Most breaches still start in the inbox.
Endpoint protection has improved. Network controls have improved. Email is still where attackers find the easiest path, because email is where the humans are, and humans are reliably busy, trusting, and in a hurry. The defense is not one product you buy and forget. It is filtering, authentication, training, and a written response plan, all working together and all kept current as the attacks change.
We tune the filters against your real false-positive rate so the gateway blocks threats without burying legitimate mail, we monitor the DMARC reports that tell us who is sending email in your name, and we run the business-email-compromise playbook the first time someone almost wires money to the wrong account, so there is no second time. When a vendor's account is the one that got compromised, we treat the inbound invoice with the same suspicion we'd give a stranger.
"They flagged a wire-fraud email three minutes after it arrived. The CFO almost approved it. Movalo called him on his cell."
The unglamorous truth is that email security degrades quietly. A new SaaS tool starts sending mail and breaks SPF. A filtering rule gets too aggressive and someone disables it without telling anyone. An exception added for a one-off campaign never gets removed. We watch for that drift, because the gap that lets the next phish through is usually one a busy team created months earlier without meaning to.