
Phishing is the most common cause of cyberattacks on businesses. Learn which protective measures truly work and why an email security gateway is the most important line of defense.
Die neuesten Beiträge aus unserem Blog.

Die Auswahl des richtigen Email Security Gateways ist entscheidend für die Sicherheit der Unternehmenskommunikation. Dieser Vergleich zeigt die wichtigsten Kriterien und typische Fallstricke.

Ein Email Security Gateway ist die zentrale Verteidigungslinie für die E-Mail-Kommunikation in Unternehmen. Dieser Guide erklärt, wie es funktioniert, welche Bedrohungen es abwehrt und warum es für…
TL;DR: 90% of all successful cyberattacks begin with a phishing email. Training alone is not enough – businesses need technical protective measures at the gateway level. Conbool MailGuard detects spear phishing, BEC, and CEO fraud through AI-based analysis, deep link inspection, and sender verification before the email reaches the inbox.
Phishing is not a new threat – but it is becoming increasingly sophisticated. While classic spam is easy to spot, today's attackers use highly personalized emails that can deceive even experienced employees. According to the BSI Situation Report 2024, phishing remains the most common cause of successful cyberattacks on German companies.
The simplest form: thousands of identical emails with generic subject lines like "Your account has been locked." These attacks rely on volume and are mostly detected by modern spam filters.
Targeted attacks on specific individuals or departments. The attacker researches the company, uses internal terminology, and imitates known business partners. These emails are nearly indistinguishable from legitimate business correspondence for content filters.
The attacker impersonates a supervisor, CEO, or finance department and requests a wire transfer or the disclosure of sensitive data. BEC emails contain neither malware nor suspicious links – they are purely text-based and rely on social manipulation.
A subtype of BEC: the attacker imitates the CEO and instructs the accounting department to execute an urgent payment. According to the BKA Federal Cybercrime Situation Report, CEO fraud causes damages in the hundreds of millions of euros annually in Germany.
Security awareness training is important, but it is not a reliable defense:
The most effective strategy is defense in depth: technical protective measures as the first line of defense, awareness as the second.
Instead of only reacting to known signatures, a modern gateway analyzes the context of the email:
Links in phishing emails often lead through redirect chains to a credential harvesting page. A gateway must:
Technical verification of sender authenticity:
Suspicious attachments are opened in an isolated environment and examined for malicious behavior – without risk to the corporate network.
Conbool MailGuard combines all four protective layers in an upstream gateway:
| Protective Layer | Function | Detection Rate |
|---|---|---|
| Reputation filter | Block known spam senders | >99% for mass spam |
| AI analysis | Contextual assessment of spear phishing | High |
| Deep link analysis | Check and detonate URLs in real time | High |
| Sandbox | Execute and observe attachments in isolation | High for zero-day |
| Sender verification | SPF/DKIM/DMARC + header analysis | Reliable for spoofing |
The integration with Microsoft 365 and Exchange Online is done via an MX record change and can be completed in less than one hour.
Typical warning signs:
How quickly does MailGuard detect new phishing campaigns?
MailGuard uses AI-based detection that does not rely on signatures. New phishing patterns are detected in real time – without waiting for signature updates.
What happens to an email identified as phishing?
The email is placed in quarantine. Administrators receive a notification and can release the email if it turns out to be a false positive.
Can MailGuard also detect internal phishing simulations?
Yes, but you can configure whitelists for internal simulation tools so that your awareness training campaigns are not affected.
How does MailGuard differ from Microsoft Defender for Office 365?
Microsoft Defender operates within the Microsoft infrastructure. MailGuard sits in front of it as an independent protective layer and filters threats before they reach Microsoft – a defense-in-depth approach as recommended by the BSI. Read more in our comparison article: Why the Microsoft 365 Spam Filter Alone Is Not Enough.
Phishing protection is not an optional add-on but a business-critical investment. The combination of technical gateway protection and employee awareness forms the most effective defense.
Conbool MailGuard provides this technical protective layer: AI-based, upstream, and seamlessly integrated into existing email infrastructures.
Start your free trial or contact us for a personalized consultation.