Introducing Multi-Vector Threat Protection

Introducing Multi-Vector Threat Protection: Correlated Intelligence, Complete Protection 

---

UPDATE (January 19, 2026): Multi-Vector Threat Protection will be made available to all MX-deployed Email Security Cloud Gateway customers by the end of this week.

---

We're pleased to announce that Multi-Vector Threat Protection will be enabled for all MX-deployed Email Security Cloud Gateway customers. Initially launched in December 2025 for customers with CyberGraph or Advanced BEC Protection, MVTP is now expanding to all MX-deployed email security customers. The rollout started on January 19 and by the end of this week all email security customers will be enabled.

Why We Built This

Email security has evolved beyond single-threat detection. Today's attackers coordinate campaigns that combine phishing URLs, fake e-signature services, and human verification steps - exploiting the gaps between isolated security layers. While our multi-context analysis approach has proven effective at analyzing 2-3 key contexts, the modern threat landscape demands broader visibility. Sophisticated attacks now distribute malicious indicators across different threat surfaces to evade traditional detection, requiring a comprehensive approach that captures intelligence from every available source.

What We're Releasing

Multi-Vector Threat Protection expands our threat intelligence platform from select context sources to comprehensive platform-wide integration. The technology correlates signals from multiple contexts to identify threats that evade single-point detection:

Baseline capabilities (all customers):

  • Mimecast intel graphs
  • Spam indicators
  • URL indicators

Enhanced capabilities (customers with CyberGraph or Advanced BEC Protection):

  • Customer social graphs (in addition to all baseline sources)

Each context flags suspicious indicators - unknown senders, newly created domain spikes, freemail usage, human verification traps and more. Our platform then aggregates these comprehensive signals, identifying the broader malicious intent that attackers try to hide across multiple attack vectors. Setup is straightforward through our AdCon interface, mirroring the Advanced BEC Protection style policy creation most of our customers are already familiar with.

Here is an example from earlier this year:

image.png

How Customers Benefit

  • Improved Detection Efficacy - Detect sophisticated attacks that traditional single-point solutions miss by correlating signals from all available contexts, providing comprehensive coverage against coordinated threat campaigns.
  • Complete Threat Visibility - All Multi-Vector detections surface in Analysis & Response with a "Multi-Vector" sub-category, consolidating detection results across different security layers and enabling faster threat identification and response.
  • Future-Ready Defense - Stay ahead of emerging attack techniques through continuous correlation of global threat intelligence, protecting against AI-generated threats and zero-day campaigns that exploit gaps between isolated security layers.

Getting Started

Multi-Vector Threat Protection is now available for all MX-deployed Email Security Cloud Gateway customers. The activation requirements depend on your customer profile:

  • Customers with licenses that do not include Cybergraph: The MVTP policy will appear in your AdCon interface ready for manual activation. You can enable it in either Monitor mode (to observe detections without taking action) or Quarantine mode (to hold suspicious messages for review). We recommend starting with Monitor mode to establish a baseline before moving to Quarantine.
  • Customers who have Cybergraph or Advanced BEC in their current package, or who are migrating to our new bundles: MVTP Monitor mode will be activated by default. Review the detections in Analysis & Response, and when you're ready to take action on detected threats, you can manually move the policy to Quarantine mode.

Configuration is quick and easy through your AdCon interface. Follow the steps in this article to learn how.

Was this article helpful?
0 out of 0 found this helpful

Comments

13 comments
Date Votes
  • Is this capability now available for all Cloud Gateway customers? We don't have ABEC or Graph however the MVTP policy option is now available.

    0
  • In reply to MiniTrump:

    Hello!

    Yes, as of January 19, 2026, Multi-Vector Threat Protection will be made available to ALL MX-deployed Email Security customers, including those without CyberGraph or Advanced BEC Protection.

    For customers without CyberGraph, MVTP will leverage URL indicators, spam indicators, and Mimecast intel feeds to improve coordinated detection across multiple threat vectors.

    The policy should appear in your Administration Console. For customers without Cybergraph, you'll need to manually activate it - you can start in Monitor mode to review detections before moving to Quarantine mode where it will take action on detected messages.

    The phased rollout is happening across all regions this week, so if you're seeing the policy option, you're ready to enable it!

    We will update this blog post tomorrow for more info!

    0
  • In reply to Alexander Decarne:

    Awesome news, thanks Alexander.

    0
  • hh

    0
  • hi

    0
  • ji

    0
  • In reply to Marjia Khan:

    Hi @Marjia Khan - do you have a question or need some assistance?

    0
  • Does this solution have abilities to combat advanced phishing attacks such as AITM?

    0
  • In reply to Thabang:

    Yes,

    Rather than relying on a single check, MVTP correlates multiple detection signals from different engines - in AiTM scenarios delivered via inbound email some relevant ones to mention are:

    • Behavioral: spots identity impersonation by recognizing when a sender's behavior doesn't match their normal patterns.
    • Chronograph: flags suspicious sending infrastructure
    • Header & Authentication Analysis: picks up structural anomalies inside emails
    • Deep URL Inspection: Amongst other things it inspects CAPTCHA pages and redirect chains, the tricks attackers use to hide malicious links.

    MVTP correlates signals across every layer and AiTM attacks are often engineered to fool any one defense in isolation. By understanding the bigger picture we are able to make smart delivery decisions in these scenarios, combatting these types of phishing more effectively.

    0
  • Hello,

    We are a Canadian customer and would like clarification on data residency and processing for MVTP and Advanced BEC Protection.

    Is email data processed or analyzed in the United States at any stage ?

    Or is all processing performed within Canadian data centers?

    If processing occurs outside Canada, what data elements leave Canada?

    Thanks,

    0
  • In reply to Junior Rmillard:

    Hi Junior,

    Please reach out to your account team, they can provided detailed answers to your questions above.

    Thank you,

    Dylan

    0
  • we have had MVTP and ABEC enabled in learning / monitor mode for a number of weeks now, and we are ready to move to "HOLD" phase for detected emails.

    Should we be creating a new policy to HOLD for MVTP and ABEC, or should we be editing the existing policies from Monitor to Hold?

    0
  • In reply to Rob Betts:

    Hey Rob,

    If you are confident in the detections visible through Analysis & Response based on the current policies you have created in MONITOR, my advise is to move those policies to HOLD.

    Regards,

    Alexander

    0

Please sign in to leave a comment.