For years, cybersecurity has treated employee awareness as one of the most important defences against phishing. Train the workforce. Run simulated phishing campaigns. Teach people to inspect sender addresses. Tell them not to click suspicious links. Repeat. There is value in all of these measures. But there is an uncomfortable question the security industry needs to confront: What happens when the attack is genuinely difficult to recognise?
Why the next generation of email security needs to put people at the centre, not in the firing line
Recent work from the National Institute of Standards and Technology has placed renewed attention on human-centred cybersecurity, examining how security can better account for human factors, usability and behaviour. For MailGuard partners, this represents an important shift in how we should talk to customers about the human element of email security. The answer is not to stop educating employees. It is to stop expecting employees to compensate for security systems that cannot recognise the threat themselves.
Humans are not security controls
Imagine an employee receives an email appearing to come from a supplier. The supplier is real. The employee has an existing relationship with them. The subject relates to an active project. The writing is professional. The sender address looks plausible. There is no suspicious attachment. The request is not completely unusual.
What exactly should the employee be expected to identify?
We often tell employees to look for the red flags. But sophisticated attacks increasingly succeed by minimising those red flags. That does not mean employees are careless. It means the problem is becoming harder.
The training paradox Security awareness training has an important purpose. It helps people understand risk, establishes reporting processes, teaches employees what to do when something feels wrong, and can reduce risky behaviour.
But training has a limitation. It cannot turn every employee into a security analyst. Employees have jobs to do. They should understand cybersecurity, but they cannot reasonably be expected to conduct forensic analysis of every email before acting on it. The more sophisticated the attack becomes, the more unreasonable it is to place the entire burden of detection on the person sitting behind the keyboard.
The real objective: make the safe decision the easy decision
Instead of asking, “How do we train our people not to fall for phishing?” ask, “How do we design our environment so that people have less opportunity to make a dangerous mistake?”
If a malicious message can be identified before it reaches the inbox, the employee does not have to detect it. If a suspicious sender can be identified through behavioural analysis, the employee does not have to investigate the sender's infrastructure.
The human becomes part of the security system, rather than being treated as its final barrier.
What this means for email security
The inbox should be treated as a decision environment. Every message presents a user with an implicit question: Should I trust this?
Security technology should do as much of the risk assessment as possible before the employee has to make that decision. That means analysing sender behaviour and reputation, domain characteristics, message context, indicators of impersonation, suspicious links and destinations, malicious or unusual attachments, communication patterns, and signals associated with credential theft and fraud.
The objective is not to remove people from the security equation. It is to give them a safer environment in which to operate.
The partner opportunity is bigger than email filtering
MSPs and resellers are often the people who can challenge assumptions inside a customer organisation. That makes this more than a technical discussion. It is a governance discussion.
Ask customers what happens after an employee reports a suspicious message. Do they measure how quickly employees report it? Are high-risk roles given additional protection? Can employees easily report something suspicious? How much malicious email reaches the inbox in the first place?
And perhaps most importantly: Are employees being trained to identify threats that technology should have stopped before they ever saw them?
Awareness still matters, but it needs to evolve
The answer is not to abandon security awareness. Employees remain a critical part of cyber resilience. But the role of awareness needs to change. Instead of trying to teach people to recognise every possible attack, organisations should teach employees how to respond safely when something is uncertain. That includes stopping when a request is unusual, independently verifying sensitive requests, reporting suspicious messages quickly, never disclosing credentials or authentication codes, following escalation procedures, and understanding that a familiar name or brand does not automatically mean a message is trustworthy.
The next step for partners
The strongest customer conversations are not about whether employees are good or bad at spotting phishing. They are about whether the organisation has built a security environment that recognises human limitations. The human element is not going away. Nor should it. But the future of email security should not depend on every employee becoming an expert at spotting deception.
Final thought
The idea that employees are the “last line of defence” sounds reassuring. It is not. A last line of defence is what remains when everything else has failed. Modern security should aim to prevent the employee from ever becoming that last line.
For MailGuard partners, that is an important conversation to have with every customer: Are you training your people to carry the burden of email security, or are you building security that works with them?
The distinction matters. And as deception becomes more convincing, it will matter even more.
Keeping Businesses Safe and Secure
Prevention is always better than a cure, and one of the best defences is to encourage businesses to proactively boost their company's cyber resilience levels to avoid threats landing in inboxes in the first place. The fact that a staggering 94% of malware attacks are delivered by email, makes email an extremely important vector for businesses to fortify.
No one vendor can stop all email threats, so it's crucial to remind customers that if they are using Microsoft 365 or Google Workspace, they should also have a third-party email security specialist in place to mitigate their risk. For example, using a specialist AI-powered email threat detection solution like MailGuard.
For a few dollars per staff member per month, businesses are protected by MailGuard's specialist, AI-powered zero-day email security. Special Ops for when speed matters! Our real-time zero-day, email threat detection amplifies your client's intelligence, knowledge, security and defence.
MailGuard provides a range of solutions to keep businesses safe, from email filtering to email continuity and archiving solutions. Speak to your clients today to ensure they're prepared and get in touch with our team to discuss fortifying your client's cyber resilience.
Talk to us
MailGuard's partner blog is a forum to share information; we want it to be a dialogue. Reach out to us and tell us what your customers need so we can serve you better. You can connect with us on social media or call us and speak to one of our consultants.
Australian partners, please call us on 1300 30 65 10
US partners call 1888 848 2822
UK partners call 0 800 404 8993




