A finance office meeting room in the early morning, two people in business dress reviewing a wire transfer approval on a laptop screen at a glass table, city skyline visible through the window in soft

Mimecast Proofpoint or Abnormal AI for Business Email Compromise

8 min read

None of Mimecast, Proofpoint or Abnormal AI publishes per-mailbox pricing, so UK enterprises must compare them on deployment architecture, bundled modules and quote-scoping rather than a public price list. UK Finance and FBI IC3 data show email-based fraud is rare by case count but disproportionately high value, which is why a verified callback step matters alongside whichever platform is chosen.

Daniel Thomas
Written by Daniel Thomas

None of Mimecast, Proofpoint or Abnormal AI publishes a public per-mailbox price, so cost comparison depends on the quote each vendor returns for the same mailbox count and deployment mode. The bigger decision for a UK enterprise handling high-value wire transfers is architecture. Mimecast and Proofpoint run as a gateway or API layer, while Abnormal AI is API-only. Pair whichever you choose with a verified callback step before releasing any changed payment instruction.

Key pointers

  • No vendor publishes a per-mailbox or per-user price list. Get quotes for the same mailbox count, deployment mode and add-ons before comparing totals.
  • Mimecast and Proofpoint can run as a secure email gateway (MX record change) or via API. Abnormal AI is API-only, with no MX record change.
  • UK Finance's 2025 fraud data show email-originated payment fraud is rare by case count but disproportionately costly per case, which fits a wire-transfer risk profile.
  • All three vendors trade through active UK-registered companies, so contracts, invoicing and support can sit with a UK legal entity.
  • Ask each vendor how BEC detection interacts with your existing controls: DMARC enforcement, Microsoft 365 or Google Workspace rules, and your payment-approval process.
  • Whichever platform you pick, keep a human step: verify any changed bank detail or urgent payment request through a separate, previously confirmed contact channel.
  • Treat any online "per-mailbox price" you see quoted for these three vendors with caution. None of it comes from the vendors themselves.
Stopping a wire transfer BEC attempt
A verified callback stays the last line of defence even when detection tools flag the message.

What Business Email Compromise Means for a High-Value Wire Transfer Desk

Business email compromise is an impersonation scam, not usually a malware attack. An attacker spoofs or takes over a senior executive's or supplier's email account and instructs someone in finance to send money to an account the attacker controls. Mimecast's own guidance describes the two most common variants as CEO fraud, where the attacker poses as the chief executive, and CFO fraud, where the same pattern runs through the finance chief's name to make a larger transfer request look ordinary.

For a UK enterprise moving high-value wire transfers, this is not an abstract risk. The FBI's IC3 recorded $55.5 billion in global exposed BEC losses across 305,033 incidents between October 2013 and December 2023, and noted that UK banks were a frequent intermediary stop for stolen funds in 2023. Of the money reported to have reached the fraudsters between June 2016 and December 2023, $17.5 billion went to recipients inside the US and $8.95 billion went to recipients outside it, confirming BEC proceeds move internationally, not just domestically.

Closer to home, UK Finance's 2025 data shows email accounted for only 1% of authorised push payment fraud cases but 7% of the value lost, exactly the pattern you would expect if the channel is used mainly for a small number of large, deliberately targeted transfers rather than mass-market scams. By value, UK Finance's breakdown of where 2025's APP fraud started attributes 32% of losses to online origins, 28% to telecommunications, 7% to email, 8% to other channels and 24% to unknown origin.

A smaller finance team runs the same risk with fewer people checking each transfer, so the underlying controls, verifying any change to bank details and slowing down urgent, out-of-hours requests, matter just as much below enterprise scale.

How Each Platform Detects and Stops BEC

The three products approach the problem from different starting points.

Mimecast sells BEC protection as a standard feature across all three of its current plans (Critical, Advanced and Premium), bundled with social graphing, dynamic bannering and on-click URL analysis on every tier. Browser Isolation, Email Continuity and Email Backup and Recovery are held back for the Advanced and Premium tiers, so the entry-level Critical plan covers detection but not those additional controls. Its higher tiers reference a Cloud Gateway architecture for continuity and secure large-file sending, consistent with its roots as a secure email gateway vendor.

Proofpoint offers Core Email Protection with a choice of deployment: a traditional secure email gateway that inspects mail inline before delivery, or an API-based integration with Microsoft 365 or Google Workspace that Proofpoint says can go live within 48 hours. It pairs this with a Threat Protection Workbench that unifies inbound, internal, account-takeover and supplier-risk investigation in one place, and an Abuse Mailbox Agent to automate handling of emails staff report as suspicious.

Abnormal AI (the current name for Abnormal Security) is built API-only. It connects directly to the mailbox rather than sitting in the mail flow, so there is no MX record change and, the vendor says, a live deployment within 60 seconds. Its marketing explicitly targets displacing a gateway rather than sitting alongside one, using behavioural AI to flag anomalies such as an unusual payment request from a spoofed executive account, in cases it says a gateway would otherwise mark safe.

None of this tells you which product will catch a specific attack aimed at your organisation. It does tell you what you are buying: a bundled layer on an existing Microsoft 365 or Google Workspace deployment (Abnormal AI), or a gateway-capable platform that can also run in API mode (Mimecast, Proofpoint).

Pricing and Cost Model

All three vendors sell BEC protection on a custom, quote-based per-mailbox or per-user basis. Mimecast's plans page lists every tier as "Contact for pricing" or "Custom pricing available". Proofpoint's and Abnormal AI's product pages route straight to a demo request, with no published price list for any tier. This means there is no rate card to compare, and any specific per-mailbox figure you see quoted online for these three products, including the widely varying numbers that circulate on comparison and pricing-aggregator sites, has not been confirmed by any of the three vendors and should not be treated as current.

What you can control is the quote you ask for. Cost for all three is driven by:

  • Mailbox or user count, and whether pricing breaks at defined bands (for example, small, mid-market and enterprise tiers).
  • Deployment mode, since a gateway migration (Mimecast, Proofpoint) typically carries more implementation effort than an API-only rollout (Abnormal AI), even where the licence cost is similar.
  • Protection tier and bundled modules, such as archiving, continuity, data loss prevention, security awareness training or identity threat protection, which can be sold as separate line items.
  • Contract term and minimum commitment, since annual and multi-year terms typically carry different unit prices.
  • Existing licences, since Proofpoint's and Abnormal AI's API modes sit alongside Microsoft 365 or Google Workspace's native filtering rather than replacing it, so you are paying for an additional layer, not a swap.

Before comparing totals, ask each vendor for a quote scoped to the same mailbox count, the same deployment mode, and the same list of included modules, and ask them to itemise anything sold as an add-on. Also ask what a mid-contract increase in mailbox count costs, and what happens to price at renewal.

Vendor and Option Comparison

CriterionMimecastProofpoint (Core Email Protection)Abnormal AI
Deployment modelGateway or API, via Cloud Gateway architectureSecure email gateway or API (Microsoft Graph integration)API only, no MX record change
BEC protectionStandard on every plan tierBehavioural AI plus Threat Protection WorkbenchCore product focus, behavioural AI
Notable differentiatorBundles continuity, archiving and large-file sending with securityUnified investigation across inbound, internal, account and supplier riskMarkets itself as a gateway replacement, not an add-on
Pricing modelQuote-based, tiered by plan (Critical, Advanced, Premium)Quote-based, per user or mailboxQuote-based, per mailbox or user
Published price listNoneNoneNone
UK legal entityMimecast Services Limited, London (active)Proofpoint Limited, Bury St Edmunds (active)Abnormal AI UK Ltd, London (active)

Mimecast suits a buyer who wants BEC protection bundled with continuity, archiving and large-file sending under one gateway-based contract, and who is comfortable with a fuller platform migration. Proofpoint suits a buyer who wants the option of either a gateway or an API deployment, plus a single investigation view that spans inbound, internal and supplier-related threats. Abnormal AI suits a buyer who wants to add behavioural detection on top of Microsoft 365 or Google Workspace quickly, without touching mail routing, though it is not a replacement for the native filtering already in place.

None of the three is a poor choice for stopping BEC on the evidence available. The right one depends on whether you are replacing a gateway, adding a layer to existing filtering, and how much implementation effort your team can absorb.

Editorial analysis

Given that none of the three publishes pricing, a CISO handling high-value wire transfers gets more value from a structured proof-of-value trial than from a feature checklist. Ask each vendor to run against a sample of real, anonymised email traffic and report what it would have flagged, then compare that against what your current controls already caught. That test, not the marketing claims on each vendor's site, is the evidence that should decide the shortlist. Whichever platform wins, treat it as one control in a chain that still needs a verified callback step before money moves, because a detection tool that is bypassed by an approving human is no protection at all.

Sources

Data & Insights

Where UK authorised push payment fraud losses started in 2025

Email accounted for a small share of cases but a disproportionate share of the money lost, by origin of the fraud.

Where UK authorised push payment fraud losses started in 2025Email accounted for a small share of cases but a disproportionate share of the money lost, by origin of the fraud.Online32% (32.3%)Telecommunications28% (28.3%)Email7% (7.1%)Other8% (8.1%)Unknown24% (24.2%)
View the data
Where UK authorised push payment fraud losses started in 2025
CategoryShare of APP fraud losses by value
Online32%
Telecommunications28%
Email7%
Other8%
Unknown24%
Source: UK Finance Annual Fraud Report 2026

Global BEC exposed losses by recipient location, 2016 to 2023

Financial-recipient exposed dollar losses reported to the FBI's IC3 show most stolen funds still land with US-based recipients, though a large share moves overseas.

Global BEC exposed losses by recipient location, 2016 to 2023Financial-recipient exposed dollar losses reported to the FBI's IC3 show most stolen funds still land with US-based recipients, though a large share moves overseas.US$0.00US$5.00US$10.00US$15.00US$20.00US financial recipientsUS financial re…Non-US financial recipientsNon-US financia…US financial recipients, Exposed dollar loss, June 2016 to December 2023 ($bn): US$17.50Non-US financial recipients, Exposed dollar loss, June 2016 to December 2023 ($bn): US$8.95
View the data
Global BEC exposed losses by recipient location, 2016 to 2023
CategoryExposed dollar loss, June 2016 to December 2023 ($bn)
US financial recipientsUS$17.50
Non-US financial recipientsUS$8.95
Source: FBI Internet Crime Complaint Center, Business Email Compromise: The $55 Billion Scam

Frequently Asked Questions

Does Mimecast, Proofpoint or Abnormal AI publish a public price per mailbox?

No. Mimecast's plans page lists every tier as custom or contact-for-pricing, and both Proofpoint's and Abnormal AI's product pages route to a demo request rather than a price list. Treat any specific per-mailbox figure you see for these three products online as unverified unless it comes from your own quote.

Can we run Abnormal AI alongside our existing Microsoft 365 filtering?

Yes. Abnormal AI is built to connect via API to an existing Microsoft 365 or Google Workspace deployment rather than replace the mail flow, so it adds a behavioural detection layer on top of native filtering instead of swapping it out.

Do Mimecast and Proofpoint require changing our mail routing?

Only if you choose the gateway deployment option. Both vendors also offer an API-based mode that does not require an MX record change, alongside their traditional secure email gateway option.

Is email actually a major source of payment fraud in the UK?

By case count, no. UK Finance's 2025 data shows email accounted for only 1% of authorised push payment fraud cases. By value, it accounted for 7% of losses, which points to a small number of high-value, deliberately targeted attacks rather than a high-volume channel.

What should we ask a vendor for before comparing quotes?

Ask for a quote scoped to your actual mailbox count, your preferred deployment mode, and an itemised list of what is included versus sold as an add-on (archiving, DLP, security awareness training, identity protection). Also ask what a mailbox-count increase costs mid-contract and what changes at renewal.

What single control matters most alongside any of these products?

A verified, out-of-band callback for any request to change bank details or release an urgent payment, using a contact method confirmed in advance rather than the one supplied in the email itself. The NCSC's guidance on business payment fraud sets out this approach for UK organisations.