Email is the main way most businesses communicate. That makes email the most exploited pathway for cyber criminals to steal credentials and gain access to business systems. Despite decades of email protection strategies, managed service providers (MSPs) and managed intelligence providers (MIPs) now face attacks that are faster, more convincing and harder to catch due to AI. In this blog, we’ll explore what MSPs and MIPs can do to provide the most up-to-date email security to clients in the AI era.
What Is Email Security, and Why Is It So Important?
Email security features and solutions scan and filter incoming email messages to block spam, phishing and malware. They also protect outbound email with encryption and data loss prevention.
Email security may seem like it should be a given at this point, but modern threats are making simple plug-and-play email solutions harder to secure. Standard secure email gateways (SEGs) were built for a world of predictable spam patterns and known malware signatures. But with AI now embedded in how cyber criminals craft their attacks, legacy SEGs are increasingly outmatched, which is exactly why email security has become one of the fastest-growing conversations MSPs are having with clients.
The numbers make the urgency clear:
- 78% of businesses experienced an increase in phishing volume over the last 12 months.
- 84% say AI-generated phishing attacks are becoming harder to defend against.
- 96% expect email security challenges to persist throughout the year.
Small and medium-sized businesses (SMBs) face this problem more acutely. Despite 92% of small businesses investing in security measures, 26% still experienced a cyberattack or data breach in the past year, meaning that it’s more important than ever to continuously monitor threats and act accordingly.
The Top Five Threats Dominating Inboxes Right Now
Email attacks are becoming more sophisticated, and a resilient email security strategy should include every angle threat actors are currently exploiting.
1. Phishing
Phishing remains the most common way threat actors get into a network. It happens when attackers impersonate a trusted sender and steal employee credentials, often by luring them to malicious sites that appear to be the real thing.
Phishing accounted for 58% of observed email attacks across nearly 800,000 sampled attacks and 159 million observed attacks in the second half of 2025. Of these attacks, email accounts for 88% of phishing attacks, making it the biggest cause of data breaches.
And if there were an Olympics of cyberattacks, attackers would have won the gold with a record-fast breakout time in 2025, gaining access and moving beyond the first compromised asset in just 27 seconds.
2. Ransomware
Ransomware groups are increasingly using phishing and stolen credentials as their initial foothold, then encrypting data and holding operations hostage. Ransomware now appears in 48% of confirmed data breaches, up from 44% the year prior.
Ransomware can be quite costly and even sink small businesses, as claims now average $631,000 per incident.
3. Business Email Compromise (BEC)
BEC is a particularly disturbing, invasive and, unfortunately, effective attack. In a BEC attack, threat actors impersonate executives or vendors to trick employees into wiring money or handing over sensitive data. Because it’s done through social engineering, BEC attacks are especially hard for traditional filters to catch.
In 2025, the FBI’s Internet Crime Complaint Center logged $3.05 billion in reported losses. And in 2026, BEC activity reached 10.7 million attacks in Q1 alone.
4. Malware
Viruses, worms and trojan horses may seem like something from the ’90s (or The Odyssey), but they’re still going strong. Analysts detected more than 2.67 million attacks with malware, adware, or unwanted mobile software in Q1 of 2026. And malware accounted for 43% of public sector breaches in Q4 of 2025.
5. AI-Generated Attacks
The newest method of attack is also among the most dangerous because it’s so difficult to detect. And it can be used in conjunction with the rest of the attacks listed above.
In 2025, AI-generated phishing achieved a 54% clickthrough rate, compared with just 12% for traditional campaigns. AI-enabled cyberattacks increased by 89% in 2025 as attackers automated malware creation, fraud and credential theft at scale. And that number is sure to keep growing as threat actors incorporate tactics like AI-generated face and voice cloning, which grew by 500% in Q4 2025.
Put simply, AI can now write personalized phishing emails or clone an executive’s voice in seconds, making it harder for clients and their employees to stay vigilant.
What Is ICES?
Whereas legacy secure email gateways sat in front of the inbox like a bouncer checking identification, integrated cloud email security (ICES) is like the security system that catches people sneaking in the back door. ICES connects directly into platforms like Microsoft 365 or Google Workspace via API, offering real-time visibility into email data, user behavior and threats after messages manage to get into inboxes — and a way to act immediately to counter those malicious messages.
ICES enables:
- Real-time monitoring — continuous insight into email flow and user habits
- Threat-hunting — advanced behavioral analysis that surfaces attack patterns traditional filters miss
- Breach prevention — early detection that stops incidents before they spread
- Timely protection — the ability to eliminate malicious links or claw back a malicious message even after delivery
For MSPs, offering ICES-based protection is a clear differentiator. It positions you as the provider who understands that email security has come a long way from the simple spam filter.
How to Sell ICES
First, you need to make your case. The financial plea for better email security writes itself:
- The average cost of a U.S. data breach reached $10.22 million in 2025.
- Insider-driven security incidents, such as phishing and credential theft, average $13.1 million per organization.
- Organizations with a documented incident response plan save an average of $1.23 million per breach.
- Organizations facing a cybersecurity skills shortage paid an extra $1.57 million per breach in 2025 — a direct argument for outsourcing to an MSP with real expertise.
Once you’ve painted the picture of what having insufficient defenses could mean for their business, ask your client these crucial questions:
- How would you continue operations if ransomware locks down your email?
- If your email servers went down for over a week, how would your employees and customers communicate with one another?
- What’s your recovery strategy if phishing leads to a data breach?
As many cyber insurance providers require specific email security measures, you can review whether your clients have the required features of email security, multi-factor authentication (MFA), segmented backups, security awareness training, and endpoint detection and response (EDR). Then, you can position a complete email security solution that includes:
- Advanced phishing protection — identifies and blocks sophisticated messages designed to trick users into revealing sensitive information
- Antivirus and zero-hour threat protection — eliminates malware before it ever reaches the inbox
- Data loss prevention — stops sensitive information from leaving the organization without proper authorization
- Compliant email retention and archiving — secure storage that meets legal and industry compliance requirements
- Policy-enforced encryption — automatically encrypts messages based on rules like keywords or recipients
- Spam and content filtering — analyzes message content to catch both nuisance and malicious mail
- URL scanning — rewrites and inspects links before a user can click through to a malicious site
- Attachment defense — sandboxes attachments to detect hidden malware before delivery
Together, these layers form a security stack that can stand up to everyday threats and the increasingly complex AI-assisted attacks showing up in client inboxes today.
How to Grow Your Security Practice with Pax8
Email security can serve as a natural entry point into a broader, more profitable managed security practice. Once a client understands their exposure, the conversation naturally extends to MFA, backup, endpoint detection and security awareness training. Continue these conversations to build recurring, multi-layered security revenue instead of one-off deals.
Pax8 makes it easier to deliver not only advanced email protection from leading vendors, but also a full security stack that covers the full spectrum of CIS Controls for best security practices. Fire up Opportunity Explorer within the Pax8 Marketplace to find gaps in your clients’ security posture and sell accordingly.
A solid security approach starts with email. Get in touch to start building your email security strategy and your managed security practice with Pax8.


