decryptingtech

Technology. Business models. Market debates.

Browse this section

Email and Web Security

Email and web security protect the two places where employees most often encounter untrusted content: the inbox and the browser. They stop malicious messages, links, files and websites; reduce account takeover and business email compromise; and govern sensitive data as users move it through email, software-as-a-service applications and generative-AI tools. These are adjacent control layers, not one homogeneous market. Email security analyzes messages and communication behavior, while web security inspects internet traffic and application use. Browser security pushes some of that enforcement into the browser itself.

The architectural direction is clear. Standalone appliances are giving way to cloud-delivered controls that combine pre-delivery prevention with post-delivery detection, identity context and automated remediation. Secure web gateways are becoming components of broader Security Service Edge platforms, while the browser is emerging as a policy point for unmanaged devices, SaaS and AI. The durable demand is attractive; the harder investment question is who captures it—specialists with superior detection and workflow data, or large platforms with distribution, bundled pricing and control of the surrounding stack.

1. Two attack surfaces, several distinct markets

Email security protects inbound, outbound and internal messages. A Secure Email Gateway (SEG) sits in the mail-delivery path, typically by changing the domain’s mail-exchange records, and accepts or rejects a message before it reaches the mailbox. API-based email security connects directly to Microsoft 365 or Google Workspace and analyzes messages and mailbox activity without becoming the mail server. industry research uses Integrated Cloud Email Security (ICES) to describe cloud-native protection integrated through APIs; in practice, the market increasingly combines API and gateway controls rather than treating them as mutually exclusive.

Web security governs traffic between a user and the public internet. Its traditional core is the Secure Web Gateway (SWG), a proxy that applies URL, malware, application and data policies. Domain Name System (DNS) security blocks resolution of malicious domains earlier and cheaply, but cannot inspect page content. Remote Browser Isolation (RBI) executes risky web content away from the endpoint and streams a safe representation to the user. An enterprise browser, or a managed security layer embedded in a mainstream browser, can directly control copy, paste, uploads, downloads, screenshots, extensions and access from unmanaged devices.

These products overlap with, but do not replace, adjacent controls. Data Loss Prevention (DLP) discovers and controls sensitive information across email, endpoints, SaaS and web traffic. A Cloud Access Security Broker (CASB) governs sanctioned and unsanctioned cloud applications. Zero Trust Network Access (ZTNA) grants identity- and context-aware access to private applications instead of broad network access. industry research defines Security Service Edge (SSE) as the cloud-delivered convergence of SWG, CASB and ZTNA with related security functions. Secure Access Service Edge (SASE) adds wide-area networking, usually software-defined WAN, to SSE. Identity security decides who should have access; endpoint security protects the device; email, web and browser controls inspect the interaction. Effective architectures share telemetry across all of them.

2. Why the market remains structurally important

The problem has shifted from crude malware delivery to manipulation of trusted people and services. Phishing persuades a user to reveal credentials, authorize a transaction or open malicious content. Business Email Compromise (BEC) impersonates a colleague, executive or supplier to redirect money or information, often without malware. In its 2025 Internet Crime Report, the FBI recorded 191,561 phishing/spoofing complaints and 24,768 BEC complaints; reported BEC losses were approximately $3bn. Verizon’s 2026 Data Breach Investigations Report likewise keeps social engineering, stolen credentials and human action central to the breach story.

The attack surface is broadening. Microsoft reported that QR-code phishing detected in its telemetry rose from 7.6m messages in January 2026 to 18.7m in March, with PDFs carrying most QR payloads. Generative AI reduces the cost of producing polished, localized and personalized lures; voice cloning and synthetic video make out-of-band verification less reliable. Attackers also hide behind legitimate file-sharing, cloud and collaboration services, weakening simple reputation-based defenses.

At the same time, Microsoft 365, Google Workspace, SaaS and hybrid work have dissolved the old perimeter. Most browser sessions are encrypted, users work from multiple networks and devices, and sensitive information can leave through webmail, personal cloud storage or a prompt sent to a generative-AI service. This keeps inspection, DLP and identity-aware access relevant even as malware filters improve. CISA’s 2025 phishing guidance recommends layered controls including DMARC enforcement, URL and attachment scanning, internal-message monitoring and phishing-resistant multifactor authentication. The market exists because no single layer is reliable enough on its own.

3. Market size: attractive growth, untidy definitions

There is no defensible single figure for “email and web security.” Research firms draw boundaries differently, and SSE revenue already includes SWG, CASB and ZTNA. Enterprise-browser revenue can also overlap with SSE or endpoint subscriptions. The most useful view is therefore by segment, with the definitions left visible.

Market segmentWhat it includesLatest credible estimateExpected growthSource and date
Email / messaging securityGateways and cloud services protecting business messaging; narrower than all email-related securityApproximately $3bn in 2023Approximately 5.6% CAGR to about $3.5bn in 2027industry research Universe: Email Security, 2024
Secure Web GatewayProxy, URL filtering, malware inspection and web DLPNo sufficiently transparent current standalone estimateIncreasingly reported inside SSE rather than as a clean standalone categoryindustry research SSE definition, 29 July 2026
Security Service EdgeSWG, CASB, ZTNA and related cloud-delivered controlsMore than $13bn forecast for 2030Part of the broader SASE market growing at a mid-teens rateindustry research, 11 August 2026
Secure Access Service EdgeSSE plus software-defined wide-area networking$24bn forecast for 2030, more than twice 2025 revenue15% CAGR through 2030industry research, 11 August 2026
Enterprise browser securitySecure browsers and browser-native enterprise controlsNo reliable public revenue figureAdoption expected to rise from less than 10% of organizations in 2025 to 25% by 2028industry research, 29 April 2025
3. Market size: attractive growth, untidy definitions

The numbers should not be added together. The industry research estimate uses a relatively narrow messaging-security definition, while industry research SSE forecast includes the modern successor to much standalone web-security spending. Browser controls may be sold separately, included in a broader platform or used to reduce the traffic that needs a traditional proxy. Directionally, email is a mature but durable market; SSE is the larger consolidation vehicle; and browser security is an earlier-stage architecture shift whose revenue boundary is still forming.

4. From gateways to continuous, cloud-delivered enforcement

The first generation used on-premises appliances. Email gateways filtered spam, known malware and disallowed attachments before passing mail to an internal server. Web proxies categorized sites and inspected employee traffic exiting a corporate network. This architecture matched an era of offices, managed devices and private data centers.

Cloud email and SaaS broke that model’s boundaries. Gateways moved into vendor clouds, while API-based products gained access to Microsoft 365 and Google Workspace mailboxes, identity events and post-delivery remediation. Their advantage was deployment speed and visibility inside the cloud service; their limitation was that a harmful message might already have arrived before an API scan acted. The market is now converging on coexistence: inline controls for deterministic pre-delivery enforcement, APIs for internal mail, behavior and retroactive removal. Proofpoint’s 2026 unification of gateway and API delivery is a useful marker of that direction.

Web security followed a parallel path from branch appliances to globally distributed cloud proxies. SWG, CASB and ZTNA then converged into SSE, allowing one policy engine to follow users beyond the office. RBI added a containment option for unknown or high-risk sites. The latest step is browser-native enforcement: rather than infer every user action from network traffic, the browser can see the application, identity and precise action directly. industry research March 2026 recommendation that organizations adopt SSE to replace standalone SWG, CASB and ZTNA products captures the consolidation trend, but replacement is rarely instantaneous; large enterprises commonly operate mixed architectures during multi-year migrations.

5. How the technology works

For an inbound email, the sending server first connects to the recipient’s gateway or cloud mail service. The control verifies sender authentication through SPF, DKIM and DMARC; checks domain, IP and URL reputation; analyzes headers, language and communication patterns; detonates suspicious attachments in a sandbox; and may rewrite links for inspection when clicked. Semantic and behavioral models look for intent—an unusual payment request, a new supplier bank account or a sender-user relationship that does not fit normal behavior. Clean mail is delivered. API-connected systems continue to scan the mailbox, correlate identity signals and remove newly identified threats from every recipient. Outbound controls apply DLP, encryption and policy; internal-mail inspection helps find compromised accounts that never cross an external gateway.

For a web session, an endpoint agent, browser setting, network tunnel or DNS policy steers the request to a cloud enforcement point. Identity and device posture determine the applicable policy. DNS filtering can stop a known malicious domain before connection; the SWG categorizes the destination, may decrypt Transport Layer Security traffic, scans content, applies application controls and DLP, then permits, blocks or isolates the session. CASB functions distinguish sanctioned from unsanctioned SaaS and control actions inside applications. ZTNA handles private applications. RBI keeps active code off the endpoint, while an enterprise browser can prevent a user from pasting source code into an AI service, uploading a customer list to personal storage or downloading corporate data onto an unmanaged device.

TechnologyDeployment pointPrimary functionStrengthPrincipal limitation
SEGInline in the mail flowPre-delivery email inspection and policyBlocks threats before the inbox; strong routing and outbound controlLess native visibility into internal mail and mailbox behavior
API / ICESInside Microsoft 365 or Google Workspace via APIsCloud-mail analysis and remediationFast deployment, behavioral context and post-delivery removalAPI latency and platform permissions; some actions occur after delivery
SWGCloud or appliance proxyWeb filtering, threat prevention and DLPDeep, consistent inspection across browsers and applicationsTraffic steering, TLS inspection complexity and cloud compute cost
DNS securityDNS resolution layerBlock risky domainsSimple, fast and inexpensive coverageCannot inspect page content or granular in-app actions
RBIRemote execution environmentContain active web contentReduces exposure to unknown browser exploits and downloadsCost, latency and user-experience trade-offs
Enterprise browserBrowser or browser extensionControl application access and user actionsFine-grained visibility over copy, paste, upload and downloadAdoption, browser standardization and overlap with SSE/endpoint tools
SSECloud security edgeConverge SWG, CASB, ZTNA and data controlsCommon policy and telemetry across users and applicationsMigration risk, platform lock-in and uneven depth across modules
5. How the technology works

6. Competitive landscape

Email and web security have different competitive centers. Proofpoint and Mimecast built specialist email franchises; Microsoft and Google control the collaboration suites and can bundle native protection; Check Point, Cisco and Fortinet span email and broader security portfolios. In web security, Zscaler, Netskope and Palo Alto Networks are central SSE competitors, with Cloudflare, Cisco, Fortinet, Broadcom, Forcepoint and others competing from network, firewall, data-security or installed-base positions. industry research July 2026 SSE assessment included Broadcom, Cisco, Cloudflare, iboss, Netskope, Palo Alto Networks, Skyhigh Security and Zscaler. industry research Q2 2025 email-security evaluation covered a different set, illustrating why the markets should not be collapsed.

VendorPrincipal positionRelevant productsStrategic strengthMain competitive consideration
ProofpointEmail and human-centric security specialistCore Email Protection, Targeted Attack Protection, Threat Response, DLPDeep email telemetry, threat research and people-centric workflows; gateway and API optionsMust defend premium pricing against suites and extend beyond email coherently
MicrosoftCollaboration-suite incumbent and security platformDefender for Office 365, Exchange Online Protection, Entra, Purview, Edge for BusinessDistribution, identity and productivity context, and attractive bundle economicsCustomers may retain specialists for detection depth, independence and operational separation
MimecastEmail-security and resilience specialistAdvanced Email Security, Cloud Integrated, continuity and archivingEstablished installed base, flexible gateway/API deployment and email continuitySimilar suite-versus-specialist pressure; portfolio breadth is narrower than hyperscalers
GoogleNative cloud email and browser platformGmail security, Workspace DLP, Chrome Enterprise PremiumControl of Gmail and Chrome, cloud-scale telemetry and browser-native enforcementStrongest fit is the Google ecosystem; heterogeneous estates create openings for independents
CiscoBroad security and networking platformSecure Email Threat Defense, Secure AccessChannel, network reach and gateway/API choiceNeeds consistent integration and execution across a broad portfolio
Check PointEmail/collaboration specialist capability inside a broad platformHarmony Email & Collaboration, Harmony Browse, InfinityAPI-led cloud application coverage and broad threat-prevention portfolioCompetes against both email specialists and larger platform bundles
ZscalerCloud-native SSE specialistZscaler Internet Access, Private Access, Data Protection, Zero Trust BrowserLarge cloud inspection platform and zero-trust architectureMust sustain differentiation as firewall and network vendors improve cloud-delivered offers
NetskopeSSE and data-centric cloud-security specialistNetskope One, Next Gen SWG, CASB, ZTNA, RBIGranular SaaS understanding and integrated data controlsInfrastructure scale, go-to-market reach and platform competition remain central
Palo Alto NetworksBroad cybersecurity platform with SASEPrisma Access, Prisma Browser, Enterprise DLPCross-sell from firewall, endpoint and cloud security plus integrated operationsCustomers must judge module depth and economics against specialists
CloudflareGlobal network platform expanding into SSECloudflare One, Gateway, Access, Browser IsolationNetwork footprint, simple architecture and convergence of connectivity with securityEnterprise security installed base and feature maturity versus long-established vendors
FortinetNetwork-security platform spanning email and SASEFortiMail, FortiProxy, FortiSASE, FortiMail Workspace SecurityChannel scale, appliance economics and Security Fabric integrationCloud-delivered consistency versus cloud-native specialists
Broadcom / SymantecLarge-enterprise web and data-security incumbentSymantec Web Protection, Cloud SWG, DLPInstalled base and mature enterprise policy/data controlsPortfolio ownership changes and customer appetite for newer cloud-native platforms
ForcepointData-centric web and SSE vendorForcepoint ONE, Secure Web Gateway, Enterprise DLPLongstanding DLP expertise and policy depthCompetitive visibility and platform momentum versus larger SSE vendors
6. Competitive landscape

The fault line is not simply feature count. Specialists argue that better language models, relationship graphs, threat intelligence and response workflows produce higher efficacy. Platforms counter with one agent, one policy layer, integrated telemetry and lower marginal cost. Buyers increasingly want both: consolidated operations without accepting a weak control at a high-risk entry point. This supports layered deployments in large enterprises even as smaller organizations favor suites and managed services.

7. AI expands both the attack surface and the control surface

For attackers, generative AI improves language, localization and personalization while automating reconnaissance across public profiles and compromised mailboxes. It lowers the cost of testing many plausible variants and strengthens impersonation through synthetic voice, images and video. It does not make every campaign sophisticated, but it removes many of the spelling and context errors that once helped users recognize fraud. Legitimate cloud services and collaboration channels further blur the distinction between trusted infrastructure and trusted content.

For defenders, the important change is analytical rather than cosmetic. Natural-language models classify intent and detect anomalous requests even when a message contains no malicious payload. Behavioral models compare sender, recipient, device and communication history. Automation can cluster campaigns, search every mailbox, remove matching messages and prioritize the users most exposed. On the web, models accelerate classification of new sites and content, while DLP identifies source code, personal information or intellectual property moving into AI services. Browser controls can allow an AI application but block sensitive prompts, uploads, downloads or copy-and-paste actions—more precise than simply blocking the domain.

AI is not a free efficacy layer. Models create false positives, can be evaded, require explainability for security teams, and add inference and cloud-inspection cost. Processing message content, prompts and files also raises privacy and residency questions. The strongest products will combine models with deterministic controls, identity and relationship graphs, sandboxing, reputation, human feedback and auditable response—not market a generic “AI-powered” label.

8. Industry economics and market dynamics

Most products are recurring subscriptions priced per user, sometimes with separate modules for advanced threat protection, DLP, archiving, browser isolation or managed response. The model produces predictable revenue, but gross margins depend on architecture: scanning attachments, decrypting traffic, running sandboxes and rendering isolated browser sessions consume real compute and network capacity. Scale matters because it spreads infrastructure and research costs and improves telemetry, but raw volume is not automatically a moat; vendors must turn observations into faster, more accurate decisions.

Distribution is equally important. Microsoft can attach protection to an existing productivity and identity relationship. Google has the same structural advantage in Workspace and Chrome. Firewall and networking vendors cross-sell into installed bases, while specialists rely more heavily on efficacy, channel partners and managed security service providers. Switching costs are moderate in a simple API deployment but higher where customers have tuned routing, DLP dictionaries, encryption, incident workflows and regulatory archives. SSE migrations are heavier still because they change traffic paths and private-application access.

Consolidation therefore has limits. A platform can reduce agents, consoles and procurement friction, but a successful attack can cost far more than a specialist license. Large regulated enterprises often pay for defense in depth; smaller customers are more likely to accept bundled “good enough” protection or buy through a managed provider. Enterprise browsers could shift value away from parts of the network stack by enforcing policy at the user interface, but they are more likely to complement SSE in the medium term: non-browser traffic, unmanaged applications and broad network controls still require other enforcement points.

9. Outlook and the five debates that matter

1. Can Microsoft keep taking share from specialists?

Its distribution, identity context and bundle economics are formidable. Specialists remain defensible where independent telemetry, detection quality, mail continuity, complex policy or incident workflow matters enough to justify a second vendor. The contest will be decided by measurable efficacy and operating cost, not feature checklists.

2. Does email security remain a distinct market?

Email will increasingly share data and response with identity, collaboration, DLP and security operations. Yet its protocol position, communication graph, continuity requirements and concentration of fraud keep it technically distinct. The category is more likely to become a specialized control inside broader platforms than disappear.

3. Does SSE absorb standalone web security?

Yes, for most new enterprise buying. SWG is becoming a capability within an SSE decision because users also need SaaS governance, private-application access and common data policy. Standalone products will persist in installed bases and narrower use cases, but the strategic budget is moving upward to the platform.

4. Does the enterprise browser become a new control point?

Probably, although the winning form is unsettled. A dedicated enterprise browser offers deep control; an extension or managed mainstream browser reduces user friction; an SSE vendor can combine browser context with network enforcement. The browser’s importance rises with contractors, unmanaged devices, SaaS and generative AI, but forcing a new browser standard across an enterprise remains a material deployment hurdle.

5. Does generative AI expand the market faster than bundling compresses it?

AI increases attack volume, impersonation quality and data-governance requirements, supporting demand. Bundling compresses the price of baseline controls. The likely outcome is polarization: basic protection becomes cheaper and more integrated, while differentiated spending concentrates on high-efficacy detection, data security, browser control and automated response.

Bottom line

Email and web security are converging operationally but not becoming the same product. Email is moving toward hybrid gateway-plus-API protection tied to identity and behavior; web security is being absorbed into SSE; and the browser is becoming a fine-grained enforcement surface for SaaS, unmanaged devices and AI. Likely winners will control valuable telemetry, deliver demonstrably better detection or data policy, and integrate without adding operational drag. The central uncertainty is economic: whether customers continue paying specialists for superior protection at critical attack surfaces, or allow suite vendors to turn more of that protection into a bundled feature.