Stopping Attacks Before They Reach the Inbox: Introducing the Proofpoint Agentic Collaboration Security System
At Protect 2026 in San Diego today, we introduced the Proofpoint Agentic Collaboration Security system. It is a single system that brings together intent-based detection, agentic investigation, and user risk agents to protect how people communicate and collaborate. They are three interlocking parts of one system: intent-based detection reasons over that context to determine what an interaction is actually trying to accomplish, and agents turn those decisions into investigation, response and user risk management that has always required an analyst's hands-on time.
Why now
The hardest attacks to detect today do not look unusual at all. A supplier's mailbox is compromised on their end, and the attacker reads months of real correspondence before replying inside a live thread, quoting an actual purchase order, from a genuine account. There is no malware, no link and no lookalike domain, so there is nothing a rule was ever written to catch. An attack aimed at one executive may never repeat, so it never forms a pattern. A request that falls outside someone's normal access still arrives from a person who is allowed to send it.
Behavioral analysis is built to catch deviation from a baseline. That design fails once the account, the conversation and the request all look the way they are supposed to. Catching these attacks means reasoning about what a message is actually trying to accomplish, not only whether it looks different from what came before across email, collaboration tools and the browser.
At the same time, the work of responding to what does get caught has outgrown what most security teams can do by hand. A single investigation can mean pulling evidence out of email, identity, endpoint, browser and half a dozen other tools before anyone can say what happened or how far it spread. A security awareness program built around static training modules cannot keep pace with a threat landscape that changes every week, and a VIP list maintained by hand is out of date the moment someone new becomes a target. Closing that gap takes more than better detection. It takes agents that can take on investigation, response and risk management work that has always required a person to do it manually.
Solving this takes a system where context, reasoning and action are connected end to end. What follows is that system, piece by piece: the graph that supplies context, the model that reasons over it, and the agents that act on what it finds.
Signals Only Matter if They Connect: The Proofpoint Knowledge Graph
Vendors increasingly describe their detection in terms of how many signals they ingest. A signal is only useful if it connects to something the system already knows. A model that stops at the domain level cannot tell you whether the person being emailed today is someone your organization already flagged as high risk, or what data that person can reach. Most vendors have no way to look past collaboration data into the rest of a customer's security stack, so their picture of any one user stays thin.
We’re expanding our Behavior Graph into the Proofpoint Knowledge Graph, extending profiling from the domain level down to groups and individual users, and adding topic and tone modeling through a topic foundry that feeds new understanding directly to the gateway. The graph also reaches beyond collaboration security into the rest of the platform, drawing in signals from data security and AI security. That lets detection ask a different question than whether a message looks right: whether the person receiving it is someone already known to be at risk, and what they could actually expose if they were compromised.
Detection That Does Not Choose Between Speed and Scrutiny: Nexus Intent-Based Detection
A single detection model has to pick between speed and rigor and apply that choice to every message it sees. Vendors that choose speed accept shallow analysis. Vendors that choose rigor accept delay, usually by holding a message for review after it has already reached the inbox. Neither approach can tell the difference between a message that looks unusual and one that is simply asking for something that does not hold up.
The Nexus Intent-Based Detection Model, running on the Knowledge Graph described above, evaluates a message's objective, whether that objective is plausible given the relationship, and the technique being used to pursue it. It resolves most decisions in under half a second using flash models, checking business context, known attacker infrastructure and the sender's risk profile, making it the only secure email gateway to deliver intent-based detection before a message reaches the user.
At the conference, we announced the general availability of two new intent based flash models that protect organizations against threats, and business disruption:
- Advanced Campaign Completion: Connects seemingly unrelated email threats into a single campaign—even when subject lines, message content, or other attributes differ. By matching attacker intent instead of exact content, it uncovers sophisticated campaigns designed to evade detection.
- Activist Bombing Protection: Detects coordinated activist email campaigns targeting organizations, even when messages come from multiple senders. By matching shared intent across emails, it identifies activist bombing campaigns that traditional threat detection can miss.
The next set of messages that are genuinely ambiguous move into extended thinking, away from the inbox, where the model weighs relationship history, campaign correlation and behavioral context before deciding. The hardest cases get a full reconstruction during investigation. Because Proofpoint operates its own gateway, this reasoning runs before delivery, in the inbox and during investigation, and what the model learns downstream feeds back into what it catches before delivery.
Every detection is also enriched across three apertures: individual, organization and vertical, so a technique caught once is tested against everyone it plausibly threatens. A technique that looks isolated at the individual level can be unmistakable once it is compared against the rest of the organization, and a campaign that is invisible inside one company can be unmistakable once it is compared only against peer institutions in the same industry. Detections benefit from the single largest community in the world for email security. Proofpoint analyzes 2.37 trillion emails, 19.5 trillion URLs and 1.27 trillion attachments a year across more than 3.4 million customers, which means we often see a compromise inside a supplier or partner who is not even a Proofpoint customer before it reaches you.
Intent-Based Protection Built For Critical Users: Privileged User Protection
An attack built for a single executive does not repeat, so it never forms a pattern that a population level model can learn from. A hostile message or a sustained personal campaign aimed at one person is not malware and is not spam, so it passes through conventional filters without tripping anything. Existing VIP protections apply a tighter policy to a list someone maintains by hand, which is not the same as understanding what is normal for that person.
Privileged User Protection builds and maintains a dedicated detection model for each protected individual, trained on their specific relationships, communication patterns and workflows, so an attack engineered for one person can be caught the first time it is attempted rather than after a pattern shows up across other victims. It also covers unwanted communications aimed at that person specifically, and it automatically lowers the threshold for deeper analysis on anything addressed only to them.
Automating Investigations That Used to Take Days: Autonomous Threat Investigation
When an alert fires, someone still has to determine what actually happened. That means pulling evidence out of email, identity, endpoint, browser and SIEM tools one at a time and piecing together a timeline by hand. Most security teams do not have the analyst hours to do that thoroughly for every alert, so investigation either does not happen or happens too slowly to matter.
Autonomous threat investigation automates that work. It can be invoked manually or triggered automatically when something warrants a closer look, and it reasons across Proofpoint telemetry and third party data, including identity, endpoint, browser, SIEM, web proxy and other MCP connected tools, to reconstruct the attack, establish timeline and blast radius, and recommend or execute a response. Analysts receive a finished investigation instead of a set of alerts to correlate themselves. Every investigation also feeds a closed loop process: what is learned from false positives, false negatives or a customer's own submission becomes updated detection logic, so the same miss is less likely to happen again.
A New Proactive Approach to Reducing Growing User Risk: Proofpoint User Risk Agents
A small number of users account for a disproportionate share of an organization’s risk, yet many security teams struggle to identify who those users are and understand why they are at risk. Without that context, teams are left guessing where to focus, which users need additional attention, and how to reduce risk effectively.
At the same time, attackers are evolving quickly. They are using AI to research targets, identify vulnerable users, and probe for weak spots. The gap is widening between machine-speed attacks using highly personalized lures and defenses that still treat user risk as a security awareness problem or rely on siloed tools.
Proofpoint User Risk Agents close this gap by bringing together two coordinated agents, the Red Team Agent and the Blue Team Agent, in a continuous loop to strengthen protection and reduce user risk. The Red Team Agent continuously researches, synthesizes, and orchestrates user-risk discovery by building context from public employee, business, and partner signals. It then uses that context to create personalized lures and orchestrate chained events, including simulated real-world attacks.
The Blue Team Agent builds dynamic high-risk user profiles, recommends and applies adaptive controls and protections, and delivers targeted, threat-informed coaching in the moment. Together, the agents create a continuously improving system, with each agent operating independently, that helps organizations proactively reduce user risk with minimal administrative effort.
Extending Protection Past the Point of Delivery: Proofpoint Advanced Browser Protection
Attacks follow the work. Roughly eighty-five percent of the workday now happens in the browser and cloud apps, and attackers have moved with it1. Phishing and account takeover finish in the browser, where credentials get typed, session tokens handed over, and consent granted. Increasingly they start there too, with no email involved at all. Ninety-five percent of in-browser attacks observed in 2025 used some form of bot protection to evade sandbox analysis2 e.g., a sandbox loading that page from our infrastructure gets shown a clean one or URLs that sit behind end-user authentication walls. And roughly one third of the payloads intercepted last year never came through email at all. They arrived through search results, malvertising etc2.
Email security has no visibility into what happens after the click. A browser tool disconnected from email threat intelligence is working from a much smaller picture. Proofpoint Advanced Browser Protection, delivered in partnership with Push Security, closes that gap. It extends the same threat intelligence that protects inbound email into the browser, validating clicked URLs in real time and defending against browser-native techniques: adversary-in-the-middle attacks, session token theft, OAuth abuse, malicious extensions.
Proofpoint is the only vendor with shared email and browser threat intelligence. Core Email Protection sees the lure, the sender, the campaign, every targeted recipient. Advanced Browser Protection sees what the user actually does in the browser. Each half makes the other better: email context tells the browser what to be suspicious of, and browser verdicts close the delivery blind spot. Through the partnership with Push Security combined with Proofpoint’s native detection and email and identity intelligence, we are able to provide a unique detection and response capabilities for Browser based attacks. Also, a technique spotted in the browser sharpens what gets caught before delivery, and a technique caught in email sharpens what the browser watches for. Detections surface in the same Threat Protection Workbench, so email and browser investigations share context instead of running as separate tools.
Looking ahead
The supplier compromise described at the start of this piece has no signature to match. No malware, no bad domain, no anomalous sender, nothing a rules engine was ever built to flag. That's the shift this system is built for: from catching behavioral anomalies to reasoning about intent, and from alerts that wait for a person to act on them to agents that investigate, respond and manage risk on their own. It's not a one-time fix. Attackers will keep finding techniques with nothing to fingerprint, keep operating past the point a message is delivered, and keep searching for whichever person is easiest to reach. Closing each of those gaps is why this system reasons before delivery, acts after an alert fires, and follows a user's risk as it changes, in the browser as much as the inbox.
What we control is how much of that work still requires a person's hands, and how precisely detection, agents and browser protection work as one system rather than three separate tools. We’re excited to release more of the new detection system and capabilities discussed in this blog in Q1 2027 as part of an update to Proofpoint's Agentic Collaboration Security system. Thank you to our customers and partners for the feedback that shaped this launch, and to everyone who joined us in San Diego this week.
Citations
- Omdia, The State of Workforce Security (2025), commissioned by Palo Alto Networks
- Push Security, Browser Attacks Report / Browser Attack Techniques (2026)