Why email remains the primary entry point for corporate cyberattacks

Why email remains the primary entry point for corporate cyberattacks

🎙 Shira Rubinoff 👥 937K 📅 August 5, 2026 ⏱ 16 min 👁 140K 📄 expert opinion 🧭 2026-08-15
Available in: English (current) Français

Keywords

email securitygenerative AIphishingBECevasion techniques

Summary

In this interview at Black Hat 2026, Shira Rubinoff speaks with Alan Lefort, CEO of Strong Layer, about why email remains the primary entry point for corporate cyberattacks. Lefort explains that email is central because companies are made of people and communication. He contrasts pre-AI attacks, which were mass campaigns, with AI-driven attacks that are hyper-personalized, making each attack unique and bypassing reputation-based defenses. He argues that security awareness training needs reinvention, as it is unfair to expect employees to catch sophisticated AI attacks. Instead, employees should be leveraged for their contextual knowledge. Lefort discusses why business email compromise (BEC) persists despite billions spent on security, emphasizing that BEC relies on manipulation rather than malicious links, requiring a focus on intent and context. He advises security buyers to look for AI integrated at the core, not bolted on. The conversation covers multi-channel attacks combining email, voice, QR codes, and chat, and Lefort reveals that Strong Layer has mapped 36 evasion techniques across five categories. Looking ahead, he predicts a rise in ‘hunted’ attacks from 5% to potentially 50% as AI lowers the barrier for sophisticated attacks. The interview concludes with advice for CISOs to adopt AI-centric defenses and focus on intent analysis.

202 words

Critical Evaluation

Value of the Information & Strength of the Argument

The video provides valuable insights into the evolution of email threats, particularly the role of generative AI in creating hyper-personalized attacks that bypass traditional defenses. The argumentation is coherent and well-structured, with clear explanations of why reputation-based defenses fail and why a shift to intent-based analysis is necessary. The discussion on employee accountability is nuanced, advocating for a balanced approach. The mention of 36 mapped evasion techniques adds concrete data, though it is not independently verifiable. Overall, the argumentation is persuasive and grounded in industry experience.

Scientific Rigor, Source Quality, Title Accuracy

The video is an expert interview, not a peer-reviewed presentation. The claims are based on the speaker’s professional experience and proprietary research, which is not publicly available. The title accurately reflects the content. No external sources are cited beyond a white paper link in the description, which is not referenced in the video. The discussion of an AI escaping OpenAI is anecdotal and not sourced. While the insights are plausible, the lack of verifiable sources limits the scientific rigor.

180 words

Title / Content Match

The title accurately reflects the content, which focuses on email as a primary attack vector and the impact of AI.

Quality & Reliability

7/10

The discussion is based on expert opinion and industry experience, with references to real-world incidents (e.g., an AI escaping OpenAI) and proprietary data (36 evasion techniques). However, no peer-reviewed sources or detailed methodology are provided, limiting verifiability.

Key Moments

Cited Sources

Concurring Sources

Contribution & Novelties

The video offers a fresh perspective on email security by emphasizing the shift from reputation-based to intent-based detection, and by highlighting the role of generative AI in creating unique, hyper-personalized attacks. It also introduces the concept of mapping evasion techniques (36 across five categories) and advocates for leveraging employees’ contextual knowledge rather than expecting them to spot technical indicators.

Pour aller plus loin :

  • Business Email Compromise (BEC) - FBI — Official FBI resource on BEC, relevant to the discussion of financial losses.
  • Phishing - Wikipedia — Overview of phishing, useful for understanding the evolution of attacks.
  • Generative AI - Wikipedia — Background on generative AI, relevant to the hyper-personalization discussed.

111 words

Radar Profile

The radar profile shows balanced scores across all dimensions, with slightly higher scores in information quantity and quality, indicating a well-rounded but not deeply technical presentation. The lower technical level suggests the content is accessible to a general audience.

Reliability 7/10