Spotlight

Report:

The Forrester Wave™: Enterprise Email Security, Q2 2023

How does Forrester define the Enterprise Email Security market in 2023?

Email security is entering a golden age driven by cloud email migration, machine learning adoption, and API-enabled integrations. The market has evolved from stagnation to innovation, with customers increasingly adopting multi-vendor, layered approaches for greater efficacy. Of 37 customer references interviewed, only 2 worked with a single vendor. Key evaluation areas include flexibility in deployments and integrations, ease of security team response, and holistic human protection beyond email to messaging, collaboration, and SaaS applications. The evaluation assessed 15 enterprise email security providers across 26 criteria.

Key Facts for The Forrester Wave™: Enterprise Email Security, Q2 2023 in 2023

How did the Enterprise Email Security market evolve in 2023?

What product features are required to be included in this year's evaluation?

What are the common features of top products in the Enterprise Email Security space?

No common features specified.

Scope Exclusions

Inclusion Criteria

Vendors must, among other requirements:

Offering Strengths — Relative Weighting

Strategy Strength — Relative Weighting

FAQs

Q: What does this research cover?

A: This research provides a comprehensive evaluation of 15 enterprise email security providers across 26 criteria grouped into three categories: current offering (including content analysis, machine learning models, malicious URL detection, antimalware/sandboxing, and email authentication), strategy (including vision, innovation, roadmap, and community), and market presence (revenue and number of customers). The evaluation assesses both secure email gateway (SEG) and cloud-native API-enabled email security (CAPES) deployment options.

Q: Who should use this research?

A: Security and risk professionals should use this research as a guide when selecting enterprise email security providers. The report helps professionals evaluate vendors based on their specific needs, including flexibility in deployments and integrations, analyst experience and response capabilities, and holistic human protection that extends beyond email to messaging, collaboration, and file-sharing applications. The Excel-based vendor comparison tool allows readers to adapt criteria weightings to fit their individual requirements.

Q: What are the mandatory features of vendors included in this market?

A: To be included in this evaluation, vendors must have: 1) At least $30 million in email security revenue from two or more geographies, 2) A productized commercial offering delivered as SEG or CAPES (not custom managed services), with majority revenue from enterprise sales rather than OEMs/MSPs, 3) A product version generally available prior to February 23, 2023, and 4) Significant interest from Forrester customers based on inquiries, advisory, and consulting engagements.

Q: What are some reasons for not being included in this report?

A:

  • Revenue below $30 million threshold
  • Operating in only one geography
  • Offering only custom managed or professional services rather than productized solutions
  • Majority of revenue from OEM or MSP channels rather than direct enterprise sales
  • Product not generally available before the February 23, 2023 cutoff date
  • Insufficient interest or engagement from Forrester's client base
  • Declined to participate in the evaluation process
  • Only partial participation in the evaluation process

Q: What should buyers consider when evaluating products in this market?

A:

  • Offer flexibility in deployments and integrations - ability to mix capabilities from multiple vendors and integrate with key security stack tools
  • Make it easy for security teams to respond - streamlined analyst experience with minimal console jumping and intuitive investigation/remediation workflows
  • Look beyond email to deliver holistic human protection - extend protections to messaging, collaboration, file sharing, and SaaS applications across devices
  • Provide adaptive human protection - move beyond standard phishing tests to real-time nudges and context-aware training
  • Demonstrate ability to connect and share data with other email security vendors and security tools
  • Show clear plans and timelines to improve analyst experience in products and with technology partners
  • Support email authentication protocols with hosted and managed services

Q: How has the Enterprise Email Security market evolved in 2023?

A:

  • Mass customer migration to cloud email infrastructure
  • Rapid adoption of machine learning for threat detection
  • Widespread use of APIs to connect systems and share data
  • Multi-vendor, layered approach to email security (35 of 37 references using multiple vendors)
  • Shift from secure email gateways (SEG) to cloud-native API-enabled solutions (CAPES)
  • Focus on analyst experience (AX) and streamlined workflows
  • Extension of protection beyond email to messaging, collaboration, and SaaS applications
  • Evolution toward adaptive human protection with real-time nudges
  • Integration of email security into broader XDR and Zero Trust strategies

Q: What differentiates Strength of Offering vs. Strength of Strategy?

A: Current Offering evaluates the strength of a vendor's existing product capabilities across 18 criteria including deployment options, detection technologies, machine learning, integrations, and analyst experience. It represents technical execution and product maturity. Strategy evaluates the vendor's future direction across 6 criteria including vision, innovation, roadmap, partnerships, pricing, and community engagement. It represents the vendor's ability to evolve and maintain market relevance over time.

Reference

View Leaders
View Vendor Movements