ATEON

Blog

Symantec Email Security Cloud: Complete Email Security

18 October 2023 · Updated 15 September 2026

Symantec Email Security Cloud: Complete Email Security

Symantec E-Mail Security Cloud

Symantec Email Security Cloud: Complete Email Security

Email is the most common route cyber criminals use to launch and distribute threats. According to Verizon's 2020 Data Breach Investigations Report, most malware is delivered by email, and 46% of organizations receive nearly all of their malware this way. As the volume of such attacks has grown, so has their level of sophistication. Advanced and zero-day threats are far harder to detect and block than traditional malware, and signature-based malware protection tools have proven largely ineffective against them. Attackers are focusing in particular on targeted phishing attacks in the form of BEC (Business Email Compromise). These compelling and dangerous targeted attacks use sophisticated methods such as domain spoofing and hiding malicious links in email.

Email Security.cloud repels phishing attacks with a comprehensive defence that includes protection, isolation, visibility, sender authentication and user awareness. It also accelerates attack response with analytics that provide deep visibility into targeted attack campaigns. Symantec Information Centric Analytics correlates email, other security telemetry and user behaviour analytics to provide even deeper visibility.

It is part of the Symantec Integrated Cyber Defense Platform, which spans endpoint and web security, threat analysis, security orchestration and automation, and more.

It strengthens the built-in security of cloud and on-premises email systems by preventing the greatest number of malware and email threats with the fewest false positives. It also increases user productivity by blocking spam and other unwanted email such as newsletters and marketing messages.

Symantec Email Security Cloud: Complete Email Security -2

Preventing emerging threats

Sandboxing reveals targeted and advanced attacks by executing unknown files in physical and virtual environments. This helps catch 'virtual machine aware' attacks — threats that do not exhibit suspicious behaviour in virtual environments. The Symantec sandbox imitates human behaviour in order to reveal attacks that only appear malicious in the presence of a person.

Behaviour analysis blocks new, crafted and hidden ransomware by examining all email characteristics, including delivery behaviour, message properties, attachments and social engineering tricks. It also blocks new ransomware variants by determining whether an email contains reused malicious code. Finally, it uses file parsing techniques to detect and extract ransomware hidden in attachments.

Fraud protection automates sender authentication by making sure your email domain cannot be spoofed, eliminating the risk of fraud for internal and external recipients alike.

Symantec Email Security Cloud: Complete Email Security -3

Symantec Email Threat Isolation

Symantec Email Threat Isolation stops credential theft by rendering risky web pages safely, and protects users from advanced email attacks such as spear phishing, credential theft and ransomware by isolating suspicious links and attachments. Email threat isolation takes prevention a step further by creating an isolated execution environment between users and email links, processing suspicious links remotely, showing users only sanitized web content, and scanning potentially infected downloads before delivery. Attacks intended to be delivered through malicious links are therefore simply neutralized.

Symantec Email Threat Isolation also stops phishing attacks. When a suspected phishing website is opened through an email link, the site is rendered in read-only mode, preventing users from entering sensitive information such as corporate passwords.

Symantec Email Security Cloud: Complete Email Security -4

Email Security.cloud accelerates attack response with analytics that provide the deepest visibility into targeted and advanced attack campaigns. This intelligence includes insight into both clean and malicious email and delivers more Indicators of Compromise than any other vendor (more than 60 data points, including URLs, file hashes and targeted attack information). All of it can be fed into your Security Operations Centre through API integration with third-party Security Information and Event Management (SIEM) systems, Symantec Information Centric Analytics or Symantec Integrated Cyber Defense Exchange.

Integrate it

Simplify your security stack and increase your return on investment by integrating email security with the rest of your security infrastructure, including DLP and encryption controls as well as endpoint, network and cloud security.

Email Security.cloud is part of the Symantec Integrated Cyber Defense Platform, so its built-in DLP controls are strengthened through integration with Symantec Data Loss Prevention, which prevents data loss across your entire environment (email, endpoint, network, cloud, mobile and storage systems). You can also meet advanced encryption needs and obtain customizable branding with Symantec Policy-Based Encryption Advanced, a cloud-based add-on service.

It is a hosted service that filters email messages and helps protect organizations from malware (including targeted attacks and phishing), spam and unwanted bulk email.