proofpoint-advisory-services-cybersecurity-consulting

Announcing the Next Evolution of Proofpoint Cyber Defense

Share with your network!

Announcing the Next Evolution of Proofpoint Cyber Defense

When the Account Is Real and the Behavior Is Normal, AI Must Detect Intent

The most dangerous attacks today don’t come from strangers. They come from real accounts, in familiar threads, asking for exactly the kind of thing those accounts normally ask for. A genuinely compromised account authenticates cleanly, sends from its usual infrastructure, and behaves exactly like it always has, because it is the same account. AI closes the rest of the gap, letting an attacker mimic a real person’s writing style and vendor relationships closely enough that even the content stops looking unusual. What’s left, the only thing not copied from history, is the objective behind the message.

Threat actors are now using AI to target, craft, and scale attacks in ways that break pattern-matching entirely. A single campaign might reach 50 victims with 50 different emails, each one worded differently, personalized to the recipient, adapted as the attacker interacts and builds trust. No two messages look alike. But the meaning underneath is identical: the same ask, the same intent, repeated 50 times in 50 different disguises.

This is why detection has to work on two levels at once. First, understanding the meaning of a message regardless of its wording, so that fifty differently-worded emails pursuing the same goal are recognized as the same threat. Second, understanding the context a message lands in, the relationships, history, and knowledge graph around sender and recipient, because the same request can be routine or malicious depending entirely on who's asking and why.

Behavioral security alone catches what looks different from a baseline. It can’t catch a chain where every step looks normal and only the underlying purpose is malicious. This new era demands discerning intent: not whether something is unusual, but what it’s trying to accomplish.

Today we’re announcing the next generation of Proofpoint Nexus, built to answer that question directly: the Nexus Intent-Based Detection Model and Privileged User Protection. The first extends intent-based reasoning to every message, at every control point. The second brings it to the individuals facing the most tailored attacks.

Introducing Nexus Intent-Based Protection

Nexus Intent-Based Protection goes beyond behavior and reasons about intent instead: the objective a message is driving toward, whether the context makes that objective plausible, and the technique being used to pursue it. That combination catches the fraudulent request that doesn’t fit the relationship, the attacker whose technique gives them away, and the insider whose access is valid but whose objective isn’t.

It runs inline, pre-delivery and post-delivery, at every control point. With it, Proofpoint becomes the first vendor to deliver intent and behavioral analysis together across both gateway and API, with a Gateway and API solution that share insights and adapt their detections in tandem, catching the kind of ordinary-looking message that would otherwise hide its real objective in plain sight.

Multi-tier intent analysis, built for the speed each decision demands

Behavioral models ask one question: is this different from normal? That fails against attacks that match a sender’s pattern exactly, and it creates false-positives on anything new that simply lacks a baseline. The Nexus  Adaptive AI Engine evaluates intent across three tiers of escalating depth, each designed to raise how much can be resolved autonomously, without waiting on a person:

  • Flash (under 500 milliseconds) runs a fast plausibility check on business context, matches against known attacker infrastructure and technique signatures, and checks the user’s risk profile. High-confidence cases resolve instantly, inline.
  • Extended Thinking (up to a few minutes, inside an isolation zone) picks up the roughly 1% of messages that can’t be reliably convicted in real time but are suspicious enough to warrant a deeper look away from the inbox. It pulls relationship and communication history to weigh business plausibility, correlates against broader threat intelligence for campaign patterns, and factors in behavioral context to judge insider risk that a fast pass can’t responsibly call.
  • Deep Thinking (triggered by reported or missed mail, post-delivery) reconstructs the full interaction, including communication history, blast radius, and related accounts, to determine definitively which intent was driving the message.

The tiers teach each other. Anything a deeper tier convicts gets checked against one question: could it have been caught earlier? If so, the faster tiers adjust accordingly. Running the Gateway and API together makes that learning bidirectional. The Gateway evaluates intent before delivery, while the API watches the inbox and east-west traffic for anything that got through and started moving laterally. What surfaces there resolves in investigation, then flows back to sharpen what runs pre-delivery, a loop no API-only or gateway-only vendor can close on its own.

Multi Level Aperture

When the intent models catch something, the finding doesn’t stop at that one message. It’s automatically enriched across five apertures to answer a question no single detection can: who else does this apply to?

  1. Individual. It’s tested against one person’s own relationships and history, the level of precision a highly targeted or personalized attack actually requires.
  2. Organization. It’s weighed against the patterns of the specific company involved: who talks to whom, and about what.
  3. Vertical. It’s compared against organizations in the same industry, where shared regulations, workflows, and vendors make some techniques far more recognizable within a peer group than they are globally. A campaign aimed at regional banks can look like nothing against world traffic and stand out sharply against other regional banks.

Other vendors may enrich against a global model. Without a multi-tenant community, they have no vertical, organization, group, or individual aperture to enrich against at all, and no way to give a high-risk user the personal-level protection their exposure calls for. 

A knowledge graph built on the widest breadth of signals in the industry

We are expanding  our behavior graph into the Proofpoint Knowledge Graph, extending profiling from the domain level down to groups and individual users, and adding topic and tone modeling that pushes new understanding directly to the gateway. It will reach beyond collaboration security into the wider platform, drawing in user risk, data security, and AI security signals, to answer questions no email security product can answer alone  : is this person actually an insider risk, and what data can they reach? A routine-looking message becomes a very different decision when the system knows the recipient is high-risk and sits next to the crown jewels, the exact users where a disproportionate share of real damage originates.

A community that sees threats first and stops them everywhere

We call this the Community Hyperloop: Proofpoint’s network spans 3.4 million customers, processing 2.37 trillion messages a year across more than 13,000 intrusion detection sensors in 105 countries. Because most of the world’s large enterprises send mail to our customers, we see compromise inside organizations that aren’t customers at all, including your suppliers. No competitor can replicate that vantage point. Every detection, investigation, and user report is evaluated for whether it protects everyone, and the answer reaches the entire network in minutes, not days, sharpening detection without any customer having to configure, tune, or maintain a thing.

The Nexus Adaptive AI Engine is included in Proofpoint customer’s existing email security entitlement. It begins rolling out in Q1 ‘27, with limited exceptions for customers with specific data residency requirements.

Introducing Privileged User Protection

High-value targets face a different kind of attack: personalized enough to evade detection, and built to never repeat, so there’s no pattern for a population-level model to learn from. An impersonation attempt aimed at one CFO doesn’t look like anything else in the world’s mail traffic. It only looks like something once you study that one relationship closely enough to know it doesn’t belong.

That’s what Privileged User Protection is built to do. Delivered as new capability, it builds an individual threat model for each high-risk user, based on their actual relationships, workflows, and communication patterns, rather than comparing them to a population. It catches personalized, multi-modal attacks that are invisible to traditional detection because they were built to be invisible to traditional detection, and it goes beyond email fraud to block unwanted communications aimed at specific individuals, analyzing text, voice, video, and image together.

Introducing the Threat Investigation Agent

The Satori Investigation Agent can be triggered automatically when something warrants a closer look, and it reasons across Proofpoint telemetry and third party data, including identity, endpoint, browser, SIEM, web proxy and other MCP connected tools, to reconstruct the attack, establish timeline and blast radius, and recommend or execute a response. Analysts receive a finished investigation instead of a set of alerts to correlate themselves. Every investigation also feeds a closed loop process: what is learned from false positives, false negatives or a customer's own submission becomes updated detection logic, so the same miss is less likely to happen again.

Satori acts as it investigates. Lower-risk containment, pulling phishing messages already sent from the compromised account, removing delivered messages still sitting in inboxes, deleting the attacker’s mailbox rule, and blocklisting the malicious URL, happens automatically. Higher-risk actions, resetting credentials and revoking sessions, adding the account to a watch list, assigning follow-up training, tightening outbound mail inspection, are queued for one-click approval, so a human stays in the loop on the decisions that call for judgment.

It’s the same intent-based reasoning running in reverse: instead of asking whether a message should be delivered, Satori asks what an attacker who got through actually did, and closes the loop back into the detection model that watches for the next one.

A Different Measure of Success

For years, detection has been graded on false positives and false negatives. That’s no longer the right yardstick for a system built to close the gap between what attackers can now do and what defenders can actually see. The measures that matter now are simpler to state: how much gets resolved autonomously, how fast a threat discovered anywhere becomes protection everywhere, how much of the real attack surface the system can see across email and browser alike, and whether the users who carry a disproportionate share of your risk are the ones getting a disproportionate share of the protection.

Behavioral detection and intent-based detection aren’t competing ideas, but only one of them scales to the attacks defining this moment. The account is real. The behavior is normal. The intent isn’t. That’s the one thing every version of these attacks has in common, whether it’s a fraudulent wire request in a familiar thread or a script quietly lifting credentials out of a browser session. Proofpoint is building AI that reads intent everywhere it matters: at the gateway, in the inbox, and now, for the people who need it most, at the individual level.

Want to see how much of this is already getting through your own defenses? Get a free Email Rapid Risk Assessment and find out what your current setup is missing.