With most organizations standardizing on cloud-delivered email in an effort to shift costs from CapEx to OpEx, they did so with the underlying assumption that email service providers would automatically include comprehensive security controls. However, many have suffered from phishing-related attacks that have led to credential theft and business email compromise (BEC), while others have faced the loss of sensitive data through both unintentional and intentional actions, leading to the addition of third-party security controls.