Search

Hongke's latest articles

HongKe

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Ut elit tellus, luctus nec ullamcorper mattis, pulvinar dapibus leo.

[Hongke Solutions] As Phishing Emails Become Increasingly Realistic, How Does KnowBe4 Help Businesses Maintain Email Security?

A "Zero-Yuan Takeover" Farce: When the CEO's Orders Actually Came from Hackers

In December 2025, a manufacturing company with annual revenue exceeding 2 billion nearly completed a so-called “strategic acquisition.” It wasn’t until the CFO, following his usual practice, clicked the “Report Suspicious Email” button in an email just before the funds were to be transferred that the entire transaction was halted in time.
The whole incident began when the CEO received an email from a “legal advisor” requesting an immediate discussion of a merger and acquisition opportunity. Over the next three weeks, the two parties exchanged several rounds of seemingly normal emails, negotiating the price terms, due diligence checklist, and payment arrangements—all of which took place entirely via email.
It wasn't until the very last moment before payment was due that the real CEO realized he had never actually given any instructions to proceed with the acquisition.
The attackers didn’t actually use very overt tactics. They didn’t send malicious attachments or include suspicious links, and they didn’t even spoof any domains. They simply compromised the supplier’s email account, spent several months observing communication patterns, and then joined existing conversations in an extremely natural way.
This isn’t a scene from a movie—it’s a true reflection of modern email attacks. As attackers begin to work like employees and speak like business partners, traditional email defenses that rely solely on perimeter blocking are rapidly losing their effectiveness.
According to Verizon’s *2025 Data Breach Investigations Report*, the proportion of AI-assisted phishing emails has doubled over the past two years, and incidents involving third parties have also risen significantly. This means that today’s phishing emails don’t necessarily look like scams; instead, they resemble the legitimate work emails you receive every day.
Phishing emails of the past—which could be identified by typos, odd phrasing, or unusual formatting—are no longer the norm. Today’s attacks are far more dangerous: they come from legitimate accounts, use natural language, provide complete context, and even align precisely with work processes.
This has also forced companies to rethink their approach to email security: when network perimeters are no longer reliable and it’s becoming increasingly difficult for users to distinguish between genuine and fraudulent emails at a glance, what truly needs to be prevented is no longer just the malicious emails themselves, but the moment when malicious interactions occur.
And the very people who are most in need of reassessment are those who were often viewed as the “weakest link” in the past. With the right guidance, training, and tools, employees are not a vulnerability—they can, in fact, become the most effective first line of defense.

Rethinking Email Security: It’s Not Just About Blocking Emails, but Managing Risk

Today, email security is no longer simply a matter of “keeping malicious emails out of your inbox.” More accurately, it is a set of tools, processes, and management methods designed to protect “people” and “information” when they interact via email.
It encompasses both the receiving and sending ends, as well as technical controls and human judgment. The goal is not simply to increase the blocking rate, but to reduce risk and improve the quality of judgment without slowing down work.
In other words, modern email security must accomplish at least three things:
  • Identify and block malicious messages that attempt to manipulate users before threats gain access.
  • Provide risk warnings that are sufficiently clear and timely at the moment of user interaction.
  • Before data is sent, prevent leaks caused by misdelivery, misjudgment, or manipulation.
When attackers shift their focus from “breaching systems” to “influencing judgment,” the battlefield for email security naturally shifts from servers, gateways, and blocklists to users’ perceptions and decision-making.
This is precisely the core focus of KnowBe4’s long-term strategy: integrating cloud-based email protection, cybersecurity awareness training, real-time guidance, and human risk management into a single line of defense. According to official KnowBe4 documentation, its HRM+ platform aims to transform employees from a surface area for attacks into security assets, integrating training, email protection, and risk management modules.

How Does Email Security Work? Four Layers of Protection Throughout the Entire Lifecycle

Level 1: Interception Before Delivery
The first layer is typically handled by a secure email gateway, native email protection mechanisms, or cloud-based email security tools. Before emails reach the inbox, they are filtered to block known malicious domains, spam, malicious attachments, and obviously abnormal sending patterns.
This layer remains important for handling large-scale, standardized attacks, but it is most effective against “known threats”; its effectiveness is limited when it comes to highly realistic, low-noise, context-specific social engineering attacks.
Level 2: Ongoing Analysis in the Inbox
Today, truly dangerous attacks are often not detected at the gateway, but rather begin to wreak havoc only after they have successfully made their way into the inbox.
As a result, modern email security platforms are placing increasing emphasis on post-delivery analysis, such as:
  • Does the sender match the historical interaction pattern?
  • Check whether the tone of the content or the context of the request is unusual.
  • Do links, attachments, and reply threads pose any risks?
  • Does the email exhibit characteristics of BEC or account compromise?
According to KnowBe4 Defend’s public statement, the solution is designed to enhance Microsoft 365’s existing email security capabilities by using AI and behavioral analysis to detect advanced inbound threats that traditional defenses might miss.
Step 3: Pre-shipment Inspection
Email risks don’t just come from external sources; they often stem from unintentional mistakes made internally as well. Common scenarios include sending an email to the wrong recipient, including internal information in an external email, or accidentally sending a sensitive attachment to someone who shouldn’t receive it.
According to publicly available information about KnowBe4 Prevent, this product focuses on managing risks associated with outbound emails and provides real-time alerts before messages are sent—such as when emails are sent to the wrong recipient, sensitive information is shared without authorization, suspicious emails are replied to, or new domains are registered. For businesses, this “hit the brakes before hitting send” mechanism is often more valuable than remedial actions taken after the fact.
Fourth Layer: Continuous Human Defenses
The final layer—and the most critical one—is the user.
No matter how good a system is, it cannot guarantee 100% protection against all threats; however, if employees are willing to pause, think, and click the "Report" button when they see a suspicious request, many attacks can actually be stopped before they succeed.
Both KnowBe4 and official public materials in Taiwan emphasize that the platform supports security awareness training, simulated phishing exercises, and one-click reporting tools such as the Phish Alert Button, enabling users to participate in defense efforts with a lower barrier to entry.

Key Types of Email Security: It’s Not an Either/Or Choice, but a Collaborative Effort

Typecore functionalityApplicable ScenariosKey Limitations
Secure Email GatewayEdge filtering, blocking a large number of known threatsSpam, known malicious attachments, and bulk attacksLimited ability to detect BEC, account takeovers, and scenario-based scams
Cloud-Based Email Security PlatformContinuous analysis via API or native integrationAdvanced Phishing, BEC, and Stealth AttacksRequires deep integration with the email environment
Identity Verification and Email VerificationSPF, DKIM, and DMARC Anti-SpoofingDomain Anti-Spoofing, Improved Email CredibilityWe are powerless to stop emails sent after a legitimate account has been compromised
Safety Awareness TrainingEnhancing the Ability to Identify, Report, and RespondLower Click-Through Rate, Increase Report RateThis needs to be done on an ongoing basis; it can't be accomplished all at once.
Automated Response ToolTriage, Investigation, Isolation, DeletionReducing Stress on Security Teams and Speeding Up Response TimesMust integrate with front-end reporting and email tools
Truly mature email security isn’t just about piling on tools; it’s about integrating these capabilities and empowering users to participate in the process. The Phish Alert Button, when used in conjunction with PhishER Plus, bridges user reports, AI analysis, and follow-up actions, thereby shortening the time from detection to response.

The Top Five Email Security Challenges: How Should Businesses Address Them?

I. Fishing and Spearfishing
This type of attack remains one of the most common and damaging forms. Attackers first gather a large amount of background information, then impersonate a legitimate entity and, using a plausible tone, ask the recipient to take a specific action.
The key is not just to block emails, but to establish a two-step verification process, especially for requests involving money transfers, account changes, contract updates, and access to personal information.
II. Business Email Compromise (BEC)
The greatest danger of BEC is that it often does not involve malware; instead, it relies solely on trust, a sense of urgency, and the authority of the sender’s role to succeed. The FBI’s 2024 IC3 Report shows that BEC caused approximately $2.77 billion in losses in 2024, with cumulative losses nearing $8.5 billion over the three-year period from 2022 to 2024.
Therefore, if the original text intends to cite loss figures, it is recommended to use a more conservative phrasing, such as “BEC continues to cause losses in the billions of dollars,” or to directly use verified range data from recent years.
III. Malware and Ransomware
Nowadays, many attacks no longer rely on obvious attachments but instead use natural language to trick victims into taking actions on their own. This makes it increasingly difficult for defenses that rely solely on signatures or static blocking to be effective on their own.
IV. Leakage of Outbound Data
Many companies actually fail not because of external attacks, but because of a single misdirected email, a message sent to the wrong person, or an attachment sent to the wrong recipient. Products like Prevent have a market precisely because they address those “close calls.”
V. Warning Fatigue
If every email identifies the external sender, every link is rewritten, and every action triggers a prompt, users will quickly come to view security warnings as background noise.
So the truly effective approach isn’t to increase the number of alerts, but to make them more precise and context-sensitive—so that users understand “why this email is dangerous,” rather than just seeing a red box they’ve long since grown numb to.

Best Practices: Creating a Closed-Loop System Where Technology and People Work Together

To ensure email security, why not start with these five steps:
  1. Establish multiple layers of defense, but avoid overlapping functions that could impact efficiency.
  2. Think of SPF, DKIM, and DMARC as foundational infrastructure, not as the ultimate solution.
  3. Make training scenario-based and real-time, rather than limiting it to annual awareness campaigns.
  4. Make the process for reporting suspicious emails as easy as possible.
  5. Continuously optimize using metrics such as click-through rate, response rate, and response accuracy.
According to publicly available information from KnowBe4, the Phish Alert Button allows users to report suspicious emails in real time and remove them from their inboxes; security training and phishing simulations have been shown to significantly reduce an organization’s vulnerability to phishing attacks.

How Does KnowBe4 Enhance Email Security? The Key Is Not to Replace People, but to Empower Them

KnowBe4’s overall strategy is not to rely on a single blocking engine to solve all problems, but rather to integrate inbound detection, outbound protection, user training, reporting mechanisms, and backend automated responses into a closed-loop system.
You can summarize it into the following value propositions:
  • Defend: Enhance advanced inbound threat detection, particularly for BEC and highly realistic phishing emails.
  • Prevent: Block misdirected emails, sensitive data leaks, and abnormal outbound email activity before messages are sent.
  • Security Awareness Training: Develop judgment through ongoing training and simulation exercises; KnowBe4 offers Traditional Chinese content and has a competitive edge in the Taiwan market due to its localized implementation.
  • Phish Alert Button + PhishER Plus: Integrating user reports, AI-powered filtering, and threat response.
  • HRM+: Elevates email security to the level of comprehensive human risk management, focusing not just on individual clicks but on the overall risk profile.

Other Articles

Hongke Dry Goods

[Hongke Insights] Plug the Gaps Before Deploying AI: Minimize Data Breach Risks with “Real-Time Monitoring + Access Control”​

As generative AI and AI agents are widely adopted in enterprises, behaviors such as prompt injection, over-agency, and unintentional data leaks by employees continue to amplify data leakage and compliance risks, creating an urgent need for proactive security solutions. This article leverages the Lepide Data Security Platform to build a comprehensive protection system centered on “pre-deployment governance + in-operation monitoring.” Through real-time sensitive data monitoring, fine-grained permission controls, end-to-end auditing, and automated incident response capabilities, it can integrate with SIEM and SOAR systems to form a closed-loop risk management system. The platform automatically consolidates excessive permissions, and abnormal behavior triggers rapid response measures such as account freezing and system isolation. This addresses the challenges of excessive AI permissions and confidential data leaks while meeting compliance requirements under regulations such as GDPR, thereby establishing a robust data security defense for enterprises implementing AI.

Read more
Hongke Dynamic

[Hongke Solutions] From Passive Defense to Proactive Prevention: Easily Handle Annual Risk Assessments and Security Audits with KnowBe4

Hong Kong’s “Protection of Critical Infrastructure (Computer Systems) Ordinance” requires companies to conduct annual cybersecurity risk assessments and complete independent audits every two years. However, most companies focus solely on technical vulnerabilities while overlooking human-related risks, which account for 80 percent of cybersecurity incidents. KnowBe4 quantifies employee risk through simulated phishing tests, establishes a dynamic risk scoring mechanism, comprehensively retains data on testing, training, and improvements, and enables one-click export of regulatory-grade reports, helping enterprises implement continuous risk management and easily navigate annual assessments and security audits.

Read more
Hongke Dynamic

[Hongke News] Why Rule-Intensive Businesses Are Better Suited for Low-Code: Making Decision Logic “Configurable” Instead of “Hard-Coded”

Many rule-intensive enterprises often face challenges during digital transformation, such as business rules being tightly coupled with underlying code, cumbersome tuning processes, and difficulties in unifying logic across systems. Low-code solutions can transform decision logic into visual configurations, shortening rule iteration cycles and clarifying the division of responsibilities between business and IT. The Decisions platform integrates a low-code environment with a rules engine to independently build a shared decision-making layer. It supports drag-and-drop rule management and cross-system integration and invocation, balancing operational flexibility with IT governance and regulatory requirements.

Read more

Contact Hongke to help you solve your problems.

Let's have a chat