Why Financial Firms Need More Than a Secure Email Gateway
Secure email gateways cannot catch the wrong-John problem. See why financial firms are adding behavior-based email security, and what it actually catches.
Secure email gateways cannot catch the wrong-John problem. See why financial firms are adding behavior-based email security, and what it actually catches.
Banks and investment firms are reaching the limits of secure email gateways, and the reason is specific. So a gateway checks whether a message looks technically bad. It cannot tell a real wire request from a fake one, when both come from a trusted account. That gap is where most financial sector email losses now happen. Closing it needs a different kind of tool, not a stricter version of the old one.
Table of Contents
ToggleEvery industry faces phishing, but finance faces something sharper. One approved email can move real money in minutes. That approval often rests on one person’s judgment, under time pressure.
Business email compromise shows exactly where that judgment gets exploited. For example, FinCEN’s own analysis of reported incidents found a median loss near $137,000 per case. Wire transfers made up the large majority of how that money actually left. Vendor email compromise drove well over half of total losses, tracked by the Anti-Phishing Working Group. That is when an attacker takes over or copies a supplier’s account, not an executive’s. None of those emails needed to look sloppy. They just needed to look like Tuesday.
Still, a secure email gateway earns its keep on volume. It checks sender reputation, scans links and attachments, and blocks what matches known-bad patterns, before a message reaches the mailbox.
| Question a gateway can answer | Question it cannot |
|---|---|
| Is this sender on a blocklist? | Is this wire request unusual for this sender? |
| Does this link lead to known malware? | Is this the same “John Smith” the firm actually banks with? |
| Does this attachment contain a known exploit? | Does this message match how this vendor normally writes? |
The right-hand column is where financial fraud actually lives now. So an email from a truly hacked vendor account passes every check in the left column. Nothing about it is technically wrong. The fraud sits in the relationship, not the payload.
Discover how Threatcop protects your workforce from modern cyber threats.
At financial firms, compliance teams have a name for this: the wrong-John problem. A wealth manager has a client named John Doe. Meanwhile, an attacker researches the firm through public filings or a past breach, and learns this too. They register a lookalike domain, or hack a real vendor mailbox. Then they send a portfolio request as a different John Doe, one outside the firm.
Yet a gateway sees a normal email to an outside address and does nothing. External email is not suspicious on its own. What catches this is behavior analysis. Does this sender-recipient pair match the relationship on file? That question needs context a gateway was never built to hold.
So this shift away from a pure secure email gateway model is not a hypothetical upgrade path. Gartner’s own research on email security has tracked a new category of tool. It answers the questions a gateway cannot, by sitting inside the mailbox through an API, rather than in front of it.
Meanwhile, compliance pressure makes the shift harder to delay. A locked-down system that blocks every email with a spreadsheet attached slows business to a crawl. A loose one risks a regulatory fine. Checking the sender-recipient relationship itself solves that tradeoff. It only steps in when the pattern looks wrong, not when a message simply holds sensitive content.
As a result, that same system produces something gateways do not. It builds an audit trail tied to risk, not just blocked volume. A risky action, caught and logged at the moment it almost happened, is exactly the evidence a regulator wants. It shows a firm actively manages human risk, not just email traffic.
Still, none of this argues for removing the gateway. It still stops the bulk malware and common phishing that behavior tools are not built to triage at scale.
So technology narrows the gap for financial firms. It does not close it alone, because a person still makes the final call to approve a wire.
Threatcop Security Awareness Training (TSAT) builds that judgment through role-based simulations. One uses a fake CC format, which mirrors exactly how a wrong-John attempt borrows internal authority to look real. Its Employee Vulnerability Score then shows which staff in payments and client-facing roles need coaching. A wealth manager and a receptionist do not carry the same risk. Average breach time, meaning how long from a convincing lure to a bad action, gives compliance a number that maps straight to the exposure window regulators ask about.
So financial firms are not outgrowing email security in general. They are outgrowing a model built to catch bad files and bad senders, in a world where the costliest attacks use neither. So add behavior analysis for the relationships a gateway cannot see. Pair it with real-time DMARC visibility on your own domain. Keep a human check for anything involving money. Train the people who make the final call. The firms getting hurt are not the ones with weak filters. They are the ones still asking their gateway a question it was never built to answer.
Gateways check whether a message is technically bad, for example a bad link or a known-bad sender. They cannot judge whether a wire request is unusual for a specific relationship, which is exactly how modern business email compromise against finance succeeds.
The wrong-John problem at financial firms describes an attacker using a common name, or a hacked vendor account, to redirect what looks like a real request. A portfolio transfer is a common target. The email passes every technical check, because nothing in it is bad in a way a filter can detect.
FinCEN’s analysis of reported incidents found a median loss near $137,000 per case. Wire transfers were the main way funds left. Vendor email compromise alone made up well over half of total BEC losses tracked industry-wide.
Not necessarily, because gateways still handle bulk spam and known malware well. The real gap is in behavior and relationship-based detection. That is a layer added alongside the gateway, not a straight swap for it.
At financial firms, training builds the judgment that no secure email gateway can fully replace, because a person still approves the final payment or data transfer. Role-based simulations that mirror real fraud patterns show whether that judgment is actually improving. Metrics like repeat-offender rates prove it, rather than assuming it.
Yogyata Sethi is a finance professional at Kratikal with experience in financial analysis, business operations, and corporate finance. She has contributed to key business initiatives, including strategic growth and the company’s public listing journey. Currently pursuing an MBA in Finance, Yogyata is passionate about financial planning, business strategy, and data-driven decision-making. She focuses on creating insights that support sustainable growth and long-term business value.
Yogyata Sethi is a finance professional at Kratikal with experience in financial analysis, business operations, and corporate finance. She has contributed to key business initiatives, including strategic growth and the company’s public listing journey. Currently pursuing an MBA in Finance, Yogyata is passionate about financial planning, business strategy, and data-driven decision-making. She focuses on creating insights that support sustainable growth and long-term business value.
S/MIME, Microsoft 365 Message Encryption, and password-protected files all work differently. See which one to use and how to...
Preventing phishing now means managing human risk as an ongoing program, not a yearly training. See the four parts,...
Adaptive email security judges behavior continuously, not just at delivery. See the real Gartner model behind it, its limits,...
Table of Contents
×