Sep 09 2026
Security

Q&A: Email Security Evolves as AI Assistants Proliferate

SMBs must double down on email security and rethink resilience as they increasingly put AI assistants on the job, Barracuda Networks’ Brian Downey says.

Email is no longer just a human-centric communication platform but an operational fabric where humans and AI interact. That means it's also a much larger and more lucrative target. As AI assistants become an essential part of everyday work — reading, summarizing, routing or acting on email before an employee reviews the full message — it’s time for small and midsized businesses to take a harder look at email security.

Inbox access, employee use of AI assistants, new potential for account compromise, and post-delivery risks all must be reviewed. New findings released recently by Barracuda Research highlight how quickly modern email attacks can escalate. A single phishing email recently progressed to identity theft, multifactor authentication bypass and endpoint compromise in minutes, demonstrating the sheer speed at which attacks can move beyond the inbox and the damage they can unleash. BizTech recently sat down with Brian Downey, senior vice president of product management at Barracuda Networks, to discuss email security for SMBs and how effective security should evolve alongside agents.

Click the banner below to learn why cyber resilience is essential to enterprise success.

 

BIZTECH: How are AI assistants impacting small businesses’ security posture? What’s happening? 

DOWNEY: We’re seeing the merging of two things. Email communication has always been a massive thing people tried to use for criminal activity. Most of us, when cybersecurity was emerging, saw threats via email, whether through attachments to emails or messages from a Nigerian prince asking for $10,000. For a long time, attacks were focused on the end user of an email, so even as ransomware came up, it was trying to get a user to take an action so it could ransom their computer. AI is changing the dynamics of these types of attacks. 

In the second wave that’s now hitting us, email is no longer human to human. Probably a lot of us have different rules set up via AI so that it can summarize emails and tasks like that. What a lot of people don’t realize is that, as AI goes through processes to summarize an email, it opens payloads associated with that email and looks at your attachments. That’s why it does such a good job giving you information back. At the same time, it inherently changes the way you need to secure your email. It’s accelerating everything. As AI looks at things instantaneously, AI takes actions much faster than a human might. That opens a window of opportunity for attacks, which propagate more quickly than we’ve ever seen before.

DISCOVER: The cybersecurity solutions and services that can help your business.

BIZTECH: It’s true: You’re letting someone into your email and you’re opening the door to these potential threats. How does the security approach change? 

DOWNEY: There are a few different things people need to start focusing on. First, some of the old security constructs, while they’re still important, might need to be complemented with other things. For example, user awareness training is important and should continue. That said, you can see how it would get bypassed in this situation. We can spend all the time we want telling an end user how to look at a phishing email, but if AI ultimately clicks on it, we need to realize that it’s been picked up already. We need to start looking at some of the dynamic changes.

Click the banner below to get small business insights delivered to your inbox weekly.

 

BIZTECH: What needs to be a part of that layered approach?

DOWNEY: There are two times when you can inspect an email and determine whether it is malicious. One is predelivery, before it hits your inbox. It’s very important and really starts to separate some of the less sophisticated attacks, a lot of spam-type things. It’s a really effective method that we continue to promote, but it should be complemented by post-delivery security, which continues to inspect your inbox after something’s delivered. When attackers use AI, they can do things that are much more sophisticated than what we’ve seen in the past. A good example of that is we’re now seeing enormous growth in emails that start as benign, they’re permitted in an inbox, but then they’re weaponized after delivery. This shows you the constant need for reinspecting emails in an inbox, to make sure they maintain their benign position post-delivery. Looking at your capabilities and what happens if an attack gets through, ensuring you’re resilient in those cases, monitoring what’s happening and making sure that when something happens, you have automated workflows that immediately kick in to take things off a network and contain the attack so it doesn’t grow any larger.

Start with predelivery. This is where you catch and remove a lot of the noise out of your email. This is where you can get rid of spam. Some of the less sophisticated attacks come from that side of email protection. The good news is that it’s becoming more robust. Second, you want to make sure you’re layering that with post-delivery security. This is based more on application programming interfaces and allows a lot more use of AI analysis and behavioral analysis of what’s happening with an email, which is enormously powerful. This is how you can start removing those email-based attacks that are weaponized after delivery, and also thwart a lot more of the advanced attacks. 

The third piece is some sort of detection and response associated with your email. You need to be monitoring what people are doing, the patterns of how messages are sent and who’s sending them, looking for anomalies, quickly investigating them, and when something is deemed a potential risk, immediately containing it.  

UP NEXT: How to detect and prevent a “man in the middle” attack.

BIZTECH: How can lean, small business IT teams maintain control over all of this without adding more complexity? 

DOWNEY: First, look at centralizing management and security. One positive that’s come up in security recently has been the move away from point products toward platforms, and that’s something we’ve embraced. Something that gives you more centralization for managing your email security. It’s okay to use multiple tools — in fact, I’d recommend it — but you need to make sure that if those tools come from different vendors, you maintain a centralized way of managing them efficiently. Second, they need to be able to leverage as much AI as possible. Often, we focus on the negatives, but a strong positive of AI is that it’s added a level of simplicity to everything we do.

The critical thing SMBs should be looking at is ease of use: Is this something that will scale with me as an organization and provide the efficiency and the simplicity I need? People need to make sure they understand how this plugs into their larger cybersecurity platform — an umbrella that covers all of your security — and the more sharing that happens across that, the more powerful your security will be. The more that data is pulled together, the more effective it is. 

SMBs also need something that they are confident has a level of completeness and depth that will support them. Anyone working with any vendor right now should really be looking at how they’re using AI for defense. How are they leveraging AI and their models underneath to understand the more sophisticated attack types? How are they using AI to simplify the experience? Ask hard questions about that.

Brian Downey, Barracuda Networks
We often focus on the negatives, but a strong positive of AI is that it’s simplified almost everything we do.”

Brian Downey Senior Vice President of Product Management, Barracuda Networks

 

BIZTECH: Can we go back to your statement about emails being weaponized after delivery? How does that happen? 

DOWNEY: What we see now is emails that come in and they might point to a link, for example. That link might be one that’s reputable or one that, at face value, looks absolutely benign and safe to click on. The attackers are intelligent and advanced enough now that they won’t turn that link into a malicious site until after the emails have been delivered. Now they’re doing large campaigns, pushing that out to all their users and then a day later, suddenly the site becomes malicious. Emails will stop being delivered based on that, but what about the emails that are already there? You want to make sure that you understand that they’re there and to claw them back out of user accounts. That has to be done in real time. And again, AI is the one reading this, and it’s reading frequently. We need to make sure is it’s not going to navigate to that link.

In a lot of our recent research, we’ve also seen a shift away from malware. Today, it’s frequently the velocity of an attack that’s changing dynamically. We’re seeing almost 10% of attacks, about 1 in7, are reusing credentials to deploy other attacks. So, on the propagation side of it, we’re seeing attacks changing and morphing as they’re discovered. We’re also seeing more advanced phishing attacks, which are now diving into identity theft and bypassing multifactor authentication to compromise endpoints. We’re seeing the speeds as well as the danger with email is that it is the point of entry, it’s not the attack itself.

DISCOVER: Find out how mature your security posture is with a self-assessment.

BIZTECH: Email AI assistants were a kind of early win, right? They’re something that, by and large, has been around. The assumption was that it’s safe or doesn’t require a lot of thought. 

DOWNEY: Every technology introduces risk. As people started using work email on their iPhones, that was a risk. As people started implementing bring-your-own-device policies, there were new risks. I think it helps companies in so many ways, but as we go through these changes, it’s just really important to understand what the risks are and make sure that you’re a step ahead of those — that you feel comfortable with the risks that you’re taking and that you’re protected against the ones that you’re not comfortable with.

BIZTECH: Should SMBs be wary of deploying AI tools or assistants to help them sort out email and work through this, given the types of threats that are out there now? 

DOWNEY: It’s a really hard place for companies right now. You never want to see a trade-off between innovating and driving efficiencies and improving your customer experience and ensuring security, and that’s where too many users are right now. I would have a hard time discouraging any small business from using AI. I’d probably go on the opposite side and say you probably need to use more AI. You need to look at how your industry is going to change with AI and start getting ahead of that curve, because every industry is going to change. 

People need to first make sure that they’re confident that as they start using AI, they’re going to be well protected. I think that that’s a question they have to ask if they’re using a managed service provider. If you don’t feel confident in that level of protection, I would say you need to pause and increase that confidence, but I don’t think the right answer is to stop using AI. It’s critical that you continue that path toward AI but do it pragmatically and be sure that you have the security in place that’s needed. And that goes beyond email; AI security is a bigger topic than just email.

Ken Richardson
Close

New Research from CDW Explores AI and Cybersecurity

Learn how AI is helping IT teams manage risk and improve resilience.