FluidOne Blog

Can you still trust your inbox?

Written by FluidOne | 12/08/2026, 09:00

The Acropolis has stood overlooking Athens for more than two millennia. But what's perhaps more remarkable is that architects are still studying it.

Not because it represents the pinnacle of modern engineering, but because many of the principles behind its design still hold true today.

Long before computer modelling, modern materials and advanced construction techniques, its builders understood something fundamental about structural integrity: if you can't trust the components carrying the load, nothing built on top of them can be relied upon.

That idea extends far beyond architecture.

Every day, organisations make thousands of decisions based on an assumption that something is genuine. A payment request from a colleague. An invoice from a supplier. A document shared by a customer. A message sent from a familiar account.

Most of these decisions happen without much conscious thought, and they need to. If every communication had to be independently verified before anyone could act, work would quickly grind to a halt. Trust removes that friction and allows organisations to collaborate, delegate and make decisions at pace.

The difficulty is that many of the signals used to establish trust are becoming less dependable. Attackers know how heavily organisations rely on familiar people, platforms and processes, and are becoming increasingly adept at using that familiarity against them.

 

The signals we used to trust

For years, security awareness programmes taught employees to look for the obvious warning signs of a malicious email: poor spelling, unusual formatting, strange attachments or an unfamiliar sender.

That advice made sense when malicious communications usually looked different from legitimate ones. Today, that distinction is becoming much harder to make.

A business email compromise (BEC) attack, where a threat actor exploits trusted identities or communication channels to gain information, access or authorisation, may arrive from a genuine account belonging to a colleague, supplier or business partner. The language may be convincing, the request entirely plausible and the timing consistent with normal business activity. The attacker may even have gained access to an existing conversation, giving them the context needed to participate without immediately attracting attention.

This isn’t a theoretical risk. Our Security Operations Centre (SOC) at CSA Cyber has observed a rise in BEC activity, including attackers using session theft and rogue device registration to blend into normal operations and make malicious activity more difficult to distinguish from legitimate use.

These attacks do not necessarily succeed because somebody has missed an obvious warning sign. They succeed because the recipient has been presented with many of the signals they would ordinarily use to establish legitimacy.

That changes the nature of the challenge. Employees are no longer being asked only to recognise something suspicious. They are being asked to question communications that appear, in almost every meaningful respect, to be genuine.

 

When familiarity becomes a weakness

Trust has always been established through signals. A company letterhead, a recognised voice on the telephone, a familiar face across a meeting table or a signature at the bottom of a document all helped people decide whether an interaction was legitimate.

In the modern workplace, those judgements are more likely to be based on an email address, a Teams message, a login prompt or a document shared through a recognised platform.

The principle of trust has not changed, but the environment in which we establish it has. Digital signals can be imitated, manipulated or used by someone other than their legitimate owner, while artificial intelligence is making credible language and convincing impersonation accessible at scale.

This matters because business processes are built around familiarity. We recognise the supplier, understand the request and know that the finance director often needs payments approved quickly. An attacker does not always need to invent an unusual scenario. It can be far more effective to study an established process and quietly place themselves within it.

The most convincing approach may therefore be the one that feels routine. It fits the relationship, arrives through the expected channel and asks the recipient to do something they have done many times before.

 

Why this is a resilience challenge

It would be easy to treat this as an email security problem but that would understate its significance.

Trust supports decisions across almost every part of an organisation, enabling people to share information, approve transactions and grant access without needing to independently validate every interaction they encounter.

If the signals supporting those decisions become unreliable, organisations are left with a difficult balance. Acting without sufficient verification creates risk, but introducing checks into every touchpoint can slow processes, frustrate employees and make ordinary work unnecessarily difficult.

The answer cannot simply be to tell people to become more suspicious. Employees still need to communicate and make decisions, often at speed. Nor is it reasonable to expect them to identify increasingly convincing deception through judgement alone.

As a result, organisations need to preserve the confidence that allows people to work efficiently, while recognising that many of the assumptions that once supported that confidence now require greater scrutiny.

That is what makes trust a resilience principle rather than merely a security concern. An organisation can only continue operating effectively if the people within it have reliable ways to determine what is legitimate, particularly when the familiar signals they once depended on no longer provide enough assurance.

 

The takeaway: Trust needs to evolve

The organisations that respond well to this challenge won't be the ones that remove trust from their processes. They will be the ones that recognise trust can no longer rest on familiarity alone.

For years, organisations have relied on signals like known senders, established relationships and trusted platforms to help determine what is legitimate. Those signals still matter, but they no longer provide the same level of assurance they once did.

That doesn't mean trust is becoming less important. Quite the opposite. Trust remains one of the foundations that allows organisations to communicate, collaborate and make decisions efficiently.

What is changing is how that trust is established.

The Acropolis continues to influence architects because the principles behind its design remain relevant, even though the world around it has changed beyond recognition. Modern organisations face a similar challenge. Trust is still essential, but many of the assumptions used to establish it were formed for a very different environment.

Business email compromise is just one example of that shift in action. It shows how easily familiar signals can be exploited when organisations rely on assumptions that no longer provide enough assurance on their own.

For business leaders, security teams and employees alike, this is not simply a question of email security. It is a reminder that trust itself needs to evolve.

Because resilience does not come from abandoning the principles that organisations depend upon. It comes from ensuring those principles remain effective as conditions change.

 

Interested in how trust is evolving?

Business email compromise offers a clear example of how familiar signals and legitimate access can be turned against the organisations that rely on them.

CSA Cyber’s latest report draws on current intelligence and real-world activity observed by the Security Operations Centre, exploring the BEC tactics analysts are seeing, including the use of session theft and rogue device registration to blend into normal operations, and highlights areas for attention across identity, access and email security.

If this article has prompted you to reconsider how trust is established within your organisation, we recommend reading the Emerging Threat Report for a closer look at the activity being observed and the controls organisations may need to review.