Close Menu
geekfence.comgeekfence.com
    What's Hot

    From transparency to action: What the latest Microsoft email security benchmark reveals

    March 13, 2026

    Twenty years of Amazon S3 and building what’s next

    March 13, 2026

    Threat Protection Updates in Secure Firewall 10.0

    March 13, 2026
    Facebook X (Twitter) Instagram
    • About Us
    • Contact Us
    Facebook Instagram
    geekfence.comgeekfence.com
    • Home
    • UK Tech News
    • AI
    • Big Data
    • Cyber Security
      • Cloud Computing
      • iOS Development
    • IoT
    • Mobile
    • Software
      • Software Development
      • Software Engineering
    • Technology
      • Green Technology
      • Nanotechnology
    • Telecom
    geekfence.comgeekfence.com
    Home»Artificial Intelligence»From transparency to action: What the latest Microsoft email security benchmark reveals
    Artificial Intelligence

    From transparency to action: What the latest Microsoft email security benchmark reveals

    AdminBy AdminMarch 13, 2026No Comments5 Mins Read0 Views
    Facebook Twitter Pinterest LinkedIn Telegram Tumblr Email
    From transparency to action: What the latest Microsoft email security benchmark reveals
    Share
    Facebook Twitter LinkedIn Pinterest Email


    In our last benchmarking post, Clarity in complexity: New insights for transparent email security,1 we shared why transparency matters more than ever in email security and how clear, consistent benchmarking helps security teams cut through noise and make confident decisions.

    Today, we’re continuing that conversation. With the latest Microsoft benchmarking data, we’re sharing what real-world telemetry reveals about how effectively modern email threats are detected, mitigated, and stopped by Microsoft Defender, secure email gateway (SEG) providers, and integrated cloud email security (ICES) solutions.

    This is part of our ongoing commitment to openness: regularly publishing performance data so customers can see how protections perform at scale.

    What’s new in the latest benchmarking data

    The newest benchmarking results reflect updated telemetry across recent months and reinforce several consistent trends:

    • Microsoft Defender removes an average of 70.8% of malicious email post-delivery, helping reduce dwell time even when cyberthreats bypass initial filtering.
    • Layered protection matters. When Defender operates alongside ICES partners, organizations benefit from incremental detection gains across promotional, spam, and malicious messages.
    • Overlapping detections remain, meaning ICES solutions can flag the same messages and the incremental value-add can vary by scenario and email type.

    This kind of data-driven visibility is critical for security teams who want to understand not just whether cyberthreats are blocked, but how and where defenses are adding value across the email attack lifecycle.

    Benchmarking results for ICES vendors

    Microsoft’s quarterly analysis shows that layering ICES solutions with Microsoft Defender continue to provide a benefit in reducing marketing and bulk email, improving their filtering by an average of 13.7%. This reduces inbox clutter and boosts user productivity in environments with high volumes of promotional email. For filtering of spam and malicious messages, the incremental gains remain modest, and the latest quarter shows a smaller uplift than the prior period—averaging 0.29% and 0.24% respectively, compared to 1.65% and 0.5% in the prior report.

    Stacked horizontal bar chart titled ‘Catch contribution’ showing ICES vendor contribution as a percentage of Microsoft Defender catch (Nov–Jan 2026) for Abnormal, Check, Cisco, DarkTrace, Tessian, Trend, and KnowB4.
    Figure 1. ICES vendor catch contribution (November 2025-January 2026).

    Focusing only on malicious messages that reached the inbox, the latest quarter shows Microsoft Defender’s zero hour auto purge performing the majority of post‑delivery remediation—removing an average of 70.8% of these threats. ICES vendors provided additional post‑delivery filtering, contributing an average of 29.2%. Together, this highlights two points: post‑delivery remediation is a critical backstop when cyberthreats evade initial filtering, and in these results Microsoft Defender delivered most of the post‑delivery catch, while ICES vendors add incremental coverage in this scenario.

    Bar chart titled “Additional post‑delivery malicious catch by Microsoft Defender zero hour auto purge” for Nov 2025–Jan 2026. Percentages by vendor: Abnormal ~56%, Check ~79%, Cisco ~72%, DarkTrace ~66%, Tessian ~31%, Trend Micro ~95%, KnowBe4 ~95%, and overall average ~70%.
    Figure 2. Post‑delivery malicious catch by Microsoft Defender (November 2025-January 2026), shown across vendors and overall average.

    Benchmarking results for SEG vendors

    For the SEG vendor benchmarking metrics, a cyberthreat was classified as “missed” if it was not detected prior to delivery. Using this definition, Microsoft Defender missed fewer high-severity cyberthreats than other solutions evaluated in the study, consistent with patterns observed in our prior benchmarking report.

    Bar chart titled “High severity email threats missed by Secure Email Gateway (SEG) vendors, November–January 2026.” Misses per 1,000 users protected: Microsoft Defender 171; Proofpoint 437; Mimecast 404; Hornet Security 794; Trend Micro 950; Ironport 1,162; Barracuda 1,267; FireEye 1,599.
    Figure 3. High-severity email threats missed by SEG vendors (November 2025-January 2026), measured as cyberthreats missed per 1,000 users protected.

    Reinforcing our commitment to the ICES vendor ecosystem

    Transparency doesn’t stop at Microsoft’s own detections. It also extends to how we work with partners.

    When we introduced the Microsoft Defender for Office 365 ICES vendor ecosystem, our goal was clear: enable customers to integrate trusted, non-Microsoft email security solutions into a unified Defender experience, without fragmenting workflows or visibility.

    That commitment continues today.

    • The ICES vendor ecosystem now includes four partners—Darktrace, KnowBe4, Cisco, and VIPRE Security Group—all integrated directly into Microsoft Defender across experiences such as Quarantine, Explorer, email entity pages, advanced hunting, and reporting.
    • Customers retain a single operational plane in the Defender portal, even when layering multiple email security technologies.
    • Integrations are deliberate and additive, designed to enhance protection and clarity without increasing operational complexity.
    • The ecosystem supports defense-in-depth strategies while preserving a single, coherent security experience.

    The recent additions reinforce our belief that email security is strongest when it combines native platform intelligence with specialized partner capabilities, surfaced through a single pane of glass.

    We continue to actively evaluate additional partnerships based on customer demand, detection quality, and the ability to deliver meaningful, differentiated signals.

    Why this matters for security teams

    Email remains one of the most targeted and exploited attack vectors, and modern campaigns rarely rely on a single technique or control gap.

    By pairing transparent benchmarking with integrated, multi-vendor protection, security teams gain:

    • Clear insight into detection coverage across native and partner solutions.
    • Reduced investigation friction with unified views and workflows.
    • Confidence in layered defenses, backed by regularly published data.

    This isn’t about claiming perfection. It’s about showing the work, sharing the numbers, and giving customers the information they need to make informed security decisions.

    Looking ahead

    We’ll continue to publish updated benchmarking insights on a regular basis, alongside ongoing investments in Microsoft Defender and the ICES vendor ecosystem.

    To explore the latest benchmarking data and learn more about how Defender and ICES partners work together, access the benchmarking site.

    To learn more about Microsoft Security solutions, visit our website. Bookmark the Security blog to keep up with our expert coverage on security matters. Also, follow us on LinkedIn (Microsoft Security) and X (@MSFTSecurity) for the latest news and updates on cybersecurity.


    1Clarity in complexity: New insights for transparent email security, Microsoft. December 10, 2025.





    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

    Related Posts

    3 Questions: On the future of AI and the mathematical and physical sciences | MIT News

    March 12, 2026

    Setting Up a Google Colab AI-Assisted Coding Environment That Actually Works

    March 11, 2026

    ChatGPT as a therapist? New study reveals serious ethical risks

    March 10, 2026

    Self-managed observability: Running agentic AI inside your boundary 

    March 9, 2026

    How an AI Course Can Help You Pivot After a Layoff

    March 8, 2026

    Posit AI Blog: luz 0.4.0

    March 7, 2026
    Top Posts

    Hard-braking events as indicators of road segment crash risk

    January 14, 202619 Views

    Understanding U-Net Architecture in Deep Learning

    November 25, 202519 Views

    How to integrate a graph database into your RAG pipeline

    February 8, 202610 Views
    Don't Miss

    From transparency to action: What the latest Microsoft email security benchmark reveals

    March 13, 2026

    In our last benchmarking post, Clarity in complexity: New insights for transparent email security,1 we…

    Twenty years of Amazon S3 and building what’s next

    March 13, 2026

    Threat Protection Updates in Secure Firewall 10.0

    March 13, 2026

    Growth at any cost is losing its luster

    March 13, 2026
    Stay In Touch
    • Facebook
    • Instagram
    About Us

    At GeekFence, we are a team of tech-enthusiasts, industry watchers and content creators who believe that technology isn’t just about gadgets—it’s about how innovation transforms our lives, work and society. We’ve come together to build a place where readers, thinkers and industry insiders can converge to explore what’s next in tech.

    Our Picks

    From transparency to action: What the latest Microsoft email security benchmark reveals

    March 13, 2026

    Twenty years of Amazon S3 and building what’s next

    March 13, 2026

    Subscribe to Updates

    Please enable JavaScript in your browser to complete this form.
    Loading
    • About Us
    • Contact Us
    • Disclaimer
    • Privacy Policy
    • Terms and Conditions
    © 2026 Geekfence.All Rigt Reserved.

    Type above and press Enter to search. Press Esc to cancel.