal that the channel, not the enterprise, is where email-security growth now lives. See Deals & Comps.
- Abnormal Security — ~$200M ARR, $5.1B valuation (Series D, Aug 2024), 100%+ YoY — the ICES category-definer re-rating email security as an AI-native, behavior-based market; expanding beyond email into account takeover and "AI agent" protection. The bellwether for whether the disruptor architecture becomes the new platform.
- Cisco → Splunk ($28B, closed 2024) — pulls Cisco's email threat defense into a mail-plus-endpoint-plus-SIEM analytics platform; the networking-giant bundle play.
- Mimecast's API pivot + human-risk expansion (Permira-owned) — full M365 API deployment launched in 2026 to narrow the ICES gap, plus moves into human-risk management (Elevate/Aware); a PE-owned SEG re-platforming ahead of its exit clock.
- Microsoft Defender for Office 365 inside E5 — not a deal but the dominant competitive fact: every enterprise that standardizes on E5 gets baseline email security "for free," continuously improving, setting the bar every third-party vendor must clear. See Product & Competitive Strategy.
- AegisAI — $36M Series A, led by Battery Ventures (announced Jul 23 2026) — with participation from existing investors Accel and Foundation Capital, bringing total funding to ~$49M less than a year after the company left stealth. AegisAI builds proprietary large language models to defend the inbox and is scaling a fleet of autonomous defense agents, including Vanguard, an agent that hunts threats beyond the inbox. The company frames the round against a sharp rise in AI-generated spear phishing. The print is a datum on the same dynamic that re-rated the category — AI-cheapened offense expanding the email attack surface (see AI for Offense) and pulling venture capital into AI-native detection built to catch what the Microsoft bundle misses.
The bear case
The email-security bull case is straightforward: email is the leading attack vector, demand is structural and non-cyclical, AI increases both the attacks (fluent BEC, deepfake voice/video) and the defenses (behavioral models), and the architecture is changing in a way that creates a significant displacement opportunity for an AI-native winner. The bear case has three prongs. First, Microsoft's bundle is the dominant competitive factor. Defender for Office 365 is bundled into the E5 license enterprises already buy and improves every year; every third-party email vendor sells a premium layer on top of a product Microsoft has an incentive to make redundant, and once the bundle is sufficient for the median CISO, third-party email security compresses to a thin specialty line. Second, the newer architecture may itself become a feature. Abnormal's behavioral-AI layer is the kind of capability a platform (Microsoft, Palo Alto, CrowdStrike) can build or buy and fold into a suite; ICES re-rated the category, but re-rating is not the same as building a durable standalone platform, and the same API access that admits Abnormal admits Microsoft and every CNAPP/SecOps platform. Third, the SEGs are declining assets carrying real debt. Proofpoint and Mimecast are large, PE-owned, levered businesses whose core architecture is exposed to the cloud transition; if the re-platforming into "human risk" does not outpace the gateway's decline, the LBO math becomes difficult. Falsifiable test: whether Abnormal sustains its growth past $500M ARR and reaches a public listing as an independent platform, or whether its net-new growth decelerates as Microsoft's bundle improves and platform vendors ship competent behavioral email modules. If Abnormal's growth holds and Microsoft does not close the efficacy gap, the AI-native displacement thesis holds; if Microsoft's filtering catches up and ICES compresses into a premium add-on, "email security is a durable standalone market" weakens to "email security is a feature of the inbox owner and the SecOps platform."
→ Cross-references: Vendors, SecOps & SIEM, Data Security, AI Security, Product & Competitive Strategy, Deals & Comps, Valuation, Commercial Due Diligence.
Updated 2026-08-16 18:13 UTC · © El Dorado Capital · el-doradocapital.com · Market intelligence for informational purposes only; not investment advice.