Abnormal Security In-Depth: Architecture, Business Model, Evan Reiser & Behavioral AI
Abnormal Security (Abnormal Security Corporation) is widely acknowledged as one of the most innovative, transformative, and rapidly compounding enterprise cybersecurity companies in modern history. Founded in 2018 by machine learning pioneers Evan Reiser and Sanjay Jeyakumar, Abnormal fundamentally reinvented cloud email security by replacing clunky legacy Secure Email Gateways (SEGs) with a modern, API-based behavioral AI platform.
Unlike traditional email security vendors that rely on static signature scanning and domain blacklists, Abnormal integrates directly via cloud APIs into Microsoft 365 and Google Workspace to model baseline human behavior across an enterprise. Valued at $5.1 billion following venture investments from Wellington Management, Insight Partners, Greylock Partners, and Menlo Ventures, Abnormal protects over 15% of the Fortune 500, generating over $200 million in annualized recurring revenue (ARR) in 2026 under the executive leadership of co-founder and CEO Evan Reiser.
Key Facts: Abnormal Security Overview
| Dimension | Details & Verified Metrics |
|---|---|
| Company Name | Abnormal Security (Abnormal Security Corporation) |
| Founding Year & Origin | 2018; San Francisco, California, United States |
| Founders | Evan Reiser (CEO), Sanjay Jeyakumar (CTO) |
| Current Valuation | ~$5.1 Billion (Series D led by Wellington Management) |
| Annualized Recurring Revenue (ARR) | ~$200+ Million (2026 run-rate) |
| Total Venture Funding | ~$530 Million (Greylock, Menlo, Insight Partners, Wellington) |
| Headcount | ~1,000 Full-Time Employees |
| Fortune 500 Market Penetration | 15%+ of the Fortune 500 Enterprise Accounts |
| Core Architecture | API-First Behavioral AI (45,000+ Signal Extraction) |
| Official Website | https://abnormalsecurity.com |
Origins: Why Legacy Email Gateways Failed Against Social Engineering
For more than twenty years, enterprise corporate email was secured through an architectural construct known as the Secure Email Gateway (SEG), pioneered by vendors like Proofpoint, Mimecast, and Cisco IronPort. Gateways operated like airport security checkpoints outside corporate walls: companies changed their public DNS Mail Exchanger (MX) records to force all inbound corporate email to route through the gateway first. The gateway inspected incoming messages for known malware signatures, blacklisted sender IP addresses, and malicious web links before forwarding clean mail to the corporate server.
However, by the late 2010s, cybercriminals recognized that the gateway architecture was fundamentally blind to modern social engineering. Attackers stopped sending viruses or suspicious links. Instead, they began executing Business Email Compromise (BEC) and executive impersonation attacks: sending pure, plain-text emails that spoofed a CEO requesting an urgent confidential wire transfer, or compromised a legitimate vendor's email account to send an updated bank routing number on a real invoice. Because these emails contained zero malicious code, zero malicious attachments, and originated from legitimate email servers, legacy gateways let them through 100% of the time. According to the FBI Internet Crime Complaint Center (IC3), Business Email Compromise became the costliest cybercrime in human history, draining more than $50 billion from global enterprises.
Evan Reiser and Sanjay Jeyakumar, who had previously built hyperscale machine learning and anti-fraud systems at Twitter and TellApart, recognized that social engineering was not an infrastructure problem—it was a behavioral problem. A gateway evaluating an incoming email has no context: it does not know if the CEO normally emails the controller, what their typical writing tone sounds like, or what a regular vendor invoice looks like. In 2018, they incorporated Abnormal Security to build an AI platform that understands normal organizational behavior to detect abnormal attacks.
The API-First Deployment Advantage: Bypassing the MX Record
The foundational architectural breakthrough that enabled Abnormal Security’s explosive enterprise adoption was its API-first deployment model. Traditional Secure Email Gateways required complex, high-risk IT cutovers: modifying corporate DNS records, updating MX pointers, and configuring mail routing rules. If a gateway experienced an outage, an entire enterprise’s email communications went completely dark.
Abnormal bypassed the MX record entirely by building native, authenticated API integrations directly with cloud email platforms: Microsoft 365 (via Microsoft Graph API) and Google Workspace. An enterprise security team can deploy Abnormal in less than five minutes simply by granting OAuth permissions in their cloud administrative console. Abnormal requires zero DNS changes, introduces zero email delivery latency, and creates zero single points of failure. Because Abnormal operates inside the cloud tenant, it gains immediate visibility into internal employee-to-employee emails, historical communication threads, and employee sign-in telemetry that legacy external gateways could never see.
The Behavioral AI Engine: Analyzing 45,000 Contextual Signals
When an email arrives in an organization protected by Abnormal, the platform executes a massive, real-time feature extraction pipeline that evaluates more than 45,000 contextual behavioral signals in milliseconds. Abnormal’s neural network models analyze three interconnected identity layers:
- Identity & Communication Graph: Maps the historical communication relationships of every employee. Does the sender normally communicate with the recipient? Is the sender claiming to be the CEO, but using an external freemail domain or an unusual display name?
- Content & Stylometric Analysis: Natural Language Processing (NLP) models evaluate the linguistic tone and urgency of the message. Does the email contain high-risk intent markers (such as requesting gift cards, wire transfers, or payroll modifications)? Does the writing style, punctuation, and phrasing match historical baseline communications from that individual?
- Authentication & Behavioral Telemetry: Cross-references technical headers (SPF, DKIM, DMARC), sender IP reputation, IP geolocation anomalies, and user sign-in telemetry.
By evaluating these signals simultaneously, Abnormal’s models calculate a multi-dimensional risk score. If an attack is detected, Abnormal automatically remediates the threat via API, moving it to the spam or trash folder before the employee ever opens it, completely eliminating the need for security analysts to maintain manual quarantine queues.
Vendor Supply Chain Risk and Invoice Fraud Defense
One of the most devastating and financially catastrophic attack vectors confronting modern enterprises is Vendor Email Compromise (VEC). In a VEC attack, cybercriminals do not spoof an email address; they physically compromise the real email account of a legitimate third-party supplier (such as a law firm, marketing agency, or component manufacturer). Using the vendor’s real inbox, the attacker replies to an ongoing conversation, attaching an updated invoice with the attacker’s fraudulent bank routing details.
Because the email originates from the vendor’s authentic server with valid SPF and DKIM signatures, neither Microsoft nor legacy gateways can detect the fraud. Abnormal solved this challenge by engineering **Vendor Base**, a global collaborative knowledge graph that tracks behavioral profiles for hundreds of thousands of corporate vendors across the world. When an invoice email arrives, Abnormal cross-references the invoice against historical billing baselines: checking whether the banking details have changed, whether the invoice formatting matches previous bills, and whether the vendor’s communication originates from an anomalous geolocation. When invoice fraud is detected, Abnormal flags the message, displays an interactive warning banner, and alerts the finance team, preventing millions of dollars in fraudulent wire disbursements.
Abuse Mailbox Automation: Freeing the Enterprise SOC
In large enterprises, security awareness training encourages employees to report suspicious emails by clicking a 'Phishing' button. In a 50,000-person enterprise, this results in thousands of reported emails flooding into an internal 'Abuse Mailbox' every week. Security Operations Center (SOC) analysts spend up to 30% of their workday manually inspecting these reported emails, analyzing headers, and searching for malware, only to find that 90% of reported messages are benign marketing newsletters or spam.
Abnormal completely automated this operational bottleneck through Abuse Mailbox Automation. When an employee reports an email, Abnormal’s AI engine investigates the message autonomously in seconds, executing natural language analysis and threat correlation. If the message is determined to be malicious, Abnormal automatically purges the email from the reporting user’s inbox and searches across the entire enterprise to claw back all identical messages from every other employee inbox simultaneously. If the message is benign spam, Abnormal automatically responds to the reporting employee with an educational explanation, eliminating thousands of hours of manual SOC toil and allowing enterprise security teams to focus on strategic threat hunting.
High-Dimensional Feature Engineering on Real-Time Graph Databases
Evaluating an incoming email against 45,000 behavioral signals in less than 200 milliseconds is a staggering distributed systems achievement. In an enterprise organization with 50,000 employees receiving 500,000 emails per day, every message represents a multi-dimensional node in a massive, constantly evolving corporate communication graph. If the feature extraction pipeline relied on standard relational database queries, calculating relationship baselines would require complex multi-table joins that would introduce seconds of processing latency.
Abnormal Security solved real-time feature computation by engineering a distributed in-memory graph database and stream processing pipeline. Abnormal ingests historical communication metadata from Microsoft 365 and Google Workspace, compiling an in-memory graph of all historical interactions. For every employee, the system maintains dynamic edge weights representing communication frequency, typical reply times, shared calendar meeting histories, and reporting hierarchies. When an incoming message arrives via webhook, Abnormal's feature pipeline computes thousands of graph traversals and statistical deviations in under 30 milliseconds. Abnormal integrates specialized hardware acceleration for natural language processing (NLP) models, evaluating semantic intent vectors and stylometric features concurrently. By executing high-dimensional feature engineering in memory, Abnormal delivers instant threat scoring without delaying legitimate business communications.
Defense Against Generative AI Phishing and Autonomous Social Engineering
The widespread availability of commercial Large Language Models (LLMs) like OpenAI's ChatGPT and dark-web models like WormGPT has fundamentally altered the economics of cybercrime. Historically, corporate employees could identify phishing emails by looking for telltale grammatical errors, poor spelling, awkward phrasing, and generic salutations written by non-native speakers.
Generative AI eliminated these traditional defensive cues. Today, cybercriminals can feed an executive’s public LinkedIn posts, podcast interviews, and conference transcripts into an LLM to generate flawless, contextually nuanced executive impersonation emails tailored to a specific CFO. Abnormal Security pioneered adversarial generative AI defense to counter this emerging threat vector. Abnormal’s natural language models are trained specifically to identify the structural characteristics of synthetic text, analyzing token probability distributions and semantic entropy. More crucially, Abnormal’s behavioral architecture renders the linguistic perfection of generative AI irrelevant: even if an AI-generated email is grammatically flawless and matches an executive’s tone, Abnormal flags the message because the sender's underlying communication graph, IP geolocation, and cryptographic authentication headers are completely abnormal. By neutralizing the offensive power of generative AI, Abnormal protects enterprises against the next generation of automated cyber warfare.
The Anatomy of Cloud Account Takeover (ATO) Detection
In modern cloud-first enterprises, email is not merely a communication channel; it is the ultimate identity verification hub. When a cybercriminal compromises an employee’s cloud credentials (via credential stuffing, session cookie theft, or sophisticated phishing), they gain access to Microsoft 365, Google Workspace, corporate Slack channels, and enterprise single sign-on (SSO) portals.
Once inside a corporate inbox, attackers execute subtle, stealthy reconnaissance: searching for financial spreadsheets, creating hidden inbox forwarding rules to exfiltrate sensitive messages, and sending phishing emails to colleagues from a legitimate internal corporate account. Traditional security tools that monitor only external traffic are completely blind to these internal attacks. Abnormal engineered Account Takeover (ATO) Protection, an identity intelligence engine that monitors post-authentication behavior inside the cloud tenant. Abnormal continuously tracks user activity telemetry: flagging impossible travel anomalies (e.g., logging in from Chicago and Amsterdam within 10 minutes), suspicious browser user-agent changes, rapid mailbox export commands, and the creation of hidden forwarding rules. When account takeover is detected, Abnormal automatically terminates the active session, resets corporate credentials via Okta or Microsoft Entra ID, and uninstalls malicious third-party OAuth apps, neutralizing insider threats in seconds.
Human Behavior Security: Expanding Beyond the Inbox to Slack and Teams
As modern enterprises adopted hybrid and remote work models, corporate communication decentralized. While email remains the formal channel for external communication, internal operational collaboration migrated almost entirely to workplace messaging platforms like Slack, Microsoft Teams, and Zoom. Recognizing that email security gateways were increasingly watching an empty front door while internal attacks occurred via direct messages, cybercriminals began executing multi-channel social engineering attacks.
Abnormal Security responded by expanding its category vision into Human Behavior Security. Leveraging the same behavioral graph architecture that secured email, Abnormal integrated native API sensors across Microsoft Teams, Slack, Zoom, and cloud identity platforms. Abnormal models baseline communication patterns within Slack channels and Teams chats: detecting compromised accounts posting malicious links in general channels, identifying unauthorized file sharing, and intercepting multi-channel impersonation scams. By creating a unified behavioral intelligence fabric that protects employees wherever they communicate, Abnormal established a comprehensive human risk management platform that bridges email security, collaboration defense, and enterprise identity governance.
Autonomous Incident Response: Automated Mailbox Clawback and Threat Correlation
When an active cyberattack penetrates an enterprise perimeter, speed of remediation is the single most critical factor in preventing financial catastrophic loss. In organizations relying on legacy Secure Email Gateways and manual SOC procedures, responding to a phishing campaign requires security analysts to manually write PowerShell scripts, search through thousands of user mailboxes, and delete malicious messages one by one. This manual process typically takes between two and six hours, during which hundreds of unsuspecting employees open the malicious emails and compromise their credentials.
Abnormal Security completely transformed incident remediation by engineering an autonomous API-driven mailbox clawback engine. When Abnormal detects a novel threat—whether through incoming behavioral scoring, employee abuse mailbox reports, or global threat intelligence feeds—the platform executes an automated enterprise-wide sweep via Microsoft Graph and Google Workspace APIs in less than 30 seconds. Abnormal’s system calculates cryptographic content hashes and semantic similarity vectors, locating every instance of the attack across tens of thousands of employee inboxes simultaneously. The system claws back and quarantines the malicious emails before employees have an opportunity to interact with them. if an employee has already clicked an unauthorized link before remediation, Abnormal automatically interfaces with identity providers like Okta and endpoint security platforms like CrowdStrike, forcing an immediate session logout and isolating the endpoint from corporate networks, reducing mean time to remediate (MTTR) from hours to seconds.
Vendor Base Graph Architecture: Cross-Enterprise Collaborative Intelligence
One of the most complex vectors in enterprise cybersecurity is third-party supply chain risk. A Fortune 500 corporation typically interacts with over 20,000 distinct external vendors, suppliers, law firms, and consulting agencies. Even if the corporation’s internal security controls are virtually impenetrable, their external suppliers often maintain weak passwords, lack multi-factor authentication, and are easily compromised by cybercriminals.
Abnormal Security engineered a revolutionary collective defense mechanism known as Vendor Base. Operating as a global, multi-tenant collaborative knowledge graph, Vendor Base continuously monitors and profiles the behavioral norms of hundreds of thousands of commercial vendors across the global economy. When an enterprise protected by Abnormal receives an invoice from a vendor, Abnormal cross-references the transaction against the global collective graph: examining whether other enterprises have recently flagged this supplier account for unusual behavior, whether the supplier's banking details match established baselines across other corporate clients, and whether the supplier’s email sending servers have recently changed. If an attacker compromises a regional law firm’s email system and attempts to send fraudulent wire instructions to fifty different corporate clients simultaneously, Abnormal’s Vendor Base recognizes the cross-enterprise anomaly instantly, neutralizing the attack across all protected organizations concurrently. This collective graph architecture transforms enterprise defense from an isolated corporate struggle into a shared global immune system.
The Free Threat Assessment Playbook: Converting CISOs via Real-World Efficacy
In the enterprise cybersecurity sales landscape, Chief Information Security Officers (CISOs) are notoriously cynical and weary of aggressive software sales pitches. Every cybersecurity vendor claims to use 'next-generation artificial intelligence' and promises '100% protection,' leaving enterprise security buyers skeptical of theoretical marketing claims.
Abnormal Security bypassed enterprise sales friction by inventing the Automated Free Threat Assessment. Because Abnormal integrates natively via cloud APIs in under five minutes with zero MX record changes, Abnormal offers prospective enterprise customers a risk-free, non-intrusive evaluation. Abnormal connects to the enterprise’s live Microsoft 365 or Google Workspace environment in read-only mode, ingesting historical communication telemetry and evaluating emails that successfully passed through the company's incumbent Secure Email Gateway (Proofpoint or Mimecast). After two weeks, Abnormal presents the CISO with an empirical, undeniable security audit: revealing dozens of active Business Email Compromise attacks, executive impersonation scams, and compromised internal accounts that had bypassed the incumbent gateway and were currently sitting in employee inboxes. By showing enterprise leaders real, verified attacks threatening their actual corporate balance sheets, Abnormal achieved astonishing enterprise conversion rates exceeding 80%, disrupting the market dominance of legacy gateway conglomerates.
Compliance and Regulatory Mandates: SEC Disclosure Rules and BEC Liabilities
In recent years, the regulatory liability confronting corporate boards of directors and executive leadership regarding cybersecurity risk has escalated dramatically. In 2023, the US Securities and Exchange Commission (SEC) enacted stringent new cybersecurity disclosure rules, requiring public companies to disclose material cybersecurity incidents within four business days and provide detailed disclosures regarding board oversight of cybersecurity risk management.
Business Email Compromise represents one of the most frequent sources of material financial loss, resulting in multi-million-dollar wire fraud incidents that trigger mandatory public SEC 8-K disclosures, shareholder lawsuits, and devastating stock price declines. Abnormal Security provides corporate general counsels and audit committees with an enterprise regulatory compliance and risk mitigation framework. Abnormal maintains immutable audit logs of all email inspection and automated remediation actions, providing clear, auditable documentation that an enterprise has deployed state-of-the-art controls to safeguard corporate treasuries against wire fraud. Abnormal achieved comprehensive SOC 2 Type II, ISO 27001, and HIPAA certifications, validating that its behavioral machine learning infrastructure processes sensitive corporate communications in full compliance with global data privacy regulations.
Zero False-Positive Engineering: Precision Machine Learning in Enterprise Email Routing
In enterprise communication, the only outcome worse than letting a malicious phishing email through to an employee is inadvertently blocking a legitimate, multi-million-dollar customer contract, supplier invoice, or board communication. If an AI cybersecurity tool generates frequent false positives, frustrated business executives bypass security controls or force IT directors to disable the software entirely.
Abnormal Security engineered its machine learning architecture around an unyielding commitment to zero false-positive precision. In enterprise email, false positives occur when algorithms mistake unusual, high-stakes language (such as an urgent acquisition negotiation or an emergency executive wire transfer) for malicious social engineering. Abnormal prevents false positives through multi-layer ensemble voting and deep identity corroboration. A message is never quarantined based on urgent linguistic phrasing alone; it must exhibit anomalous behavioral deviations across multiple independent dimensions—such as sudden IP geolocation anomalies, uncharacteristic email client headers, and unfamiliar relationship graphs. Abnormal incorporates automated self-tuning mechanisms: as an organization evolves, acquires subsidiaries, and hires new executives, the behavioral graph updates dynamically in real time, ensuring that legitimate executive urgency is never silenced while malicious deception is decisively neutralized.
Identity Threat Detection and Response (ITDR): Securing the Modern Cloud Identity Fabric
Modern enterprise work does not occur within the physical boundaries of corporate offices; it operates across a sprawling constellation of cloud SaaS applications connected via federated single sign-on (SSO). Cybercriminals have recognized that compromising a single set of enterprise credentials grants broad access to enterprise data stored across Microsoft 365, Google Workspace, Slack, ServiceNow, and Salesforce. Once an attacker gains entry, they blend in with legitimate employee activities, bypassing conventional network perimeter controls and signature-based antivirus.
Abnormal Security recognized that email security and identity security are fundamentally inseparable. By ingesting behavioral telemetry across both email communication patterns and cloud directory authentication events, Abnormal engineered an advanced Identity Threat Detection and Response (ITDR) capability. Abnormal models each user's habitual authentication velocity, typical geographic login locations, VPN endpoints, multi-factor authentication (MFA) device fingerprints, and concurrent SaaS application access sessions. When an executive appears to log in from Chicago and Tokyo within thirty minutes—or when an employee account suddenly generates anomalous mailbox forwarding rules, downloads massive quantities of confidential SharePoint documents, and requests unauthorized password resets—Abnormal's identity intelligence engine flags the session as an active account takeover (ATO). The platform autonomously revokes active session tokens, disables compromised cloud credentials, and prompts security operations teams with an end-to-end investigation timeline, preventing lateral movement before attackers can exfiltrate proprietary corporate intellectual property.
Enterprise Autonomous Operations: The Strategic Shift from Reactive SOCs to Self-Healing Defenses
For decades, enterprise cybersecurity departments operated as reactive triage clearinghouses. Tier-1 security operations center (SOC) analysts spent their workdays overwhelmed by thousands of low-fidelity alerts, manually inspecting suspicious email attachments, cross-referencing IP blacklists, and responding to employee reports of spam and phishing. This operational exhaustion led to severe analyst burnout, delayed incident response times, and catastrophic breaches slipping through unreviewed alert queues.
Abnormal Security pioneered the architectural transition toward self-healing, autonomous security operations. By eliminating 99% of manual email triage through authoritative machine learning decisions, Abnormal liberates enterprise security teams to focus on strategic threat hunting, architectural resilience, and proactive risk management. Abnormal's AI architecture operates 24/7/365 without human fatigue, evaluating every inbound, outbound, and internal message against millions of behavioral parameters in milliseconds. In the modern threat environment—where generative AI tools allow threat actors to launch millions of hyper-personalized, context-aware phishing lures simultaneously—human analysts cannot manually inspect attacks at the speed of computation. Abnormal Security represents the archetype of next-generation enterprise defense: an autonomous, self-learning cognitive layer that defends corporate communications at computational velocity, establishing unprecedented resilience for the global digital economy.
Extended FAQ: Frequently Asked Questions
Who founded Abnormal Security and when?
Abnormal Security was founded in 2018 by machine learning pioneers Evan Reiser (CEO) and Sanjay Jeyakumar (CTO) in San Francisco, California.
What is Abnormal Security's valuation and revenue?
Abnormal Security is valued at $5.1 billion following its Series D round led by Wellington Management, generating over $200 million in annualized recurring revenue (ARR) in 2026.
How does Abnormal Security differ from Proofpoint and Mimecast?
Proofpoint and Mimecast require MX record rerouting and scan static links; Abnormal deploys via API in 5 minutes and uses behavioral AI across 45,000 signals to stop text-only BEC.
What is Business Email Compromise (BEC)?
BEC is a socially engineered cyberattack where attackers impersonate executives or vendors using plain-text requests for wire transfers or sensitive data without using malware or links.
How long does it take to deploy Abnormal Security?
Abnormal deploys in under five minutes via native cloud APIs for Microsoft 365 and Google Workspace with zero MX record changes and zero email downtime.
What is Vendor Supply Chain Risk protection?
Vendor Supply Chain Risk profiles thousands of global vendors to detect compromised supplier email accounts, invoice manipulation, and fraudulent wire redirection.
What is Abuse Mailbox Automation?
Abuse Mailbox Automation autonomously investigates and remediates employee-reported phishing emails in seconds, eliminating manual SOC triage.
How many Fortune 500 companies use Abnormal?
Abnormal Security protects more than 15% of the Fortune 500, securing corporate email at Xerox, Hitachi, Mattel, Choice Hotels, and major financial institutions.
Can Abnormal Security detect generative AI phishing?
Yes, Abnormal's behavioral models identify synthetic language patterns generated by LLMs like ChatGPT and evaluate whether sender identity matches historical baselines.
Is Abnormal Security planning an Initial Public Offering (IPO)?
Yes, with seasoned executive leadership, $200M+ in ARR, and public-company governance, Abnormal is actively preparing for an initial public offering on American equity markets.