Verizon puts it at 21 seconds. Microsoft 365 catches most of what arrives, and for many organizations that is enough. The problem is the small number of messages built to have nothing worth catching. No attachment, no link, only a phone number.
Every figure here is traced to a primary source and dated. 7 minute read · Updated .
The Mirage2FA kit reached around 4,500 organizations across the US and EU this year. It defeats two-factor by stealing the session cookie after login, so there is no payload to detect.
Reported to the FBI in a single year. Phishing losses tripled, from $70M to $216M, while complaint volume stayed flat. Not more mail. Better mail.
We attach in read-only monitor mode and show you what your filtering already allowed through. Fifteen minutes to set up, and the findings stay yours.
Both are sold as API based email security. The difference is measured in seconds and easy to miss on a datasheet.
Verizon puts the median time to click a phishing link at 21 seconds, and 28 seconds more to submit credentials. Under a minute from delivery to compromise.
Any window between delivery and removal is a window your people are already moving through.The practical difference
Verizon Data Breach Investigations Report. We do not use the 183 second figure that circulates in vendor material, because it does not match the report.
Microsoft, as well as Google, is the training ground.Their point, not ours. Attackers rehearse against a free tenant running the same defenses as the target. Check Point, Essential Guide to Email Security.
This is the case that makes timing decisive. Every control downstream of delivery has nothing to work with.
Over fourteen days in August 2026, Check Point caught 24,700 copies of one campaign across 9,000 organizations. The message offered a hardship program and gave a toll free number. The attack completed on the phone, where the caller was asked for bank details or a payment.
| What a filter looks for | Present in the message |
|---|---|
| Malware | None |
| Attachment | None |
| Malicious link | None |
| Spoofed login page | None |
| A phone number | The entire payload |
After someone places the call, sandboxing, URL rewriting and click-time checks no longer apply. Nothing else in the stack can step in. The only control left is the message itself, so it matters whether that control runs before delivery or after.
Check Point, debt relief phishing disclosure, 25 August 2026. No named group was attributed.
Almost every modern email security product connects through the Microsoft 365 API. The difference is what it may do once connected.
| Check Point | Post-delivery API tools | |
|---|---|---|
| When it acts | Before delivery. The message never reaches the mailboxCheck Point product documentation | After delivery. It reaches the mailbox, then is withdrawn |
| Against a no interaction attack | Never delivered, so never triggered | Removal after the fact does not undo it |
Be fair about where the other approach is strong. Behavioral detection of business email compromise is good in this category, and for many organizations post-delivery removal is fast enough. The argument is timing, not whether these products work.
If your vendor says pre-delivery is coming, ask how. Gartner's December 2025 research says post-delivery vendors add it by taking your MX record or rewriting your mail flow rules. That is the gateway model they spent a decade telling you to leave, and Gartner warns it adds latency and disruption. A retrofit is not an architecture.
Gartner Magic Quadrant for Email Security, 1 December 2025. Deployment behavior from vendor documentation.
We sell this, so the useful thing we can tell you is when the answer is no. If all four are true, this is not your next spend.
Spend on identity and payment verification instead. Both remove more risk and cost less.
It answers the one question almost nobody can answer. What is sitting in your users' inboxes that your filtering already passed.
TechPower is an advisory led technology partner. We evaluate, procure, deploy and support security and infrastructure for enterprise and mid-market organizations, and stay accountable for it afterwards rather than handing it off.
Jarrod Downs, our network architect, runs the technical side of every email engagement, from connecting the assessment through deployment and tuning. You meet him on the first call.
We carry a deliberately small set of partners rather than a catalog. Check Point earns its place here because it blocks before delivery.
Implementation and support run through our own team. We do not subcontract deployment, and the people who scope the work run it.
Connect it read-only, see what your filtering passed, and we will tell you honestly whether this is the right next spend.
Book a call and we will set it up