- HOME
- Email security
- Prevention vs. response: Why email security can’t just be about blocking
Prevention vs. response: Why email security can’t just be about blocking
- Last Updated : August 28, 2026
- 8 Views
- 5 Min Read
In 2023, a finance employee at a multinational firm transferred $25 million after participating in a video call with people she believed were her colleagues and CFO. Every person on that call was a deepfake. No malicious attachment was involved. No link was clicked. The attack bypassed every layer of technical filtering because it never passed through a filter at all.
That example is extreme, but the underlying dynamic isn’t. A significant category of email-based attacks is specifically designed to look like normal business communication. They don’t carry malware. They don’t trigger URL scanners. They arrive, they’re read, and then something goes wrong. A wire transfer is approved, credentials are shared, a vendor relationship is exploited. By the time IT is aware, the damage is done.
This is the gap that a blocking-only approach to email security cannot close.

Why blocking became the default
Email security has historically been synonymous with filtering. Spam filters, antivirus scanning, attachment sandboxing, URL rewriting, and other such tools exist to stop threats before they reach the inbox. For a long time, this worked reasonably well. The majority of email threats were volume-based: mass phishing campaigns, malware-laden attachments, obvious scam attempts. Blocking them at the gateway was the logical and largely effective response.
Vendors built products around this model, and IT teams measured success accordingly. A low spam rate and a clean inbox were signs that the system was working. In this context, security becomes a gate.
The problem is that the threat landscape has moved faster than the blocking model has adapted.
What blocking cannot catch
Modern email attacks increasingly exploit trust rather than technology. Business email compromise (BEC) is the clearest example. In a BEC attack, a threat actor impersonates a trusted figure such as a CEO, a finance director, a known vendor, and requests an action: a payment, a credential, a document. The email often contains no malicious payload whatsoever. It is, by most technical definitions, a clean message.
Conversation hijacking takes this further. Attackers gain access to a real email thread, often through a compromised account, and insert themselves into an ongoing exchange. Recipients see a familiar name, a familiar subject line, and a message that follows naturally from what came before. Filters have no basis on which to flag it.
AI-generated phishing adds another layer of difficulty. Where earlier phishing attempts were often identifiable by awkward language or generic templates, LLM-assisted attacks can now produce contextually appropriate, well-written messages at scale. The volume-based signals that trained spam models to recognize phishing are becoming less reliable as the quality of malicious content improves.
The FBI’s Internet Crime Complaint Center consistently ranks BEC among the costliest categories of cybercrime. This isn’t because it’s the most common, but because the losses per incident are high and the attacks are difficult to detect before they succeed.
None of these attack types are unstoppable. But they require a different kind of capability to catch. The protection mechanism has to operate after delivery too, not just before it.
The response layer: What it is, and why it’s missing
Response, in the context of email security, refers to everything that happens after a suspicious or malicious message has reached an inbox. It includes:
- Detection after delivery: The ability to identify a threat that wasn’t caught at the gateway, through user reports, behavioral signals, or retrospective analysis.
- Investigation: Access to a complete, searchable record of email activity, so that when an incident is reported, the scope can be assessed quickly.
- Containment: The ability to pull a message from inboxes across the organization once a threat is identified.
- Audit and compliance: A tamper-evident record of communications that can support incident response, legal review, or regulatory requirements.
Most SMB and mid-market IT teams have incomplete coverage across these four areas. Detection after delivery often relies on users self-reporting. This often turns out to be an inconsistent and slow mechanism. Investigation is difficult without a proper archive, because email logs are either incomplete or not readily searchable. Containment tools are frequently absent from entry-level security products. And audit capability is often treated as a compliance afterthought rather than a security function.
The reason response receives less investment is partly structural. Vendors who sell email security as a blocking product have little commercial incentive to draw attention to what happens when blocking fails. IT teams, measured on uptime and incident counts rather than response time, optimize for prevention. And because response capability only becomes visible during an incident, its absence is easy to overlook until it’s urgently needed.
Prevention and response aren’t competing priorities
It would be a mistake to read this as an argument against investing in prevention. Blocking is still the first and most important line of defense. The goal is to stop as many threats as possible before they reach users. Prevention tools—such as gateway filtering, DMARC enforcement, anti-spoofing controls, and attachment sandboxing—are essential and should be maintained.
The argument isn’t that blocking is insufficient in principle. It’s that blocking is insufficient alone.
A useful analogy is physical security. A building invests in access controls, locks, and perimeter monitoring to prevent unauthorized entry. It also invests in cameras, alarms, and incident response procedures for the scenario where prevention fails. No security team would argue that cameras are unnecessary because the locks are good. The same logic applies to email.
The organizations that handle email-based incidents most effectively are those with both layers in place. They block the majority of threats at the gateway. When something gets through, they have the visibility to detect it quickly, the tools to investigate its scope, and the capability to act before significant damage occurs.
What a complete email security posture looks like
A strong email security posture addresses both the prevention and response sides of the equation. On the prevention side, this means gateway-level filtering, DMARC and SPF enforcement, and controls against impersonation and spoofing. On the response side, it means archiving, audit logs, searchable mail history, and defined procedures for what happens when a threat is reported post-delivery.
For many IT teams, the response side requires a deliberate addition rather than an upgrade to existing tools. The question to ask isn’t just “what does this product block?” but “what can we see, search, and do after an incident begins?”
Zoho eProtect is designed with both layers in mind. Its filtering and threat detection capabilities address the prevention side by blocking malicious messages before they reach users. Its email archiving and audit features address the response side by giving IT teams the visibility and searchable mail history needed to investigate incidents, establish timelines, and meet compliance requirements. For organizations that have historically treated email security as a gateway problem, eProtect offers a way to close the gap without managing separate products.
The baseline has shifted
The cost of a blocked threat is low. The cost of an undetected one, especially a BEC attack or a compromised account that goes unnoticed for days, can be significant, both financially and reputationally.
Email threats have matured to the point where the question is no longer whether a sophisticated attack will occasionally get through, but how quickly it will be caught when it does. Organizations that have only invested in blocking are well-prepared for the first question and largely unprepared for the second.
Closing that gap isn’t a matter of replacing prevention with response. It’s a matter of recognizing that a complete email security posture requires both, and building accordingly.


