Site navigation

Concerning Email Security Gaps Highlighted in New Report

Graham Turner

,

Email security trends 2025
With growing cyber-threats and outbound email errors causing major data losses, organisations face increasing pressure to align security strategies with evolving risks

Secure communications specialiser Zivver, has published its latest report, shedding light on critical gaps in email security practices and their alignment with increasing regulatory requirements.

The findings from Email Security Trends 2025: The Widening Disconnect Between Email Security and Risk Management highlight the often-overlooked threats in email security, and the scrutiny of regulatory demands on organisations.

Landmark directives such as NIS2, DORA, and GDPR demand rigorous risk management, information classification, and data leak prevention, with email firmly in the compliance spotlight. Email is a cornerstone of business communication, with 93% of employees ranking it as “important” or “very important” for their daily work, according to the report.

Yet, as the sophistication of cyber-threats increases and compliance requirements evolve, the risks tied to email usage have become a pressing concern for organisations worldwide.

According to the report, which surveyed 400 IT decision-makers and 2,000 employees across the US, UK, Netherlands, France, Germany, and Belgium, over two-thirds of IT leaders report that vendors are not innovating quickly enough to address emerging risks, and 60% of employees admit to using workarounds to bypass email security policies.

Additionally, only 24% of IT leaders feel their security spending is very well-aligned with actual risks, leaving organisations vulnerable to both inbound and outbound threats.

The report highlights several critical findings: while 47% of IT leaders focus on phishing and inbound threats, two-thirds acknowledge that outbound email mistakes – such as misaddressed emails or improper encryption – result in greater data losses.

Over half of employees admit to making email-related mistakes every few months, with 60% bypassing policies through workarounds, underscoring the need for improved tools and training. Despite 73% of employees being aware of email security policies, only 52% consistently follow them.


Recommended reading


Furthermore, just 34% of email incidents are formally reported, leaving IT teams in the dark about the true scale of breaches. Notably, 54% of employees are more prone to errors when busy or overwhelmed, emphasising the importance of providing supportive solutions.

Rick Goud, Co-Founder and CIO at Zivver said: “Compliance requirements today demand that organisations take a comprehensive view of email security, integrating robust solutions that address both inbound and outbound risks.

“By embedding security measures into existing workflows and ensuring they align with evolving regulations, businesses can create a safer and more compliant environment for employees.

“This report offers actionable insights to help organisations align their security measures with today’s challenges while maintaining the trust and productivity that email enables.”

Graham Turner

Sub Editor

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data