News

Ben Avner
|
|
Reading Time:
5
min

Why Investigation, Not Classification, Is the Future of Email Security
A recent independent research report from Software Analyst Cyber Research (SACR) introduces a new way to think about email security and recognizes Ocean as the pioneer of a new architectural category.
For nearly two decades, the email security market has evolved by improving one fundamental capability: classification.
Secure Email Gateways (SEGs) compare emails against known signatures. Cloud email security platforms use behavioral analytics and machine learning to assign risk scores. More recently, AI has been added to improve detection rates and reduce false positives.
While these approaches have become more sophisticated, they all share the same underlying assumption:
An email should be classified as malicious or benign based on measurable signals.
The latest research from Software Analyst Cyber Research argues that this model has reached its limits.
Instead, the report introduces a new architectural category, Investigation-Centric Email Security, and positions Ocean as the company pioneering this approach.
Why Classification-Based Email Security Falls Short
Modern phishing attacks have changed dramatically.
Attackers now use generative AI to create convincing emails at scale, compromise legitimate business accounts, impersonate trusted partners, and adapt campaigns in real time.
These attacks often do not exhibit the traditional indicators that legacy security products were built to detect.
A business email compromise (BEC) or vendor email compromise (VEC) attack may carry no malicious attachment, no suspicious link, and no obviously malicious domain. The signal lies in the context: the relationship between the parties, the timing, and whether the request makes sense for the business - all of which are elements a classification engine cannot reliably evaluate.
Yet security vendors continue adding more signals, including:
Reputation scores
Behavioral anomalies
Sender history
NLP models
URL reputation
Attachment analysis
Each improves detection incrementally, but they all remain classification engines, because they ultimately answer only one question:
Does this email look malicious?
The challenge is that sophisticated attacks increasingly resemble legitimate business communication.
What Is Investigation-Centric Email Security?
Investigation-centric email security is an architecture that asks what an email is trying to accomplish, not just how malicious it looks. Instead of scoring a message, it investigates sender intent, identity, business context, among other relevant factors, to reach an evidence-based verdict.
Instead of focusing on signal-based prediction, Ocean was built around a different question:
What is the sender's intent, and what are they trying to accomplish?
Rather than assigning a probability score, Ocean investigates every inbound email in real time using more than a dozen specialized AI agents.
These agents work together to:
Understand the sender's intent
Verify sender identity
Inspect links and attachments
Validate business relationships
Analyze organizational context
Correlate evidence across multiple sources
Instead of producing a risk score, Ocean delivers an evidence-based conclusion that explains why an email is safe or malicious.
This shifts email security from statistical prediction to autonomous investigation.
Every Verdict Includes Evidence
One of the central ideas highlighted in the SACR report is that modern AI makes investigation practical at machine speed.
Rather than relying on a single model or threshold, Ocean orchestrates multiple specialized AI agents that independently analyze different aspects of an email before producing a final verdict.
Ocean’s investigation engine, Ray, runs a swarm of purpose-built sub-agents across areas such as invoice analysis, infrastructure assessment, sandboxing, and content review, compressing investigations that could take analysts hours into under 40 seconds.
Every decision is supported by evidence that security teams can review.
That means analysts are not simply asked to trust a score. They can understand exactly how the system reached its conclusion.
This improves confidence while reducing the time spent investigating suspicious emails.
A New Architectural Category
The report introduces Investigation-Centric Email Security as a distinct architecture within the broader email security market.
Instead of focusing primarily on detection models, this architecture emphasizes autonomous investigation, evidence generation, and contextual reasoning.
The distinction matters because architectural choices determine how security products adapt to change.
Classification systems improve by adding more signals.
Investigation systems improve by reasoning over more evidence.
As AI-powered attacks continue to evolve, the ability to understand context, not simply recognize patterns, becomes increasingly important.
Built for the AI Era
Generative AI has fundamentally changed the economics of phishing.
Attackers can now generate personalized, highly convincing campaigns in minutes, making it increasingly difficult for static rules, reputation systems, and traditional machine learning models to keep pace.
Meeting this challenge requires more than another detection model.
It requires systems capable of reasoning through ambiguity, validating business context, and autonomously investigating every email before making a decision.
That is the foundation Ocean was built on from day one.
Recognition from Independent Research
We are grateful to Software Analyst Cyber Research for its thoughtful analysis of where the email security market is heading and for recognizing Ocean's approach as a new architectural category.
As organizations rethink how to defend against AI-powered threats, we believe the future belongs to platforms that do not simply classify emails. They understand them.
Every other architecture is ultimately limited by the signals it can measure. Ocean is built to understand intent, evaluate context, and generate evidence, making it well prepared for a world where AI is changing both how attacks are created and how defenders respond.
If you are evaluating where email security is headed, we encourage you to read the full Software Analyst Cyber Research report, From Perimeter to Proof: The New Architecture of Email Security.
See Ocean in Action. Book a Demo.
Frequently Asked Questions
What is investigation-centric email security?
Investigation-centric email security is an architecture that determines what an email is trying to accomplish rather than assigning it a risk score. It uses AI agents to investigate sender identity, links, attachments, business relationships, organizational context, and other contextual signals, then delivers an evidence-based verdict explaining why an email is legitimate or malicious.
How is investigation-centric email security different from a secure email gateway or ICES platform?
Secure email gateways (SEGs) and integrated cloud email security (ICES) platforms primarily classify emails by analyzing signals that indicate whether an email is malicious. Investigation-centric platforms instead determine what an email is actually to accomplish. That distinction becomes increasingly important as novel attacks closely resemble legitimate business communication.
Why does explainability matter in email security?
Boards, auditors, regulators, and cyber insurers increasingly expect security teams to explain and defend their decisions. An evidence chain that shows why a verdict was reached enables analysts to act with confidence, satisfy audit requirements, and provide defensible documentation instead of relying on an opaque risk score.