![Krish P.](/assets/transparent-ad5be28fbcd25b7b08d2cebe1d957125437fb5407d75ee717965ad22c8808791.gif "Krish P.")
KP

Krish P.

Web Development Intern

Computer Software

Enterprise (\> 1000 emp.)

8/21/2026

Business partner of the seller or seller's competitor, not included in G2 scores.

"Highly capable of mail security through an API, will search asynchronously, but there's a gotcha."

4.5/5

What do you like best about Abnormal AI?

I'm a Cyber Security Engineer at a medium size financial services company. Our motive for using Abnormal Security is to defend our Microsoft 365 tenant against sophisticated phishing and Business Email Compromise (BEC) attacks, as well as vendor impersonation attacks, that our normal Secure Email Gateway (SEG) could not defend against. Our SOC team also uses its automated remediation capabilities to deal with the huge volume of emails that are reported to them with suspicious content.The best thing about Abnormal is the deployment itself is so simple. Since it integrates directly using Microsoft 365 APIs rather than needing intricate MX record modifications, it was up and running in our environment in just a matter of moments. The AI engine's ability to grasp the nuances of communication and To ensure the proper setting for what's considered the norm in employee performance is extremely precise. Commonly discovers highly advanced attacks and forgery of vendor invoices with no visible malicious links or attachments. Prior to Abnormal, at least half of a security analyst's day would be spent manually examining reported email or ramping through their inboxes, one by one. With the platform's auto-remediation, though, nearly all of that is done in the background, and that's a giant timesaver for our small team. It is indeed a high dollar solution to use Abnormal Security versus traditional email security, but for our team, the ROI has been 100% worth it. The per-mailbox pricing model seemed like a bit of an "up front investment" for a medium size user base. This combination of user-provided policy and the overwhelming number of engineering hours our SOC analysts put in taking care of user-reported phishing tickets weekly makes the platform self-funding not just in recovered productivity, but in recovered time. Most important of all, denying one costly vendor scam or bogus wire transfer message eradicates the entire yearly position. Automation and risk reduction are worth a lot for asecurity team faced with heavy workload and members who can't keep up with threats in their inbox all day. Review collected by and hosted on G2.com.

What do you dislike about Abnormal AI?

Abnormal works through the API (asynchronously, not within the mail flow itself as a traditional gateway would be) so scanning processes are not synchronous. This implies a malicious e-mail will appear in a user's inbox for a few seconds in between the AI system analyzing it and retriving it. There's a very fine margin for error if someone is focused on their inbox and presses the keys really rapidly. Also, there are instances when the system is a bit too strong in money related emails; it may mistake for example a genuine invoice or a message from a collaborator for ‘graymail' and perhaps even ‘potential threat'. Succumbing to these false positives takes some time as it isn't always readily possible to just whitelist a trusted domain without a bit of a hoop-jumping exercise. Review collected by and hosted on G2.com.

What problems is Abnormal AI solving and how is that benefiting you?

The danger of account takeover and targeted VIP spoofing was huge as our CEO would be involved in emergencies calls for wire transfers under fake names. Our previous gateway only protected on a threat signature basis and had no protection against text only attacks. But in Abnormal they realized that our executives really do write and communicate. It recently thwarted a dishonest vendor who asked our finance department to wire funds to another account for a bill worth hundreds of thousands of dollars. So, by automating the triage on our abuse mailbox and preventing these zero day social engineering attacks, it has cut our organisational risk even down to the next level and allowed us to direct our security team's efforts towards proactive threat hunting as opposed to copious amounts of email management. Review collected by and hosted on G2.com.

Show More

Validated ReviewerIncentivizedSource: G2 invite

See what 79 reviewers think of Abnormal AI

4.8 out of 5 · Verified reviews from real users

[
Read all reviews
](https://www.g2.com/products/abnormal-ai/reviews)