UK’s trusted IT infrastructure partner since 2003
sales@servnetuk.com
0800 987 4111
Servnet
ConfiguratorGet in Touch
AI Email & SaaS Security
Abnormal Security

Stop the attacks
your SEG misses.

Abnormal Security uses behavioural AI to stop business email compromise, account takeover, supply chain fraud, and SaaS attacks — the kind with no malicious links or attachments that bypass every traditional gateway. Recognised as a Gartner Magic Quadrant Leader for Email Security Platforms.

Abnormal by the numbers
Enterprise customers globally2,500+
BEC losses prevented for customers$1.8B
Signals analysed per email message20M
Deployment time — API-only, no MX changes5 min
FBI-reported BEC losses in 2023 (industry)$2.9B
Gartner MQ Leader — Email Security Platforms 2024#1
Cloud Email Security

Stop more attacks. Fully automate operations.

Abnormal's core email products stop advanced attacks while autonomously handling triage and remediation — so your team focuses on strategy, not alert queues.

✉️
BEC · Phishing · Social Engineering

Inbound Email Security

Stops email attacks with autonomous AI — BEC, spear phishing, vendor impersonation, and socially engineered attacks that contain no malicious links or attachments. Behavioural AI models trained on thousands of identity signals detect attacks that secure email gateways miss entirely.

🔓
Compromised Account Detection & Response

Email Account Takeover Protection

Detects and mitigates compromised Microsoft 365 and Google Workspace accounts by analysing behavioural anomalies — suspicious logins, mail rule creation, forwarding configuration, and OAuth app consent. Automatically remediates compromised sessions and terminates attacker access.

🛡️
Microsoft 365 Misconfiguration Detection

Security Posture Management

Continuously identifies Microsoft 365 misconfigurations, legacy authentication protocols, exposed API connectors, and Shadow IT integrations that create risk — surfacing gaps before attackers exploit them, with prioritised remediation guidance.

📬
Personalised Graymail Filtering

Email Productivity

Maximises inbox productivity by intelligently filtering graymail — newsletters, promotional emails, and bulk mail — using personalised behavioural models. Learns individual preferences to keep inboxes clean without accidentally removing legitimate business communications.

↩️
Accidental Data Leak Prevention

Misdirected Email Prevention

Prevents data leaks caused by emails sent to wrong recipients — detecting when email content, recipients, or context suggests an accidental misdirection and alerting the sender before the message leaves the organisation.

AI Security Agents

Autonomous AI agents that eliminate repetitive work.

Abnormal's AI Security Agents handle the manual tasks that consume analyst time — triage, coaching, and reporting — at superhuman speed and scale.

🤖
Autonomous Email Triage Agent

AI Security Mailbox

Responds to reported emails and coaches users at superhuman speed — analysing every user-reported suspicious email, providing instant verdicts, and sending personalised guidance. Eliminates the manual triage backlog that burdens SOC teams, freeing analysts for complex investigations.

🎣
Hyperpersonalised Security Awareness Training

AI Phishing Coach

Delivers hyperpersonalised security awareness training based on each individual's actual susceptibility patterns — sending targeted, context-specific coaching in the moment of risk. Reduces phishing susceptibility without mandatory annual training programmes.

📊
Board-Ready Security Reporting

AI Data Analyst

Provides personalised, board-ready security reporting through natural language queries — answering questions like "What are our top email threats this quarter?" and generating visualisations and executive summaries without manual report building.

SaaS Security

Protect cloud apps beyond the inbox.

Abnormal extends AI behavioural protection beyond email to the SaaS applications where modern business happens — Slack, Teams, Zoom, and Salesforce.

💬
Slack · Zoom · Salesforce & More

SaaS Account Takeover Protection

Detects and prevents account takeovers across SaaS applications including Slack, Zoom, and Salesforce — applying the same behavioural AI that protects email to collaboration and business applications where attackers increasingly operate.

📱
Microsoft Teams Threat Detection

Messaging Security

Detects malicious content shared in Microsoft Teams — including phishing links, malware-laden files, and impersonation attacks conducted via chat rather than email. Extends Abnormal's behavioural protection to the collaboration layer of the modern workplace.

Platform in Action

See Abnormal stop real attacks

Every stopped threat is backed by contextual evidence, behavioural signals, and a clear explanation of the AI verdict — so analysts understand exactly why each email was flagged.

Abnormal Security explainable AI threat detection dashboard showing contextual evidence, identity signals, communication history, and analyst verdict for a business email compromise attack attempt
Abnormal AI threat detection — explainable verdicts with full behavioural context for every blocked BEC attempt
Abnormal Security automated threat remediation — AI autonomously detecting and removing BEC, phishing and social engineering emails from employee inboxes before user engagement, with 4x fewer inbox threats
Autonomous remediation — AI removes threats before users can engage
Abnormal Security unified threat console with custom quarantine controls, SOAR integration, URL rewriting, and Microsoft 365 quarantine release for enterprise email security operations
Unified console — custom controls, SOAR integration, and Microsoft quarantine management

Why organisations choose Abnormal

🎯
Stops attacks that SEGs cannot detect

Secure Email Gateways (Mimecast, Proofpoint) use reputation and signature-based detection. They miss targeted BEC attacks with no links, no attachments, and no known-bad indicators. Abnormal's behavioural AI catches these by detecting deviations from established communication patterns — not matching against known bad.

One-click API deployment — no MX record changes

Abnormal connects to Microsoft 365 or Google Workspace via API — no MX record changes, no mail flow modification, no policy migration required. Live within minutes. Reaches full effectiveness within 24–48 hours as behavioural baselines are established from historical email data.

🧠
20 million signals analysed per email

Abnormal analyses over 20 million signals per email — sender identity, behavioural patterns, writing style, communication graph, infrastructure attributes, and cross-platform activity — generating a precise risk score for every inbound message.

📊
Recognised — 2024 Gartner MQ for Email Security Platforms

Abnormal Security was recognised as a Leader in the 2024 Gartner Magic Quadrant for Email Security Platforms — validating its AI-native approach as the new standard for enterprise email protection.

🏢
2,500+ enterprise customers globally

Over 2,500 enterprise organisations use Abnormal — across financial services, healthcare, manufacturing, retail, and public sector. Customers include companies that already run Mimecast or Proofpoint and layer Abnormal on top to catch what their SEG misses.

🔗
Integrates with existing security operations

Native SIEM, SOAR, and XDR integrations streamline response workflows — forwarding structured threat data to Splunk, Microsoft Sentinel, Palo Alto Cortex XSIAM, and other platforms. Abnormal's Knowledge Bases (PeopleBase, VendorBase, AppBase) provide behavioural context across integrations.

Frequently asked questions

What is Abnormal Security?

Abnormal Security is an AI-native cloud email security platform that protects Microsoft 365 and Google Workspace from advanced email attacks including business email compromise (BEC), spear phishing, vendor fraud, account takeover, and supply chain attacks. Unlike traditional secure email gateways, Abnormal uses behavioural AI — building a unique identity model for every user, vendor, and counterparty to detect threats that have no malicious indicators.

What products does Abnormal offer?

Abnormal organises its platform into three categories: Cloud Email Security (Inbound Email Security, Email Account Takeover Protection, Security Posture Management, Email Productivity, Misdirected Email Prevention), AI Security Agents (AI Security Mailbox, AI Phishing Coach, AI Data Analyst), and SaaS Security (SaaS Account Takeover Protection for Slack/Zoom/Salesforce, and Messaging Security for Microsoft Teams).

How is Abnormal different from Mimecast or Proofpoint?

Mimecast and Proofpoint are Secure Email Gateways (SEGs) that filter email using reputation, signatures, and rule-based detection — effective for known spam and mass phishing. Abnormal is designed to catch what SEGs miss: targeted BEC attacks with no links or attachments, vendor impersonation using legitimate domains, and account takeover by compromised internal users. Most Abnormal customers deploy it alongside their existing SEG as a second layer.

What is Business Email Compromise (BEC)?

Business Email Compromise is a targeted attack where fraudsters impersonate executives, vendors, or trusted partners to deceive employees into making fraudulent payments or transferring sensitive data. BEC attacks contain no malicious links or attachments — they rely entirely on social engineering and impersonation — which is why traditional email security tools consistently fail to detect them. The FBI IC3 reported $2.9 billion in BEC losses in 2023, making it the most financially damaging cybercrime category.

Can Abnormal detect when an internal account is compromised?

Yes. Abnormal Email Account Takeover Protection monitors all Microsoft 365 and Google Workspace account activity — logins, mail rule changes, forwarding rules, OAuth app consent, and API access — and detects anomalies indicating a compromised account. Automated response terminates active sessions, revokes suspicious mail rules, and alerts the security team. This works for both human accounts and compromised service principals.

Does Abnormal protect platforms beyond email?

Yes. Abnormal SaaS Account Takeover Protection extends protection to Slack, Zoom, Salesforce, and other SaaS platforms — detecting compromised accounts sending malicious content in business applications. Messaging Security covers Microsoft Teams specifically. The AI Security Mailbox and AI Phishing Coach work across all integrated platforms to automate triage and reduce human susceptibility.

Deploy Abnormal Security

Servnet will connect Abnormal to your Microsoft 365 or Google Workspace tenant — no mail flow changes, no downtime, active within minutes.

Talk to a Specialist →All Cyber Security
Solutions we deliver

Use Abnormal Security as part of a complete solution

Email SecurityRansomware ProtectionSecurity Awareness Training