SecurityBrief Canada - Technology news for CISOs & cybersecurity decision-makers
Canada
Proofpoint launches AI security against trusted attacks

Proofpoint launches AI security against trusted attacks

Wed, 23rd Sep 2026 (Today)
Mara Sugue
MARA SUGUE News Editor

Proofpoint has launched Agentic Collaboration Security, a system designed to stop attacks that resemble ordinary business communications.

It combines an intent-based detection model with automated tools that investigate threats and adjust protections around higher-risk users. The system works across email, collaboration platforms and web browsers, where phishing, supplier compromise and payment fraud attempts can appear to come from trusted contacts and familiar workflows.

The launch addresses a problem many security teams face as attackers move away from easily spotted mass campaigns and toward messages that blend into routine corporate activity. A compromised supplier account, for example, can be used to continue an existing email thread, while a fraudulent request may fit an established purchasing or finance pattern.

AI is adding to that challenge by increasing the volume and speed of such activity, according to Proofpoint. In that environment, anomaly detection alone may not be enough when the sender, conversation and request all appear plausible.

The new system relies on what Proofpoint calls intent-based detection, which examines what a communication is trying to achieve and whether that objective makes sense in its wider context. It draws on a shared data layer called the Proofpoint Knowledge Graph, which combines threat intelligence, attack patterns, information on compromised suppliers, and organisational data such as business relationships, communication habits, access rights and user risk.

That foundation supports the Nexus Intent-Based Detection Model, which uses multi-stage analysis to assess interactions. Most decisions are made in less than half a second, while less clear-cut cases trigger deeper analysis to determine whether a message is malicious or legitimate in context.

How it works

Proofpoint says its position across both email gateway and API-based protection allows analysis to begin before a message reaches a user and continue after delivery inside the inbox. Intelligence gathered after delivery can feed back into earlier detection, creating what it describes as a connected system rather than a set of separate tools.

The first element is intent-based detection at the gateway and in the inbox. For users with significant authority or access, such as senior executives and finance approvers, dedicated detection models are designed to spot attacks tailored to a specific person.

The second element is automated threat investigation. Proofpoint says the system can reconstruct an attack, identify related messages, determine how widely it has spread and assemble evidence for a response, reducing the manual work required from security teams.

The third element is adaptive user protection, which identifies users considered at higher risk within a specific organisation and changes protections or coaching in response. Internal Blue Team and Red Team agents are used to assess risk and test defences using business context to identify weak points.

Market pressure

The launch comes as security vendors push to show how AI can be used not only by attackers but also in defence. The focus is shifting from filtering obviously suspicious content to analysing trust relationships, authority levels and transaction context, particularly in email and collaboration software where many financial and operational decisions are made.

Proofpoint also linked the new system to the continuing rise in highly targeted social engineering. Such attacks often do not repeat in a standard form, making them harder to catch with models trained only on known patterns. By focusing on intent and context, the company is seeking to identify attacks that may look legitimate at first glance.

The new functions will be delivered as an update to Proofpoint's existing collaboration security offering, so current customers will not need to move to a separate product. Availability may differ in some countries because of data residency rules.

Proofpoint says it serves more than 80 of the Fortune 100, more than 14,000 large enterprises and millions of smaller organisations. It operates across email, cloud and collaboration security, placing this launch in a segment where large vendors are competing to expand protection beyond the traditional email gateway.

“Attackers increasingly operate inside the relationships and workflows organisations already trust,” said Tom Corn, Executive Vice President and General Manager, Threat Protection Group, Proofpoint. “That changes the detection problem. Security needs to understand what an interaction is trying to accomplish, reason over the context around it, and act before the attacker succeeds. Not with disparate tools, but as one system that gets smarter with every decision it makes.”