Forrester's analyst covering this market describes what preceded the current period as a decade of stagnation, followed by what he calls the "golden age of email security", still running through 2023 and 2024.

Ten years of stagnation in the security category that defends the channel through which most attacks arrive is a remarkable thing to admit. Email has been the primary initial access vector for as long as anyone has measured it, and the tooling defending it went a decade without meaningful change.

Understanding what ended that is the most useful thing in this market, because it explains both the current vendor list and the category's new name.

The gateway and its blind spot

For most of that decade the architecture was the secure email gateway. You pointed your mail exchange records at the vendor, mail flowed through their infrastructure, they inspected it, and clean mail continued to your platform.

That model works against mail arriving from outside and is structurally blind to everything else.

Internal email never passes through it. A compromised account emailing four hundred colleagues with a malicious link goes directly from the mail platform to the recipients, and the gateway sitting at the perimeter sees nothing. Given that account compromise is how a large share of significant incidents progress, that is not a minor gap.

The gateway also cannot see what happened after delivery. A message that was clean on arrival and whose linked destination was weaponised two hours later is already in the inbox.

API-based architecture changed this. Rather than sitting in the mail path, these platforms connect to the mail and collaboration platforms directly, seeing all mail including internal, retaining the ability to retract messages already delivered, and observing behavioural context across the whole environment rather than one message at a time.

Forrester's characterisation of Abnormal AI as part of a new guard of API-based vendors that shook up a stagnant market is a description of that architectural shift rather than of one company.

The behavioural approach follows from the architecture. A platform that can see every message a person normally sends and receives can identify the unusual one. A gateway inspecting a single message in isolation can only ask whether it contains something known to be bad.

Why the category was renamed

Forrester renamed this market from its 2023 predecessor, and its explanation is worth reading as threat intelligence rather than as taxonomy.

Attackers are shifting to other entry points, running targeted multistep campaigns that include voice and text, and exploiting SaaS platforms, internal messaging applications, collaboration tools, and file-sharing environments. These are essential to modern work and they are vulnerable.

The consequence Forrester draws is that organisations must take a more holistic approach to securing the human element, ensuring these tools receive the same protection as the inbox.

The multistep detail is the important one. A campaign that begins with a text message, moves to a voice call, and ends with a request in a collaboration channel never touches email at all. Each step is individually unremarkable and the sequence is the attack.

That is genuinely hard to defend with tools organised by channel, and it is the argument for a platform that observes across all of them. It is also why collaboration platforms are now in scope: a message in an internal channel carries an implicit trust that an external email does not, and attackers understand that.

Inside The Forrester Wave: Email, Messaging, And Collaboration Security Solutions, Q2 2025

The evaluation scored ten vendors against twenty seven criteria: Abnormal AI, Barracuda, Check Point Software Technologies, Cloudflare, Darktrace, Google, Microsoft, Mimecast, Proofpoint, and Trend Micro.

Abnormal AI placed as a Leader with the highest score in the strategy category and maximum scores in vision, innovation, roadmap, malicious message and account compromise detection, and AI models, training, and explainability, alongside above-average customer feedback.

Proofpoint also placed as a Leader.

Mimecast placed as a Strong Performer, and Forrester's assessment situates it interestingly: a well-established vendor with private equity backing, a new chief executive, and a series of strategic acquisitions, building a human risk management platform with email, messaging, and collaboration protection as a key pillar. Forrester positions it for customers wanting a holistic view of human risk alongside protection across communication channels.

Cloudflare placed as a Strong Performer with maximum scores in nine criteria, positioned by Forrester for organisations augmenting existing tooling with deep content analysis and malware detection rather than replacing it.

That positioning is worth noting because it describes a layering strategy rather than a displacement one, which is how a meaningful number of organisations actually deploy in this category.

A period of digestion

Forrester's assessment of where the market sits now is candid. The threat and AI landscape will probably prevent another prolonged stagnation, but many vendors are in a period of digestion, integrating acquisitions and new capabilities.

That framing matters for anyone buying in the next year.

The golden age was driven by acquisition activity, private equity investment, venture funding, and generative AI innovation. What follows a period like that is integration, and integration is where acquired capability either becomes part of a platform or remains a separate product behind a shared logo.

The practical diligence question is the same one that applies to any assembled platform. Ask to see a detection that could only have been produced by correlating signals from two originally separate products. If the answer is two findings displayed adjacently, the integration is presentational.

The related question is roadmap honesty. A vendor in digestion has engineering capacity committed to integration work that produces no new customer-visible capability, which is the correct investment and means the roadmap for the next eighteen months is thinner than it looks.

The convergence with human risk

Mimecast's positioning around a human risk management platform points at a real convergence, and Forrester's own framing supports it: these solutions must protect employees from harmful messages and deliver timely awareness and training prompts encouraging vigilance and safe data practices.

Protection and training in one product is a meaningful change. The traditional split had a security tool blocking threats and a separate awareness platform running quarterly training and periodic phishing simulations, with no connection between them.

Combining them enables something better. A person who clicks something risky can receive an intervention at that moment, in context, about the specific thing they did, rather than a training module three months later about phishing in general. Behavioural evidence from the security tool can target training at the people whose behaviour actually warrants it.

It also imports the governance questions that come with human risk management. Per-person behavioural data held by security, individual risk scoring, and the works council and data protection considerations that follow in several European jurisdictions apply here as much as they do in a dedicated human risk platform.

The practical position is the same one: be explicit that the data serves protection rather than performance management, and write that down before anyone asks.

Both sides have the same tools

The AI dynamic in this category is unusually symmetrical, and it has invalidated a decade of user training.

The advice was to look for poor grammar, generic greetings, awkward phrasing, and implausible urgency. Those were reliable signals because attackers operating at volume could not write well in every target language.

That constraint is gone. Convincing text in any language is now cheap, which means the heuristics people were trained on no longer discriminate. Worse, they produce false confidence: someone who was taught to spot bad grammar and sees good grammar concludes the message is legitimate.

Voice cloning removes the standard fallback of calling to verify, which is the specific reason Forrester's description of multistep campaigns including voice matters.

On the defensive side, the same capability improves detection. Abnormal's maximum score in AI models, training, and explainability points at where the competition sits, and explainability is the part worth pressing on. A behavioural model flagging a message as anomalous needs to tell an analyst why, because a queue of unexplained flags is a queue nobody works.

The net effect is that detection is moving from content inspection toward relationship and behaviour analysis. Whether this sender normally emails this recipient, whether this request fits the established pattern, whether the payment instruction differs from every previous one from this supplier. Those signals survive good grammar.

What this leaves for the organisation

The uncomfortable residue is that the attacks this category struggles most with are the ones with no malicious content at all.

A business email compromise message asking to update bank details for an invoice contains no link, no attachment, and no malware. It is a plausible request from a plausible sender about a real relationship. Detection depends entirely on knowing that this is not how that supplier normally communicates, which is a behavioural judgement rather than a content one.

Even a good platform will sometimes let one through, which is why the durable control is a process rather than a product. Payment instruction changes verified through a separately established channel. Approval thresholds that require a second person. A culture where checking an unusual request from an executive is expected rather than career-limiting.

The technology raises the floor considerably and that is worth paying for. The residual risk sits in the process, and it is the part that no vendor in this evaluation can sell you.

Analyst Source

Forrester Research

Category definition, vendor inclusion, and evaluation findings in this article draw on Forrester's coverage of email, messaging, and collaboration security. The Q2 2025 Wave scored 10 vendors against 27 criteria and renamed the category from its 2023 predecessor to reflect attacker movement into messaging, collaboration, and file-sharing environments.

Source research

Forrester does not endorse any vendor named here, and tier placement should not be read as a recommendation to buy.